Scoped API keys: give each key only what its job needs

feature

Each API key now holds its own set of capabilities, so the key in your CI can do less than the key on your laptop. Pick them when you create a key: open the dashboard, then API Keys.

  • read lists projects and entries. Every key holds it.
  • write creates and edits projects and entries.
  • publish publishes an entry, including one you publish as you create it.
  • delete deletes an entry, or unpublishes one.

Four presets sit above the checkboxes: Full access (all four), CI / automation (read, write and publish), Read only, and Custom. Every key that existed before this change was given publish and delete as well, so nothing you already run breaks.

A call the key is not scoped for gets a 403 that names what is missing, such as API key lacks publish permission. deploylog push --publish needs both write and publish. Run deploylog whoami to see what the current key holds.

The API keys section of chapter 11 of the DeployLog manual describes every preset and capability.