---
title: "Get a kubeconfig"
method: GET
path: "/v1/kubernetes/clusters/{id}/kubeconfig"
tags: ["Kubernetes"]
---

# Get a kubeconfig

`GET /v1/kubernetes/clusters/{id}/kubeconfig`

A kubeconfig for this cluster with a freshly minted cluster token embedded, the same kind of token createKubernetesClusterToken returns. It holds no client certificate, and it stops working when the token expires after one hour. `orl kube kubeconfig` writes one that keeps working: it holds no token and runs `orl kube token` for each kubectl request. A cluster that is deleting or failed answers 409 INVALID_CLUSTER_STATE, and so does a cluster that is creating until its control plane's certificate authority exists. A restricted or pending organization can still get one. Needs clusters:write on an API key, or the owner, admin or member role on a session.

## Path parameters

- `id` string, required

## Response `200`

The kubeconfig

- KubernetesKubeconfig
  - `expiresAt` string, required — When the embedded token expires (RFC 3339).
  - `kubeconfig` string, required — The kubeconfig document (YAML), ready to save as a file. Its server is https://<id>.k8s.<zone>:6443 and it embeds a cluster token, never a client certificate.
  - `role` 'cluster-admin' | 'view', required — The in-cluster role the embedded token carries.
  - `ttlSeconds` integer, required — The token's lifetime from when it was minted.

## Other responses

- `401` — Missing or invalid API key
- `403` — The caller is authenticated but may not do this. As on every operation, the caller's role or the API key's scope does not allow it, or the request targets another organization (FORBIDDEN, or NOT_A_MEMBER for a session), or the organization is suspended pending review (ORG_SUSPENDED) or has been deleted (ORG_DISABLED). This operation can also be refused because of the account. A new workload (a VM or pod create, a VM fork, a Kubernetes cluster or node pool create, a node pool scaled up) answers INSUFFICIENT_BALANCE, ACCOUNT_RESTRICTED or ACCOUNT_PENDING_VERIFICATION; a restart or reboot answers INSUFFICIENT_BALANCE; an API key create answers ACCOUNT_RESTRICTED or ACCOUNT_PENDING_VERIFICATION; a deposit or card save answers ACCOUNT_PENDING_VERIFICATION, VERIFICATION_UNAVAILABLE or FUNDING_UNDER_REVIEW; and a runner pool create answers ACCOUNT_PENDING_VERIFICATION. Every gate also answers ACCOUNT_SUSPENDED for a suspended organization, but only platform admins and internal callers reach it: a customer's request for a suspended organization is refused at authentication with ORG_SUSPENDED before it gets to a gate. A new API key or a wider scope clears none of these; see [Account and balance refusals](https://docs.openrelay.inc/docs/errors#account-and-balance-refusals) for what each one means and what to do.
- `404` — Resource not found
- `409` — The request conflicts with existing state

## Changes

- **2026-10-03** `bcf63adad2c3` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/openrelay/apis/openrelay-api/changes/v1/kubernetes/clusters/:id/kubeconfig/get.md)

---

[API](https://skmtc.dev/openrelay/apis/openrelay-api.md) · [All operations](https://skmtc.dev/openrelay/apis/openrelay-api/llms.txt) · [OpenAPI document](https://skmtc.dev/openrelay/apis/openrelay-api/revisions/bcf63adad2c3?raw)
