Why a separate credential?
Pipelines are stateful infrastructure - creating one provisions a worker, opens a connection to your destination, and starts consuming data. We use a different credential type so that:- Read-only API keys (which may be embedded in client-side code, CLI scripts, or shared between teammates) cannot accidentally create, modify, or delete pipelines.
- ServiceKeys can be rotated independently of the API keys your application already uses to call the Foundational and Streaming APIs.
- Pipeline mutations are auditable - every CRUD action is attributed to the user who issued the ServiceKey.
Creating a ServiceKey
- Sign in to the GoldRush Platform.
- Open your account settings and select Service Keys.
- Click Create Service Key, give it a name, and copy the value shown.
Using a ServiceKey
Send the key as a bearer token on every Pipeline REST request:Scope and permissions
ServiceKeys inherit the group of the user who created them. Two users in different groups cannot see each other’s pipelines through the API, even if both have a ServiceKey.
Rotation and revocation
Rotate a ServiceKey at any time by creating a new one and revoking the old one:- Create a new ServiceKey on the Platform.
- Update your secret store / CI variables to use the new key.
- Verify your pipelines still respond (
GET /platform/pipeline-api/). - Revoke the old key on the Platform.
401 Unauthorized.