mutagent CLI and the SDK act as you without a browser. Keys start with
mg_live_. On your own machine you rarely need to copy one: mutagent login creates and stores a key
for you. Create a key by hand for CI, scripts and servers.
Organization key or workspace key
The key
mutagent login stores is an organization key that expires after 30 days. Pick a workspace key
when a pipeline should only ever touch one workspace.
Create a key
1
Open the API keys page
In app.mutagent.io, go to Settings › Organization › API Keys for an
organization key, or Settings › Workspace › API Keys for a key limited to the current
workspace.
2
Create it
Click Create Organization API Key (or Create API Key on the workspace page), give it a
name, and pick an expiration: Never, 7, 30, 90 or 180 days, or 1 year.
3
Copy it
The full key is shown once. Store it in your CI secret store or a password manager.
Use a key in CI
SetMUTAGENT_API_KEY and every mutagent command authenticates with it, with no browser and no
stored sign-in. With an organization key, also name the workspace:
Output
To store the key on the machine instead of exporting it in every shell, run
MUTAGENT_API_KEY=mg_live_... mutagent login --json once.
A GitHub Actions step:
CI=true, which most CI systems set, turns off every prompt, the same as --non-interactive.
--api-key <key> on a single command works too, but it puts the key in your shell history; prefer the
environment variable.
The SDK reads the same key:
Revoke a key
Revoke a key on the page where it was created. It stops working on the next request. An expired key stays in the list until you revoke it.Good practice
- One key per pipeline or machine, so revoking one breaks nothing else.
- Set an expiration on keys that live in CI.
- Prefer a workspace key when the job only needs one workspace.
- Never commit a key. If one leaks, revoke it first, then create its replacement.