Skip to main content

Admin Commands

Manage API tokens and security settings for your self-hosted Runtime instance.
Admin commands require direct database access. They’re for self-hosting operators, not end users.

Prerequisites

Set these environment variables:

create-token

Create a new API token with specified permissions.

Required Arguments

Options

Scopes

Examples

Output


revoke-token

Revoke an API token (soft delete).

Arguments

Options

Example

Output

Revoked tokens immediately stop working. The record is kept for audit purposes.

list-tokens

List API tokens (metadata only, no values).

Options

Examples

Output


rotate-pepper

Guide through pepper rotation process.

Options

Rotation Process

1

Add new pepper to environment

2

Deploy with new config

Restart API and worker with updated environment.
3

Check migration status

4

Wait for old tokens to expire

Or revoke them manually.
5

Remove old pepper

Example

Output:
Pepper rotation cannot migrate existing tokens automatically (raw tokens aren’t stored). You must:
  1. Keep old pepper active during migration
  2. Issue new tokens with new pepper
  3. Eventually revoke old tokens

Running in Docker

If running Runtime in Docker, exec into the container:

Security Best Practices

Create separate tokens for different users/services instead of sharing.
Temporary access should expire:
Give only the scopes needed:
  • CI pipelines: read,deploy
  • Monitoring: read
  • Full access: admin (rarely needed)
Review tokens periodically:
Even without a breach, rotate peppers annually.