watsonx Orchestrate

 View Only

 Trouble finding orchestrate resource in IBM Cloud

Jump to  Best Answer
Joseph Boppell's profile image
Joseph Boppell posted 06/17/26 10:06 AM

Someone on my team invited me to their 30-day orchestrate trial. I was setting up the orchestrate ADK in my CLI and it asked me for my WXO API Key. So, I went to the orchestrate settings and generated an API Key and pasted that, but I got a 400 error. On the ADK setup guide, clicking "Generate API Key" in the orchestrate settings brings you to your IBM Cloud account to create an API Key in the IAM management. However, it just gave me an API Key right away without bringing me to IBM Cloud. When I went to my IAM management in IBM Cloud and created an API Key, I then got a 500 error when using it in the CLI. I then noticed that this orchestrate instance wasn't listed in my resources on IBM Cloud, which is why the API Key didn't work.

How do I have access to orchestrate without it being available in my resources? I'm using the same account on both platforms, so it doesn't make sense.

Any help is appreciated. Thanks

Harold Bergeron's profile image
Harold Bergeron  Best Answer

Hi Joseph,

Good news: your last sentence is actually the diagnosis. Two things are
tangled together here.

1) Wrong key type (your 400). The key that popped up immediately in
Orchestrate Settings is the WxO instance service credential, meant for
calling the WxO REST APIs directly. It is NOT an IBM Cloud IAM key, and the
ADK CLI won't accept it for `env activate`. The ADK wants an IBM Cloud IAM
API key (IBM Cloud > Manage > Access (IAM) > API keys) — which is why the
setup guide sends you there.

2) The real blocker (your 500, and the instance missing from your
resources). You were invited to someone else's 30-day trial, so that
Orchestrate instance lives in THEIR IBM Cloud account, not yours. Being
invited as a user inside the Orchestrate app is not the same as having IBM
Cloud (IAM) access to the underlying instance. So an IAM key you create in
your account authenticates as you, but you have no IAM access to an instance
that sits in their account -> 500, and it never shows in your resource list.
"Same account on both platforms" is the trap: your web login is via the
invite, but the resource is in the inviter's account.

How to fix it, pick one:
- Easiest: have the person who created the trial run the ADK setup / generate
  the IAM key from the account that owns the instance.
- Or have them grant your IBM Cloud identity IAM access to the instance's
  resource group (then it'll show in your resources and your IAM key works).
- Or, for a clean setup of your own, start your own Orchestrate trial under
  your own IBM Cloud account — then the instance is yours, the IAM key
  matches, and the ADK activates with no drama.

When you do activate, make sure the instance URL/region in your ADK env
config matches where that instance actually lives.

Quick confirm: in IBM Cloud, check the Resource list for the account you're
keyed into. If the Orchestrate instance isn't there, options 1 or 2 are your
path.