# Create org service account **POST /api/v1/organizations/{id}/service-accounts** Creates an org-scoped customer service account and returns its secret once. roles is required and accepts at most one non-blank name: ORG_GROUP_CREATOR or ORG_READ_ONLY. Legacy Agent Engine names (ORG_ADMIN, ORG_MEMBER) are still accepted. role_assignments echoes the stored Agent Engine role. Requires ORG_ADMIN. ## Servers - https://agentengine.mongodb.com: https://agentengine.mongodb.com () ## Authentication methods - Bearer auth ## Parameters ### Path parameters - **id** (string) Organization ID ### Body: application/json (object) Create request - **description** (string) - **ip_access_list** (array[string]) Optional IP/CIDR allowlist. Empty or omitted means unrestricted. At most 100 entries. - **name** (string) - **roles** (array[string]) Roles is the initial role set. Exactly one role is required. Organization accounts accept ORG_GROUP_CREATOR or ORG_READ_ONLY. Project accounts accept PROJECT_OWNER, PROJECT_READ_ONLY, or AGENT_DEVELOPER. Legacy Agent Engine names (ORG_ADMIN, ORG_MEMBER, PROJECT_MEMBER) are still accepted. role_assignments echoes the stored Agent Engine role those names resolve to. - **secret_expires_after_hours** (integer) Optional secret TTL in hours. Defaults to 2160 (90 days) when omitted. ## Responses ### 406 Unsupported or malformed API version, an operation unavailable in the selected published contract, or an unacceptable representation (including unsupported media-type parameters or excluded SSE). Existing authentication, authorization, and rate-limit failures take precedence. #### Body: application/json (object) - **badRequestDetail** (object) Optional validation details defined by the standard error schema; API negotiation errors do not emit this field. - **detail** (string) Human-readable error details. - **error** (integer) HTTP status code. - **errorCode** (string) Machine-readable error code. - **parameters** (array[string]) Request parameter names associated with the error; omitted when none apply. - **reason** (string) HTTP status reason phrase. ### 201 Created #### Body: application/json (object) - **client_secret** (string) - **service_account** (object) ### 400 Bad Request #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) ### 403 Forbidden #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) ### 404 Not Found #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) ### 409 Conflict #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) ### 429 Too Many Requests #### Headers - **Retry-After** (string) Seconds to wait before retrying #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) ### 500 Internal Server Error #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) ### 503 Service Unavailable #### Headers - **Retry-After** (string) Seconds to wait before retrying #### Body: application/json (object) - **code** (string) - **error** (string) - **success** (boolean) [Powered by Bump.sh](https://bump.sh)