Admin Commands
Manage API tokens and security settings for your self-hosted Runtime instance.Admin commands require direct database access. They’re for self-hosting operators, not end users.
Prerequisites
Set these environment variables:create-token
Create a new API token with specified permissions.Required Arguments
Options
Scopes
Examples
Output
revoke-token
Revoke an API token (soft delete).Arguments
Options
Example
Output
Revoked tokens immediately stop working. The record is kept for audit purposes.
list-tokens
List API tokens (metadata only, no values).Options
Examples
Output
rotate-pepper
Guide through pepper rotation process.Options
Rotation Process
1
Add new pepper to environment
2
Deploy with new config
Restart API and worker with updated environment.
3
Check migration status
4
Wait for old tokens to expire
Or revoke them manually.
5
Remove old pepper
Example
Running in Docker
If running Runtime in Docker, exec into the container:Security Best Practices
Use specific principals
Use specific principals
Create separate tokens for different users/services instead of sharing.
Set expiration dates
Set expiration dates
Temporary access should expire:
Use least privilege
Use least privilege
Give only the scopes needed:
- CI pipelines:
read,deploy - Monitoring:
read - Full access:
admin(rarely needed)
Audit regularly
Audit regularly
Review tokens periodically:
Rotate peppers periodically
Rotate peppers periodically
Even without a breach, rotate peppers annually.
Related
- Configuration - Environment variables
- Docker Compose - Running services