User & Access Key Commands
Manage identities, access permissions, self-service password changes, and programmatic Access Keys.
1. User Management Commands (liorans3 user)
List Users (user list, alias: ls)
liorans3 user list
Example Output:
USERNAME ROLE STATUS MUST CHANGE PASS CREATED
admin admin active no 10/1/2026, 6:00:00 PM
ci-worker readwrite active no 10/1/2026, 6:10:00 PM
auditor readonly active yes 10/1/2026, 6:15:00 PM
Inspect User Profile (user get, alias: info)
liorans3 user get ci-worker
Create User (user create)
liorans3 user create ci-worker --role readwrite -P "WorkerPass123!"
Update Role or Status (user update)
# Update role
liorans3 user update ci-worker --role admin
# Disable or enable account
liorans3 user disable ci-worker
liorans3 user enable ci-worker
Self-Service Password Change (user passwd)
Any authenticated user can change their own password:
liorans3 user passwd --old "OldPassword123!" --new "NewPassword456!"
Administrative Password Reset (user reset-password)
Admins can reset any user password and enforce change on next login:
liorans3 user reset-password auditor --new "TempPass789!" --must-change
Delete User (user rm, alias: delete)
liorans3 user rm auditor --yes
2. Access Key Commands (liorans3 key)
Create Access Key (key create)
Generates a new programmatic Access Key pair:
liorans3 key create "backend-worker" --expires-days 90 --save-to-profile backend
Example Output:
=============================================================
NEW ACCESS KEY CREATED
=============================================================
Name: backend-worker
Key ID: bk_live_0192a7b8c9d0
Secret Key: sk_live_9f83a21b4c7e6d5a8b7c6d5e4f3a2b1c
Owner: admin
Expires: 2026-12-30T12:00:00.000Z
=============================================================
WARNING: The Secret Key above is ONLY displayed once.
Store it securely immediately; it cannot be recovered later.
Saved credentials to local profile 'backend'.
=============================================================
List Access Keys (key list, alias: ls)
liorans3 key list
Example Output:
KEY ID NAME OWNER STATUS LAST USED EXPIRES CREATED
bk_live_0192a7b8c9d0 backend-worker admin active 10/1/2026, 6:20:00 PM 12/30/2026, 12:00:00 PM 10/1/2026, 6:00:00 PM
Rotate Access Key Secret (key rotate)
Immediately revokes the previous secret and generates a new secret for the same Key ID:
liorans3 key rotate bk_live_0192a7b8c9d0 --save-to-profile backend
Revoke Access Key (key revoke, aliases: rm, delete)
liorans3 key revoke bk_live_0192a7b8c9d0 --yes
Output:
Access key 'bk_live_0192a7b8c9d0' revoked successfully.