Manage service accounts.
Synopsis
Manage service accounts, the programmatic identities that call the platform.
A service account is scoped to an organization or a project and is identified by a client ID and secret.
Exchange the client ID and secret for a 1-hour access token at POST /api/v1/oauth/token. Send that token only to endpoints explicitly enabled for service-account authentication and that the assigned role allows:
curl --fail-with-body --silent --show-error --user ‘’ --data grant_type=client_credentials ‘/api/v1/oauth/token’ \| jq -er ‘“Authorization: Bearer” + .access_token’ \| curl --fail-with-body --silent --show-error --header @- ‘/api/v1/’
The create and rotate commands print safe curl examples for both steps.
Options
-h, --help help for service-account
Options inherited from parent commands
--log-file string override log file path --log-level string file log verbosity (error|warn|info|debug) (default "info") --no-log disable file logging -q, --quiet silence stderr below error -v, --verbose count raise stderr verbosity (-v info, -vv debug)
SEE ALSO
agentengine - Agent Engine local development CLI.
agentengine service-account create - Create a service account.
agentengine service-account delete - Deactivate a service account.
agentengine service-account get - Show service account details.
agentengine service-account list - List service accounts.
agentengine service-account rotate - Issue a new secret for a service account.