Create a service account.
Synopsis
Create a service account and issue its first client secret.
The secret is shown only once; save it immediately.
Exchange the client ID and secret for a 1-hour access token at POST /api/v1/oauth/token. Send that token only to endpoints explicitly enabled for service-account authentication and that the assigned role allows:
curl --fail-with-body --silent --show-error --user ‘’ --data grant_type=client_credentials ‘/api/v1/oauth/token’ \| jq -er ‘“Authorization: Bearer” + .access_token’ \| curl --fail-with-body --silent --show-error --header @- ‘/api/v1/’
Project roles are PROJECT_OWNER, PROJECT_READ_ONLY, or AGENT_DEVELOPER; organization roles are ORG_GROUP_CREATOR or ORG_READ_ONLY. List and get display the stored Agent Engine role: PROJECT_READ_ONLY stores as PROJECT_MEMBER, and ORG_GROUP_CREATOR stores as ORG_ADMIN and pairs as Atlas Organization Project Creator. AGENT_DEVELOPER has no Atlas equivalent; it can invoke, build, and deploy agents. Legacy names PROJECT_MEMBER, ORG_ADMIN, and ORG_MEMBER are accepted, and print a deprecation warning.
Examples:
agentengine service-account create ci-pipeline --role AGENT_DEVELOPER agentengine service-account create audit-reader --org-id --role ORG_READ_ONLY
agentengine service-account create <name> --role <role> [flags]
Options
--base-url string Platform base URL --context string Named context to target (see 'agentengine context list') --description string Human-readable description -h, --help help for create --ip-access-list strings IPs or CIDRs allowed to use the credential (default: unrestricted) --json Output the created service account as JSON --org-id string Organization scope for the service account --project-id string Project scope for the service account --role string Role granted to the service account (project: PROJECT_OWNER, PROJECT_READ_ONLY, AGENT_DEVELOPER; organization: ORG_GROUP_CREATOR, ORG_READ_ONLY). Legacy names PROJECT_MEMBER, ORG_ADMIN, and ORG_MEMBER still work and print a deprecation warning. --secret-expires-in duration Secret lifetime as a whole number of hours, e.g. 720h (default: server default of 2160h)
Options inherited from parent commands
--log-file string override log file path --log-level string file log verbosity (error|warn|info|debug) (default "info") --no-log disable file logging -q, --quiet silence stderr below error -v, --verbose count raise stderr verbosity (-v info, -vv debug)
SEE ALSO
- agentengine service-account - Manage service accounts.