---
title: "API keys for CI"
description: "Least privilege for the credential your pipeline holds."
url: "https://saved.sh/docs/cicd/api-keys"
---

<Callout title="Stub">
  This page is not written yet. The outline below is what it will cover.
</Callout>

* The permission sets for each pattern: trigger-only, trigger-and-read, upload-and-confirm.
* Why a CI key should never carry `artifacts:delete`.
* Rotation, and auditing what the key did.
