For AI agents: a documentation index is available at https://www.mongodb.com/docs/llms.txt — markdown versions of all pages are available by appending .md to any URL path.
Docs Menu

agentengine service-account create

Create a service account.

Create a service account and issue its first client secret.

The secret is shown only once; save it immediately.

Exchange the client ID and secret for a 1-hour access token at POST /api/v1/oauth/token. Send that token only to endpoints explicitly enabled for service-account authentication and that the assigned role allows:

curl --fail-with-body --silent --show-error
--user ‘’
--data grant_type=client_credentials
‘/api/v1/oauth/token’ \|
jq -er ‘“Authorization: Bearer” + .access_token’ \|
curl --fail-with-body --silent --show-error
--header @-
‘/api/v1/’

Project roles are PROJECT_OWNER, PROJECT_READ_ONLY, or AGENT_DEVELOPER; organization roles are ORG_GROUP_CREATOR or ORG_READ_ONLY. List and get display the stored Agent Engine role: PROJECT_READ_ONLY stores as PROJECT_MEMBER, and ORG_GROUP_CREATOR stores as ORG_ADMIN and pairs as Atlas Organization Project Creator. AGENT_DEVELOPER has no Atlas equivalent; it can invoke, build, and deploy agents. Legacy names PROJECT_MEMBER, ORG_ADMIN, and ORG_MEMBER are accepted, and print a deprecation warning.

Examples:

agentengine service-account create ci-pipeline --role
AGENT_DEVELOPER agentengine service-account create audit-reader --org-id --role ORG_READ_ONLY
agentengine service-account create <name> --role <role> [flags]
--base-url string Platform base URL
--context string Named context to target (see 'agentengine context list')
--description string Human-readable description
-h, --help help for create
--ip-access-list strings IPs or CIDRs allowed to use the credential (default: unrestricted)
--json Output the created service account as JSON
--org-id string Organization scope for the service account
--project-id string Project scope for the service account
--role string Role granted to the service account (project: PROJECT_OWNER, PROJECT_READ_ONLY, AGENT_DEVELOPER; organization: ORG_GROUP_CREATOR, ORG_READ_ONLY). Legacy names PROJECT_MEMBER, ORG_ADMIN, and ORG_MEMBER still work and print a deprecation warning.
--secret-expires-in duration Secret lifetime as a whole number of hours, e.g. 720h (default: server default of 2160h)
--log-file string override log file path
--log-level string file log verbosity (error|warn|info|debug) (default "info")
--no-log disable file logging
-q, --quiet silence stderr below error
-v, --verbose count raise stderr verbosity (-v info, -vv debug)
Rate this page