Store a key
Do not put API keys in:
- Dockerfiles
- Images
- Source code
- Shell history
- Public CI logs
Rotate a key
Rotate does these things:- It revokes the old secret immediately.
- It keeps the id, the scope and the expiry date of the key.
- It replaces the secret and shows the new secret one time only.
409 api_key_expired. Create a replacement key instead.
Rotate needs a browser session. Read What a key cannot do.
Rotate with downtime
Use Rotate only when you can update the deployed secret immediately.- Rotate the key. Run
boat api-key rotate <id>, or use the dashboard. To find the id, runboat api-key list. - Copy the new secret.
- Update
BOAT_API_KEYin your platform secret manager. - Redeploy or restart the workers that use the key.
Replace without downtime
- Create a new key.
- Update the platform secret to the new key.
- Redeploy or restart the workers.
- When the new deployment is live, revoke the old key.
Revoke a key
Runboat api-key revoke <id>, or click Revoke in the dashboard. Revoke needs a browser session.
- Revoke turns off the key immediately.
- The next Boat API request with that secret fails with an auth error. This includes existing CLI configs and running processes.
- The sandboxes and Agents that the key created stay.
boat api-key usage <id>still shows their totals.