Skip to main content

Schema introspection

Every command below with arguments supports two read-only flags for tooling and AI agents:
  • --show-file-schema: print the JSON Schema for the full request object (the format --filename accepts).
  • --show-argument-schema <flag-name>: print the JSON Schema for one argument’s value. Pass the kebab flag name without the leading -- (e.g. project-id, not --project-id).
Both write pure JSON to stdout and never call the API. They cannot be combined with any other command-specific flag.

create

Create a data plane API key Create a fine-grained data plane API key rooted at a project. The caller’s key must carry project.fine_grained_api_key_dp.post for the project. Only an organization-rooted key created in the organization’s Settings → API Keys, on the Data Plane tab, can carry it, and a key created through this operation never can, so a provisioned key cannot create keys. The permissions requested are limited to the organization’s data plane key policy, and expires_at to the system’s maximum lifetime. The project must already exist on this data plane: a project created on the control plane reaches it asynchronously, and the operation answers 404 until it does. key_value is returned once and cannot be retrieved again.

Usage

Options

Also supports --show-file-schema, --show-argument-schema <flag-name>, and --filename. See Schema introspection for details.