Skip to content

Authentication

Send a token in the Authorization header with every request:

Authorization: Bearer <token>

Use a service account key for scripts, CI, and anything else that runs without you. A key belongs to one project and only works there.

Create a service account with a key in your current project:

Terminal window
enumctl sa create ci --key ci --print-token-only

The token starts with enum_sk_ and is shown only once. Keys expire after 90 days by default. Pass --expires-in, --expires-at, or --no-expiry to change that.

Add a key to an existing service account, for example to rotate it:

Terminal window
enumctl sa keys create <service-account-id> --name ci-2 --print-token-only

Revoke a key:

Terminal window
enumctl sa keys delete <api-key-id>

Service accounts cannot create organizations or projects, and cannot manage service accounts or keys.

CodeHTTP statusMeaning
unauthenticated401The token is missing, invalid, or expired
permission_denied403The token is valid but has no access to the project or method