Skip to content

feat(access-key): create read-only and app-scoped keys - #11

Merged
ciehanski merged 1 commit into
mainfrom
feat/scoped-access-keys
Sep 27, 2026
Merged

ciehanski merged 1 commit into
mainfrom
feat/scoped-access-keys

Conversation

@ciehanski

Copy link
Copy Markdown
Member

dpctl access-key add could only create keys with full access to every app. Adds two flags:

  • --scope read creates a key that can only make GET requests. Default stays full.
  • --app <name> limits the key to one app; repeat for several. Omit for all apps.

Examples:

  • dpctl access-key add "MyApp CI" --app MyApp-iOS --app MyApp-Android
  • dpctl access-key add "Metrics bot" --scope read

The API scopes by app id but people type app names, so names are resolved first and a bad one fails before the key is minted rather than after.

access-key ls gains a Scope column reading full access, all apps or read only, MyApp-iOS.

Neither field is sent when the flag is absent, so a key created without the new flags is byte-identical to before.

@ciehanski
ciehanski merged commit 3d47739 into main Sep 27, 2026
3 checks passed
@ciehanski
ciehanski deleted the feat/scoped-access-keys branch September 27, 2026 05:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant