--- title: "Authentication" canonical: "https://admiral.io/docs/access" description: "Sign in to Admiral in the console or the CLI, and use a personal or service account API key, bounded by scopes, for scripts and CI." --- # Authentication Admiral is hosted, so authentication has two sides: how *people* sign in through the console or the CLI, and how *machines* (CI and automation) authenticate to the API. This page explains both. There is no identity provider for you to install or configure, because that is part of the managed service. ## Signing in [#signing-in] You sign in to the console through your identity, and the CLI signs in the same way: ```bash admiral auth login ``` `admiral auth login` opens a browser to complete sign-in, then stores a session so subsequent commands are authenticated. Your session is maintained by Admiral Cloud with configurable idle and absolute lifetimes. ## Token types [#token-types] For anything non-interactive you use an API key. Admiral issues two kinds, for two different access patterns. ### Personal API keys [#personal-api-keys] * Scoped to an individual user. * Created in the console. * Used for CLI access and API calls on your behalf. * Act with your permissions, limited to the scopes the key was created with. Use a personal API key for local scripting and one-off automation that acts as you. A key stops working when its owner leaves the organization. ### Service account API keys [#service-account-api-keys] * Scoped to a service identity, not a person. * Created in the console or through the API. * Used by machines, such as CI pipelines. * Do not vanish when a person leaves. Use a service account API key for CI. An agent does not use an API key. Admiral trusts its cluster instead, see [Agents](https://admiral.io/docs/agents.md#how-does-an-agent-prove-who-it-is). ## Scopes [#scopes] API keys carry scopes that bound what they can do (for example, `catalog:read` versus `catalog:write`). Grant the narrowest scope that fits the job, especially for a service account key that lives in CI. A personal key for Terraform is limited to the Terraform API, which serves [hosted state](https://admiral.io/docs/concepts/state.md). ## Rotating and revoking [#rotating-and-revoking] Treat an API key like any other secret. Rotate service account keys on a schedule, and revoke any key that may be exposed. A revoked key stops authenticating immediately. ## Where to go next [#where-to-go-next] * [Agents & Execution](https://admiral.io/docs/agents.md): How an agent proves who it is without an API key