Skip to main content
Reference
Owners and admins need the workspace-scoped service_credentials.manage permission.
Each grant is project-scoped and must name a project inside the owning workspace. Available grants are project-read, project-write, query-read, and query-write; write requires its matching read. Creation displays the secret once. Updates never reveal or rotate it. Service credentials authenticate headless HTTP API calls and, where deployed, the separate Admin MCP service. They do not authenticate the public unified MCP endpoint. They are never a CLI login method and the CLI never persists them.