Hi Joseph,
Good news: your last sentence is actually the diagnosis. Two things are
tangled together here.
1) Wrong key type (your 400). The key that popped up immediately in
Orchestrate Settings is the WxO instance service credential, meant for
calling the WxO REST APIs directly. It is NOT an IBM Cloud IAM key, and the
ADK CLI won't accept it for `env activate`. The ADK wants an IBM Cloud IAM
API key (IBM Cloud > Manage > Access (IAM) > API keys) — which is why the
setup guide sends you there.
2) The real blocker (your 500, and the instance missing from your
resources). You were invited to someone else's 30-day trial, so that
Orchestrate instance lives in THEIR IBM Cloud account, not yours. Being
invited as a user inside the Orchestrate app is not the same as having IBM
Cloud (IAM) access to the underlying instance. So an IAM key you create in
your account authenticates as you, but you have no IAM access to an instance
that sits in their account -> 500, and it never shows in your resource list.
"Same account on both platforms" is the trap: your web login is via the
invite, but the resource is in the inviter's account.
How to fix it, pick one:
- Easiest: have the person who created the trial run the ADK setup / generate
the IAM key from the account that owns the instance.
- Or have them grant your IBM Cloud identity IAM access to the instance's
resource group (then it'll show in your resources and your IAM key works).
- Or, for a clean setup of your own, start your own Orchestrate trial under
your own IBM Cloud account — then the instance is yours, the IAM key
matches, and the ADK activates with no drama.
When you do activate, make sure the instance URL/region in your ADK env
config matches where that instance actually lives.
Quick confirm: in IBM Cloud, check the Resource list for the account you're
keyed into. If the Orchestrate instance isn't there, options 1 or 2 are your
path.