Cyberia SecretOps
08 / Access
API Keys & Roles
Scoped keys with roles, prefixes and expiry for every automation.
In this feature
- Keys at organization, project and app scope
- Role assignment per key
- Expiry with never-expires opt-in
- Alive / expired status at a glance
- Prefix identification without revealing the key
- Search and filter by status or role
// In the console
What it looks like
Issue API keys at organization, project or app level, assign a role such as operator or viewer, set an expiry and track status by prefix — so a CLI, a CI pipeline and a server agent each authenticate as themselves.
API Keys & Roles

Least privilege
A key per consumer
Separate keys for the CLI, CI and each server mean revoking one never takes the rest down.
Identity
Prefixes, not values
Keys are recognised by prefix in lists and logs, so you can audit usage without exposing material.
Lifecycle
Expiry is the default
Keys carry an expiry and surface in the expiring-soon counter well before they lapse.
Included out of the box
Keys at organization, project and app scope
Role assignment per key
Expiry with never-expires opt-in
Alive / expired status at a glance
Prefix identification without revealing the key
Search and filter by status or role