1. Introduction to Programmatic Authentication
While human users log into the OCI Web Console using a username, password, and MFA factor, automated applications, scripts, CLI tools, and microservices require programmatic authentication mechanisms.
Oracle Cloud Infrastructure (OCI) provides three primary non-interactive credential types:
- API Signing Keys: RSA 2048-bit key pairs used by the OCI CLI, SDKs, and Terraform provider to sign HTTPS requests.
- Auth Tokens: Oracle-generated secret strings used as passwords for legacy protocol authentication (such as Docker CLI logins to OCIR or Git repository access).
- OAuth2 Client Credentials: Industry-standard OAuth2 tokens used for headless microservice-to-microservice authentication inside OCI Identity Domains.
2. Technical Comparison of Programmatic Credentials
| Credential Type | Primary Target Protocols / Tools | Generation Method | Secret Storage Rules |
|---|---|---|---|
| API Signing Key | OCI CLI, Python/Go/Java SDKs, OCI PowerShell | User uploads RSA 2048-bit public key to OCI Console; signs local API requests using private key | Private key stored securely on client machine; public key fingerprint registered in OCI |
| Auth Token | Docker CLI (docker login to OCIR), Git over HTTPS, Database Cloud Backup | Auto-generated by OCI Console GUI upon request | Displayed ONCE only upon creation; must be saved immediately to password vault |
| OAuth2 Client | Headless microservices, REST APIs, Identity Domain Apps | Provisioned via Identity Domain App Registration (Client ID + Client Secret) | Client secret managed via OAuth2 token exchange endpoints |
[!IMPORTANT]
API Key Fingerprint Validation
When an SDK or CLI executes an API request, OCI validates the HTTP request signature against the fingerprint of the public API signing key uploaded to the user’s profile. If the local private key does not match the uploaded public key fingerprint, OCI returns401 NotAuthenticated.
3. OCI Web Console (GUI) Step-by-Step Walkthrough
Generating API Keys and Auth Tokens is executed directly within the OCI Web Console GUI.
Step 1: Uploading an API Signing Key in the Console
- Generate an RSA 2048-bit key pair on your local workstation using OpenSSL:
bash
openssl genrsa -out ~/.oci/oci_api_key.pem 2048
openssl rsa -pubout -in ~/.oci/oci_api_key.pem -out ~/.oci/oci_api_key_public.pem - Log in to the Oracle Cloud Console (
https://cloud.oracle.com). - Click the Profile Icon in the top-right corner ➔ Click User Settings.
- Scroll down to Resources in the left panel ➔ Click API Keys.
- Click Add API Key.
- Select Choose Public Key File ➔ Upload
oci_api_key_public.pem. - Click Add.
- OCI displays the generated Configuration File Preview containing your User OCID, Tenancy OCID, Fingerprint, and Home Region. Copy these values to your local
~/.oci/configfile.
Step 2: Generating an Auth Token for Docker CLI (OCIR)
- On the User Settings page, click Auth Tokens under Resources.
- Click Generate Token.
- Enter a description:
OCIR-Docker-Login-Token. - Click Generate Token.
- Copy the generated secret string immediately.
Action Warning: Copy this token now. You won't be able to see it again!
- Use the Auth Token as your password when logging into Oracle Cloud Infrastructure Registry via Docker CLI:
bash
docker login iad.ocir.io -u 'tenancy-namespace/username'
4. Common Architectural Misconceptions & Pitfalls
Misconception 1: “A User Account Can Have Unlimited Active API Keys”
- Reality: OCI enforces a hard limit of maximum 2 active API Signing Keys per user account. To rotate API keys, upload a second key, update application config files to use the new fingerprint, and delete the old key.
Misconception 2: “Auth Tokens Can Be Retrieved Later in the OCI Console if Lost”
- Reality: Auth Tokens are displayed exactly once at the time of creation. If an Auth Token string is lost, it cannot be recovered from OCI; it must be deleted and regenerated.
5. OCI Credentials vs. Google Cloud (GCP) Credentials
For cloud architects familiar with Google Cloud, the following table compares programmatic authentication:
| Credential Feature | Google Cloud (GCP) | Oracle Cloud Infrastructure (OCI) | Key Technical Difference |
|---|---|---|---|
| CLI / SDK Signing | GCP Service Account JSON Key Files | API Signing Keys (RSA 2048-bit Public Key uploaded to User Profile) | OCI uses asymmetric RSA HTTP signing; GCP uses downloadable service account JSON private keys. |
| Container Registry Passwords | GCP Artifact Registry OAuth2 Tokens | Auth Tokens generated in User Profile GUI | OCI Auth Tokens act as static passwords for third-party tools like Docker CLI. |
| Max Key Count | 10 keys per Service Account | 2 API Signing Keys per User Account | OCI enforces strict key rotation boundaries per user account. |

