For developers integrating marketplaces, the CLI is the fastest way to generate initial API keys after bootstrapping your Orchestrator instance. Install it, run offerhub keys create, and you have a usable API key in seconds.
Install and use the @offerhub/cli to manage API keys, inspect configuration, and understand CLI capabilities and API availability.
The @offerhub/cli package provides a command-line interface for managing the OFFER-HUB Orchestrator. It offers rapid configuration inspection and API key creation from the terminal without writing raw curl commands.
For developers integrating marketplaces, the CLI is the fastest way to generate initial API keys after bootstrapping your Orchestrator instance. Install it, run offerhub keys create, and you have a usable API key in seconds.
The CLI registers a single binary: offerhub.
The CLI resolves its connection settings from three sources, evaluated in strict priority order (packages/cli/src/utils/config.ts:loadConfig):
| Priority | Source | Details |
|---|---|---|
| 1 | Environment variables | OFFERHUB_API_URL and OFFERHUB_API_KEY in the current shell environment |
| 2 | .env file | .env file in the current working directory (loaded via dotenv) |
| 3 | Global config file | ~/.offerhub/config.json |
~/.offerhub/config.json)You can save default connection settings to ~/.offerhub/config.json so you do not need to export environment variables in every shell session.
offerhub config setConfigure connection settings interactively or non-interactively via flags.
| Option | Type | Description |
|---|---|---|
--api-url <url> | String | Orchestrator API base URL (default: http://localhost:3000 interactively) |
--api-key <key> | String | Master key or administrative API key |
When run interactively in crypto mode, the wizard also generates and displays a random 32-byte hex WALLET_ENCRYPTION_KEY suitable for your Orchestrator .env.
offerhub config showDisplays the active configuration (API URL, masked key, payment provider, and file path of ~/.offerhub/config.json).
offerhub config showOutput:
offerhub keys listList all API keys stored in the Orchestrator database.
| Option | Description | API Availability |
|---|---|---|
-u, --user-id <userId> | Filter keys by user ID | Not supported in API. AuthController.listApiKeys (apps/api/src/modules/auth/auth.controller.ts:36-47) only accepts pagination parameters (limit, cursor). API keys are platform/tenant-level credentials rather than per-user keys. The --user-id flag is ignored by the backend. |
Output:
offerhub keys createCreate a new API key. Runs interactively if flags are omitted.
| Option | Description | API Availability |
|---|---|---|
-s, --scopes <scopes> | Comma-separated scopes: read, write, support (or domain scopes: orders, users, balance) | Supported. Validated by ScopeGuard on the Orchestrator API (apps/api/src/modules/auth/auth.controller.ts:27). |
-n, --name <name> | Key name or descriptive label | Supported. Persisted in the ApiKey database model. |
-u, --user-id <userId> | User ID prompt / flag | Not supported in API. The backend endpoint POST /auth/api-keys binds only name and scopes. API keys belong to the marketplace integration, not to individual end users. |
The plaintext API key (ohk_...) is returned only once at creation time. The Orchestrator stores a cryptographic hash (bcrypt) with salt in the database. Copy the key immediately — it cannot be recovered later.
offerhub keys revoke <keyId> Unavailable in APIThe CLI provides a revoke command to revoke an API key by ID:
Backend route not implemented: offerhub keys revoke sends DELETE /auth/api-keys/:id (packages/cli/src/commands/keys.ts:179). However, DELETE /auth/api-keys/:id does not currently exist in the Orchestrator API (apps/api/src/modules/auth/auth.controller.ts). Running this command returns an HTTP 404 error.
To revoke an API key in current releases, delete or deactivate the corresponding row directly in the PostgreSQL ApiKey table or rotate credentials.
offerhub keys token <keyId>Generate a short-lived token (ohk_tok_...) from an existing API key for temporary frontend or delegate sessions (POST /auth/api-keys/:id/token).
| Option | Description | Behavior |
|---|---|---|
-t, --ttl <seconds> | Requested token TTL in seconds | Fixed at 1 hour (3600s). The Orchestrator backend (apps/api/src/modules/auth/auth.service.ts:58-60) hardcodes token expiration to expiresIn: '1h'. The --ttl flag has no effect on server-side token lifetime. |
Output:
The CLI exposes three commands intended for managing Orchestrator maintenance mode:
offerhub maintenance enableofferhub maintenance disableofferhub maintenance statusBackend routes not implemented: These commands dispatch requests to admin/maintenance/enable, admin/maintenance/disable, and admin/maintenance/status (packages/cli/src/commands/maintenance.ts). However, no maintenance controller or routes exist in the Orchestrator API (apps/api/src/modules). Executing any maintenance command will fail with an HTTP 404 route error.
After provisioning the Orchestrator using the Scaffolder, configure the CLI and create an API key:
To authenticate client requests without exposing the long-lived master or production API key, generate a short-lived 1-hour session token:
Use the returned ohk_tok_... token in the Authorization: Bearer ohk_tok_... header for client requests.
If configuration is missing when running any command, the CLI provides clear instructions:
create-offer-hub-orchestrator)