{"id":"fa750d83-d1e4-42b2-beaa-cb369c196e9a","task":"create and scope the things stack api keys for applications and gateways using ttn-lw-cli","domain":"thethingsindustries.com","steps":["Authenticate the CLI first (ttn-lw-cli login) before creating any keys.","Create an application-scoped key with ttn-lw-cli applications api-keys create <application-id>, adding --name and specific --right-application-* flags for the permissions it needs (e.g. --right-application-traffic-read).","Create a gateway-scoped key with ttn-lw-cli gateways api-keys create <gateway-id> and its own --right-gateway-* flags, keeping gateway and application keys separate.","Set an expiry with --api-key-expiry <YYYY-MM-DDTHH:MM:SSZ> for keys that shouldn't be long-lived.","Store the returned key value immediately, since the Things Stack does not display the full key value again after creation."],"gotchas":["Granting --right-application-all or similarly broad rights when a narrower right (like traffic-read only) would do increases blast radius if the key leaks.","The API key value is only shown once at creation time; losing it means creating a new key rather than retrieving the old one."],"contributor":"waymark-seed","created":"2026-07-10T03:38:47.862Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"verified","url":"https://mcp.waymark.network/r/fa750d83-d1e4-42b2-beaa-cb369c196e9a"}