API keys
API keys (personal access tokens) let the CLI, CI scripts, MCP clients and your own code act on your account without your password. They look like dh_pat_ab12CD34_….
Create a key
Section titled “Create a key”- In the console, go to Settings → API Keys and click Create API Key.
- Enter a Key Name (for example Production Deploy Key).
- Choose the Access:
- Full access: everything you can do, except account, security and billing settings.
- Read only: view resources only (
GETandHEADrequests).
- Choose an Expiration: 30 days, 90 days, 1 year or never.
- Click Create Key and copy it now. You won’t be able to see it again.
DockHive emails you whenever a key is created. You can have up to 25 active keys.
Use a key
Section titled “Use a key”| Where | How |
|---|---|
| API | Authorization: Bearer dh_pat_... |
hivepod CLI and MCP server |
export HIVEPODS_TOKEN=dh_pat_... |
dockhive tunnel CLI |
dockhive login --token dh_pat_... or export DOCKHIVE_TOKEN=dh_pat_... |
curl https://gw.dockhive.sh/api/v1/auth/me \ -H "Authorization: Bearer $DOCKHIVE_API_KEY"Treat keys like passwords: keep them in your CI’s secret store, never in your code.
What keys can’t do
Section titled “What keys can’t do”For your safety, API keys can’t change your account. These always need a console sign-in:
- your profile, email, password and two-factor authentication,
- connecting or disconnecting GitHub, and your sessions,
- billing: checkout and payment methods (keys can read your plan, subscription and invoices),
- creating or revoking API keys.
A key that tries gets 403 with “API keys cannot be used for account, security, billing or API-key management.”
Revoke a key
Section titled “Revoke a key”In Settings → API Keys, click revoke on the key and confirm. Anything using it (CLI, CI scripts, MCP clients) loses access within a minute. The list shows each key’s status (active, expired or revoked), when it was last used and when it expires.
If your account is suspended, its keys stop working.