Skip to content
Thyme Docs

API Keys

Manage credentials in Console → API Keys for your deployment. A newly created secret key is shown once; store it securely because the original value cannot be retrieved later.

Different keys serve different purposes

  • A standard thyme login creates a personal upload/read credential used by the regular CLI workflow.
  • thyme login --management requests an owner/admin's consent for a workspace-bound management credential with the listed scopes.
  • Named executable webhooks use a separate run-only URL credential and do not require a management key.

A management request must satisfy both key scope and workspace authorization. See API authentication for current scope and resource rules.

Create and revoke

Create the appropriate key, copy its shown-once value, and put it in your local credential store or CI secret manager. If a key is lost, create a replacement and revoke the old key. Revocation stops further authenticated requests; it does not cancel transactions already submitted to the chain.

Do not paste production credentials into docs examples, task source, or project args. A task normally needs a bound application secret, not your management key.

Local credential storage

The CLI stores credentials in ~/.thyme/config.json (0600). Standard and management credentials are stored separately. Switching a project's .env does not automatically revoke or replace stored credentials.

thyme logout removes the standard local token. Use the management logout options for a workspace credential. Neither operation revokes the server-side key; use console revocation when access should end across machines.

See authentication, login, and CI.