Skip to main content
Reference
Create and manage service credentials: workspace-owned secrets that let headless automation call Helix Cloud. You manage them with your WorkOS login, but they never log the CLI in. Cloud only. Owners and admins need the workspace-scoped service_credentials.manage permission.

Usage

Every subcommand also accepts --workspace.

Subcommands

Arguments

Options

Behavior

  • The workspace resolves as described in Cloud resource resolution.
  • Each grant is project-scoped and must name a project ID inside the owning workspace.
  • Available grants are project-read, project-write, query-read, and query-write, comma-separated; write requires its matching read.
  • Each project may appear in only one --grant, and a grant cannot repeat a permission.
  • Creation prints the secret once on stdout. With --json, the full create response, including the secret, is printed instead. Updates never reveal or rotate it.
  • update needs at least one of --name, --grant, --expires-at, or --clear-expiry.
  • revoke asks for confirmation in a terminal. Without one, or with --json, it fails before any request unless you pass --yes.
  • Service credentials authenticate headless HTTP API calls and the unified MCP endpoint at https://mcp.helix-db.com/mcp.
  • MCP exposes only the query and customer administration tools their project grants allow. These sessions do not get Cloud discovery or observability tools.
  • They are never a CLI login method and the CLI never persists them.

Examples