Service Accounts (Recommended)
Service accounts provide passwordless CI/CD integration. See the Service Accounts guide for full details.1
Create a service account
2
Set the environment variable
3
Run with secrets
GitHub Actions
The
id-token: write permission is required if you configured OIDC on your service account.
Without OIDC, it can be omitted.GitLab CI
Other Providers
Relic works with any CI/CD provider that supports environment variables. The pattern is always the same:- Install Relic (
bun add -g relicornpm install -g relic) - Set
RELIC_SERVICE_TOKENin your pipeline environment - Run
relic run -e <environment> -- <your command>
OIDC Trust Policies
For additional security, add OIDC trust policies to your service accounts. This verifies the CI platform’s identity so the service token only works from trusted environments. See the OIDC Trust Policies guide for details.API Keys (Legacy)
API keys still work but require two environment variables (RELIC_API_KEY + RELIC_PASSWORD) and expose your master password to the CI environment. To use API keys:
Scope Filtering
Use--scope to inject only a subset of secrets:
Folder Filtering
Use--folder to inject secrets from a specific folder:
Security Considerations
- API keys can be revoked from the web dashboard at any time
- Each API key has scoped permissions (
secrets.read,user.keys.read) - API keys can be scoped to a specific project, restricting access to only that project’s secrets
- All API keys require an expiration date (maximum 365 days)
- API key usage is logged in the audit trail
- The master password is used only for decryption and is never sent to the Relic server