Issue a new secret for a service account.
Synopsis
Issue a new client secret for a service account.
The new secret is shown only once. The previous secret keeps authenticating for up to 7 days, or until it expires if sooner; rotating again ends its grace period immediately.
Exchange the client ID and secret for a 1-hour access token at POST /api/v1/oauth/token. Send that token only to endpoints explicitly enabled for service-account authentication and that the assigned role allows:
curl --fail-with-body --silent --show-error --user ‘’ --data grant_type=client_credentials ‘/api/v1/oauth/token’ \| jq -er ‘“Authorization: Bearer” + .access_token’ \| curl --fail-with-body --silent --show-error --header @- ‘/api/v1/’
agentengine service-account rotate <client-id> [flags]
Options
--base-url string Platform base URL --context string Named context to target (see 'agentengine context list') -h, --help help for rotate --json Output the rotated service account as JSON --org-id string Organization scope for the service account --project-id string Project scope for the service account --secret-expires-in duration Secret lifetime as a whole number of hours, e.g. 720h (default: server default of 2160h)
Options inherited from parent commands
--log-file string override log file path --log-level string file log verbosity (error|warn|info|debug) (default "info") --no-log disable file logging -q, --quiet silence stderr below error -v, --verbose count raise stderr verbosity (-v info, -vv debug)
SEE ALSO
- agentengine service-account - Manage service accounts.