Each API key now holds its own set of capabilities, so the key in your CI can do less than the key on your laptop. Pick them when you create a key: open the dashboard, then API Keys.
readlists projects and entries. Every key holds it.writecreates and edits projects and entries.publishpublishes an entry, including one you publish as you create it.deletedeletes an entry, or unpublishes one.
Four presets sit above the checkboxes: Full access (all four), CI / automation (read, write and publish), Read only, and Custom. Every key that existed before this change was given publish and delete as well, so nothing you already run breaks.
A call the key is not scoped for gets a 403 that names what is missing, such as API key lacks publish permission. deploylog push --publish needs both write and publish. Run deploylog whoami to see what the current key holds.
The API keys section of chapter 11 of the DeployLog manual describes every preset and capability.