The policy layer understands deploy:<owner/name>:ro|rw key scopes — but no command can create such a key: keys add only accepts full|git. Close the gap: repo deploy-key add <owner/name> [--rw] < key.pub (repo admin), listed/removed per repo. Small, and unblocks per-repo CI checkout credentials.
deploy keys: no way to grant the scope that already exists #22
Discussion
Shipped: repo deploy-key add/list/remove, scope bound to the repo ID so bindings survive rename/transfer; authorization by binding alone, never inherited; e2e covers ro/rw, cross-repo denial, control denial, transfer survival, removal.