> ## Documentation Index
> Fetch the complete documentation index at: https://cerebrium-kyle-phase0-docs-fixes.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Cerebrium's documentation MCP server is available at https://cerebrium.ai/docs/mcp for searching and querying these docs directly. Install the Cerebrium agent skill with `npx skills add https://cerebrium.ai/docs`. Append .md to any docs page URL to fetch that page as plain Markdown. API keys and authentication tokens are created in the Cerebrium dashboard at https://dashboard.cerebrium.ai.

# Create Service Account

> Create a new service account for a project.



## OpenAPI

````yaml https://s3.eu-west-1.amazonaws.com/www.cerebrium.ai/openapi_spec.json post /v2/projects/{project_id}/service-accounts
openapi: 3.0.0
info:
  title: Cerebrium REST API
  description: >-
    REST API for interacting with Cerebrium. This API is mainly used by the
    Cerebrium CLI client, please run `pip install cerebrium` to install it.
  version: 1.0.0
  license:
    name: Proprietary
    url: https://www.cerebrium.ai/terms-of-service
servers:
  - url: https://rest.cerebrium.ai
security: []
paths:
  /v2/projects/{project_id}/service-accounts:
    post:
      tags:
        - Service Accounts
      summary: Create Service Account
      description: Create a new service account for a project.
      operationId: createServiceAccount
      parameters:
        - name: project_id
          in: path
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              properties:
                description:
                  description: Description of the service account (max 500 characters).
                  type: string
                expiresIn:
                  description: >-
                    Lifetime of the initial token in seconds (max 31536000, i.e.
                    one year). Use 0 for a token that never expires.
                  type: integer
                grants:
                  description: >-
                    List of project IDs the service account is granted access to
                    (1-50 entries).
                  type: array
                name:
                  description: Name of the service account (1-100 characters).
                  type: string
              required:
                - name
                - grants
                - expiresIn
              type: object
      responses:
        '200':
          description: The created service account together with its initial token.
          content:
            application/json:
              schema:
                properties:
                  createdAt:
                    description: Creation timestamp in RFC 3339 format.
                    type: string
                  createdByUserId:
                    description: ID of the user who created the service account.
                    type: string
                  description:
                    description: Description of the service account.
                    type: string
                  grants:
                    description: >-
                      List of project IDs the service account is granted access
                      to.
                    type: array
                  id:
                    description: Unique identifier of the service account.
                    type: string
                  name:
                    description: Name of the service account.
                    type: string
                  projectId:
                    description: ID of the project that owns the service account.
                    type: string
                  token:
                    description: >-
                      The initial token, with its id, secret, and expiry. The
                      secret value is only returned once, at creation.
                    type: object
                type: object
        '400':
          description: >-
            Bad request. The request was malformed or contained invalid
            parameters.
          content:
            application/json:
              schema:
                properties:
                  message:
                    description: Human-readable description of the error.
                    type: string
                type: object
        '401':
          description: >-
            Unauthorized. The Authorization header is missing or the token is
            invalid.
          content:
            application/json:
              schema:
                properties:
                  message:
                    description: Human-readable description of the error.
                    type: string
                type: object
      security:
        - BearerAuth: []
components:
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        Service Account Token authentication. To authenticate API requests:


        1. **Create a Service Account Token:**
           - Go to the [Cerebrium Dashboard](https://dashboard.cerebrium.ai/) and open the **API Keys** page
           - Click **Create Service Account**, name it (e.g., "GitHub Actions CI/CD"), choose an expiry date, and click **Create**
           - **Copy the token** generated for the desired service account

        2. **Use the Token:**
           Include the service account token in the Authorization header of API requests:
           `Authorization: Bearer <your-service-account-token>`

        3. **Best Practices:**
           - Create separate service accounts for different environments (dev, staging, prod)
           - Store tokens securely as secrets in consuming applications or workflows
           - Set appropriate expiry dates and rotate tokens regularly
           - Never commit tokens to source control

        For CI/CD integration examples, see the [CI/CD
        documentation](https://docs.cerebrium.ai/cerebrium/deployments/ci-cd).

````