API Keys
Manage credentials in Console → API Keys for your deployment. A newly created secret key is shown once; store it securely because the original value cannot be retrieved later.
Different keys serve different purposes
- A standard
thyme logincreates a personal upload/read credential used by the regular CLI workflow. thyme login --managementrequests an owner/admin's consent for a workspace-bound management credential with the listed scopes.- Named executable webhooks use a separate run-only URL credential and do not require a management key.
A management request must satisfy both key scope and workspace authorization. See API authentication for current scope and resource rules.
Create and revoke
Create the appropriate key, copy its shown-once value, and put it in your local credential store or CI secret manager. If a key is lost, create a replacement and revoke the old key. Revocation stops further authenticated requests; it does not cancel transactions already submitted to the chain.
Do not paste production credentials into docs examples, task source, or project args. A task normally needs a bound application secret, not your management key.
Local credential storage
The CLI stores credentials in ~/.thyme/config.json (0600). Standard and management credentials are stored separately. Switching a project's .env does not automatically revoke or replace stored credentials.
thyme logout removes the standard local token. Use the management logout options for a workspace credential. Neither operation revokes the server-side key; use console revocation when access should end across machines.
See authentication, login, and CI.