Kordin Neo
Organization Acme Labs
Search or jump to ⌘K
$21.05
A bell with a count and a short list of what needs attention is not in this build yet. Documentation Get help Signed in as Sam Okonkwo Your settings
The last state is the one nobody draws: the same request twice returns the key's details with no key in them.

API Keys

For scripts and CI. Not for signing in.
Copy this now — you will not see it again
We do not keep a copy. If you lose it, the only thing to do is create another one and remove this. Every key we issue starts with kordin_key_, so a string found somewhere it should not be can be recognized and revoked without anyone having to try it.
kordin_key_7f3a2c1b9e04d5a6c8f1b2e3d4a5c6b7d8e9f0a1b2c3d4e5
API keys for this org
Key Service account Access Expires Last used Inference spend Money is billing, and billing is not in October.
CI deploys
created just now
ci-deployer Developer · acme-web 1 Dec 2026
in 90 days
never $0.00
Nightly backup script
created 18 days ago
backup-runner Viewer · acme-web 12 Sep 2026
in 11 days
12 hours ago $4.10

A key cannot hold a role. It borrows the one its service account holds, so the row names the account and the account names the role — which is also why there is no grant list here. And every key expires: there is no way to make one that does not, so the column can never be empty.

ci-deployer

A service account. Not a person, and it cannot become one.
Keys belong to accounts, and accounts belong to people. The account is what holds the role, the purpose and the person answerable for it. A key is only a credential under it — which is why removing a key changes nothing about who is allowed to do what.
What the account carries
Responsible person Sam Okonkwo — the human answerable for this account. Required, because an account with nobody behind it is the one nobody turns off. If Sam leaves, offboarding hands this over rather than deleting it.
Purpose Building and deploying acme-web from CI. Written when the account was made, so a reader in six months does not have to guess from the name.
Role Developer · acme-web — it can deploy, roll back and read logs. It cannot manage projects, people or other accounts, and it can never do more than the person who created it. There is no role that lets a service account own the org.
Review date 1 Mar 2027 — the date somebody has to look at this again and say it is still needed. Separate from the keys' expiry on purpose: a key expiring asks rotate this, a review date asks should this exist at all.
Keys under it One, CI deploys, expiring 1 Dec 2026. An account may hold several, which is how a rotation happens without a gap: create the next one, move CI onto it, remove the old one.
Delete the account and its keys

API Keys

That key already exists, and we cannot show it again

This is the same request as a moment ago, so no second key was made — which is correct, and it is also why there is nothing to copy. The key called CI deploys exists and is usable; the secret was only ever shown once.

If you have it, nothing is wrong. If you do not, create a new key and remove this one — there is no way to recover a secret we never kept.

replayed · key CI deploys exists · secret not recoverable

API Keys

That key is not being accepted

ci-deployer was revoked five hours ago by Sam Okonkwo, and something is still presenting it. Nothing is broken and nothing is at risk — a revoked key is refused at the boundary, before it reaches anything.

What to look at: whatever holds it still has the old value. Replacing the value where it is stored is the whole of the fix, and a new key is issued once and shown once.

See when it was revoked
you can fix this

The request did not carry a valid credential. Sign in again or present a valid API key.

Reference 3d81ba90c4e7Get help ›
Show the code UNAUTHENTICATED

API Keys

That key is being throttled

ci-deployer made more requests in the last minute than the interval allows. Nothing was rejected permanently and nothing was charged — the requests are being asked to wait, and the response says how long.

This is a limit on the pace of requests, not on what the key may do. Retrying after the interval works; retrying immediately extends it.

What it has spent
you can fix this

Too many requests were made in a short period. Wait for the interval given with this response and try again.

Reference c7a204ef1b55Get help ›
Show the code RATE_LIMITED