Skip to main content
An API key lets the mutagent CLI and the SDK act as you without a browser. Keys start with mg_live_. On your own machine you rarely need to copy one: mutagent login creates and stores a key for you. Create a key by hand for CI, scripts and servers.

Organization key or workspace key

The key mutagent login stores is an organization key that expires after 30 days. Pick a workspace key when a pipeline should only ever touch one workspace.

Create a key

1

Open the API keys page

In app.mutagent.io, go to Settings › Organization › API Keys for an organization key, or Settings › Workspace › API Keys for a key limited to the current workspace.
2

Create it

Click Create Organization API Key (or Create API Key on the workspace page), give it a name, and pick an expiration: Never, 7, 30, 90 or 180 days, or 1 year.
3

Copy it

The full key is shown once. Store it in your CI secret store or a password manager.

Use a key in CI

Set MUTAGENT_API_KEY and every mutagent command authenticates with it, with no browser and no stored sign-in. With an organization key, also name the workspace:
Output
Exit code 0 means the key works in that workspace. The other exit codes: To store the key on the machine instead of exporting it in every shell, run MUTAGENT_API_KEY=mg_live_... mutagent login --json once. A GitHub Actions step:
CI=true, which most CI systems set, turns off every prompt, the same as --non-interactive. --api-key <key> on a single command works too, but it puts the key in your shell history; prefer the environment variable. The SDK reads the same key:

Revoke a key

Revoke a key on the page where it was created. It stops working on the next request. An expired key stays in the list until you revoke it.

Good practice

  • One key per pipeline or machine, so revoking one breaks nothing else.
  • Set an expiration on keys that live in CI.
  • Prefer a workspace key when the job only needs one workspace.
  • Never commit a key. If one leaks, revoke it first, then create its replacement.