Skip to main content

User & Access Key Commands

Manage identities, access permissions, self-service password changes, and programmatic Access Keys.


1. User Management Commands (liorans3 user)​

List Users (user list, alias: ls)​

liorans3 user list

Example Output:

USERNAME ROLE STATUS MUST CHANGE PASS CREATED
admin admin active no 10/1/2026, 6:00:00 PM
ci-worker readwrite active no 10/1/2026, 6:10:00 PM
auditor readonly active yes 10/1/2026, 6:15:00 PM

Inspect User Profile (user get, alias: info)​

liorans3 user get ci-worker

Create User (user create)​

liorans3 user create ci-worker --role readwrite -P "WorkerPass123!"

Update Role or Status (user update)​

# Update role
liorans3 user update ci-worker --role admin

# Disable or enable account
liorans3 user disable ci-worker
liorans3 user enable ci-worker

Self-Service Password Change (user passwd)​

Any authenticated user can change their own password:

liorans3 user passwd --old "OldPassword123!" --new "NewPassword456!"

Administrative Password Reset (user reset-password)​

Admins can reset any user password and enforce change on next login:

liorans3 user reset-password auditor --new "TempPass789!" --must-change

Delete User (user rm, alias: delete)​

liorans3 user rm auditor --yes

2. Access Key Commands (liorans3 key)​

Create Access Key (key create)​

Generates a new programmatic Access Key pair:

liorans3 key create "backend-worker" --expires-days 90 --save-to-profile backend

Example Output:

=============================================================
NEW ACCESS KEY CREATED
=============================================================
Name: backend-worker
Key ID: bk_live_0192a7b8c9d0
Secret Key: sk_live_9f83a21b4c7e6d5a8b7c6d5e4f3a2b1c
Owner: admin
Expires: 2026-12-30T12:00:00.000Z
=============================================================
WARNING: The Secret Key above is ONLY displayed once.
Store it securely immediately; it cannot be recovered later.
Saved credentials to local profile 'backend'.
=============================================================

List Access Keys (key list, alias: ls)​

liorans3 key list

Example Output:

KEY ID NAME OWNER STATUS LAST USED EXPIRES CREATED
bk_live_0192a7b8c9d0 backend-worker admin active 10/1/2026, 6:20:00 PM 12/30/2026, 12:00:00 PM 10/1/2026, 6:00:00 PM

Rotate Access Key Secret (key rotate)​

Immediately revokes the previous secret and generates a new secret for the same Key ID:

liorans3 key rotate bk_live_0192a7b8c9d0 --save-to-profile backend

Revoke Access Key (key revoke, aliases: rm, delete)​

liorans3 key revoke bk_live_0192a7b8c9d0 --yes

Output:

Access key 'bk_live_0192a7b8c9d0' revoked successfully.