Reference
Owners and admins need the workspace-scoped service_credentials.manage permission.
project-read, project-write, query-read, and query-write; write requires its matching read.
Creation displays the secret once. Updates never reveal or rotate it.
Service credentials authenticate headless API/MCP automation. They are never a CLI login method and
the CLI never persists them.