Reference
Cloud commands authenticate only with the WorkOS session created by helix auth login.
They never accept or store application database keys or service credentials.
push, sync, auth create-key, workspace switch, and project update are not commands.
Cloud resource lifecycle is exposed only where documented above.