Creates an org-scoped customer service account and returns its secret once. roles is required and accepts at most one non-blank name: ORG_GROUP_CREATOR or ORG_READ_ONLY. Legacy Agent Engine names (ORG_ADMIN, ORG_MEMBER) are still accepted. role_assignments echoes the stored Agent Engine role. Requires ORG_ADMIN.
Body
Required
Create request
-
Maximum length is
500. -
Optional IP/CIDR allowlist. Empty or omitted means unrestricted. At most 100 entries.
Not more than
100elements. -
Maximum length is
100. -
Roles is the initial role set. Exactly one role is required. Organization accounts accept ORG_GROUP_CREATOR or ORG_READ_ONLY. Project accounts accept PROJECT_OWNER, PROJECT_READ_ONLY, or AGENT_DEVELOPER. Legacy Agent Engine names (ORG_ADMIN, ORG_MEMBER, PROJECT_MEMBER) are still accepted. role_assignments echoes the stored Agent Engine role those names resolve to.
At least
1but not more than1element. -
Optional secret TTL in hours. Defaults to 2160 (90 days) when omitted.
Responses
-
Unsupported or malformed API version, an operation unavailable in the selected published contract, or an unacceptable representation (including unsupported media-type parameters or excluded SSE). Existing authentication, authorization, and rate-limit failures take precedence.
-
Created
-
Bad Request
-
Forbidden
-
Not Found
-
Conflict
-
Too Many Requests
-
Internal Server Error
-
Service Unavailable
curl \
--request POST 'https://agentengine.mongodb.com/api/v1/organizations/{id}/service-accounts' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--data '{
"description": "string",
"ip_access_list": [
"string"
],
"name": "string",
"roles": [
"string"
],
"secret_expires_after_hours": 42
}'
{
"description": "string",
"ip_access_list": [
"string"
],
"name": "string",
"roles": [
"string"
],
"secret_expires_after_hours": 42
}
{
"detail": "This operation is not available in API version 2026-09-20-preview.",
"error": 406,
"errorCode": "OPERATION_NOT_IN_API_VERSION",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"detail": "This operation supports text/event-stream, which the Accept header excludes. Remove unsupported media-type parameters or accept this type with a positive q value.",
"error": 406,
"errorCode": "UNACCEPTABLE_MEDIA_TYPE",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"detail": "The requested API version is not supported. Supported versions: 2026-09-20-preview.",
"error": 406,
"errorCode": "UNSUPPORTED_API_VERSION",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"detail": "This operation is not available in API version 2026-09-20-preview.",
"error": 406,
"errorCode": "OPERATION_NOT_IN_API_VERSION",
"parameters": [
"Accept"
],
"reason": "Not Acceptable"
}
{
"client_secret": "string",
"service_account": {
"active_secret": {
"created_at": "string",
"expires_at": "string",
"last_used_at": "string",
"masked_value": "string"
},
"client_id": "string",
"created_at": "string",
"description": "string",
"id": "string",
"ip_access_list": [
"string"
],
"is_active": true,
"is_system_managed": true,
"name": "string",
"org_id": "string",
"owner": "string",
"project_id": "string",
"role_assignments": [
{
"org_id": "string",
"project_id": "string",
"role": "string"
}
],
"type": "string",
"updated_at": "string"
}
}
{
"client_secret": "string",
"service_account": {
"active_secret": {
"created_at": "string",
"expires_at": "string",
"last_used_at": "string",
"masked_value": "string"
},
"client_id": "string",
"created_at": "string",
"description": "string",
"id": "string",
"ip_access_list": [
"string"
],
"is_active": true,
"is_system_managed": true,
"name": "string",
"org_id": "string",
"owner": "string",
"project_id": "string",
"role_assignments": [
{
"org_id": "string",
"project_id": "string",
"role": "string"
}
],
"type": "string",
"updated_at": "string"
}
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
# Headers
Retry-After: string
# Payload
{
"code": "string",
"error": "string",
"success": true
}
# Headers
Retry-After: string
# Payload
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
{
"code": "string",
"error": "string",
"success": true
}
# Headers
Retry-After: string
# Payload
{
"code": "string",
"error": "string",
"success": true
}
# Headers
Retry-After: string
# Payload
{
"code": "string",
"error": "string",
"success": true
}