API keys
API keys let scripts, CI pipelines and the yard CLI call Yard's API
without a browser. How to use one in a request is in the
API reference.
Personal and organization keys
- A personal key acts as you, with the role you have right now in each organization. If your role changes, so does what the key can do. Make them in Account → API keys.
- An organization key acts for one organization only, for things like a deploy pipeline or a shared script. It acts as a Member or an Admin, chosen when it is made, and never more than the admin who made it can do now. Organization admins make them in Settings → API keys.
No key, whatever its scopes, can manage API keys, sessions, passwords, passkeys or two-step sign-in, sign in to agents, connect GitHub, or approve a CLI sign-in.
Scopes
| Scope | Allows |
|---|---|
| Read | Listing and opening organizations, workspaces, files and chats. |
| Write | Changing things: files, canvases, chats, and settings the owner may change. |
| Runners | Registering and managing runners. |
Give a key only the scopes it needs. A new key starts with Read.
Create a key
- Choose New key.
- Give it a Name you will recognise later, such as "GitHub Actions deploy".
- Tick its Scopes.
- Choose when it Expires: 30 days, 90 days, 1 year or never. For an organization key, also choose what it Acts as.
- Choose Create key.
The key is shown once. Copy it and keep it somewhere safe: Yard stores only a fingerprint of it and cannot show it again.
The list shows each key's first characters, scopes, when it was last used and from where, and when it expires. Organization keys also show who made them.
Rotate a key
Rotate makes a new secret for the same key and shows it once. Choose what happens to the old secret: Stop the old secret now, or keep it working for 1 hour, 24 hours or 7 days while you swap it everywhere it is used. Until then the key is marked "rotating".
Revoke a key
Revoke stops the key at once. Anything still using it gets an error. This cannot be undone; make a new key instead.
Expired and revoked keys stop working. Each key can make up to 600 requests a minute.
Sign in the yard CLI
yard login makes a personal key for the CLI without you copying anything:
- The CLI prints a code and opens a page in your browser
(
/cli/login?code=…). Sign in to Yard if you are asked to. - The page Sign in the yard CLI shows the Code, the Computer it came from, and what the key May do.
- Check that the code matches the one in your terminal, then choose
Confirm and sign in. If you did not just run
yard login, choose This was not me.
The CLI receives its key and the key appears in Account → API keys,
where you can revoke it like any other. yard logout revokes it too.
See installing the CLI and the CLI reference.