Reference
Create and manage service credentials: workspace-owned secrets that let headless automation call
Helix Cloud. You manage them with your WorkOS login, but they never log the CLI in. Cloud only.
Owners and admins need the workspace-scoped service_credentials.manage permission.
Usage
--workspace.
Subcommands
Arguments
Options
Behavior
- The workspace resolves as described in Cloud resource resolution.
- Each grant is project-scoped and must name a project ID inside the owning workspace.
- Available grants are
project-read,project-write,query-read, andquery-write, comma-separated; write requires its matching read. - Each project may appear in only one
--grant, and a grant cannot repeat a permission. - Creation prints the secret once on stdout. With
--json, the full create response, including the secret, is printed instead. Updates never reveal or rotate it. updateneeds at least one of--name,--grant,--expires-at, or--clear-expiry.revokeasks for confirmation in a terminal. Without one, or with--json, it fails before any request unless you pass--yes.- Service credentials authenticate headless HTTP API calls and the unified MCP endpoint at
https://mcp.helix-db.com/mcp. - MCP exposes only the query and customer administration tools their project grants allow. These sessions do not get Cloud discovery or observability tools.
- They are never a CLI login method and the CLI never persists them.
Examples
Related
helix auth— the WorkOS login used to manage credentials.helix workspace— list your workspaces.helix project— find the project IDs to grant.