Reference
Owners and admins need the workspace-scoped service_credentials.manage permission.
project-read, project-write, query-read, and query-write; write requires its matching read.
Creation displays the secret once. Updates never reveal or rotate it.
Service credentials authenticate headless HTTP API calls and, where deployed, the separate Admin MCP
service. They do not authenticate the public unified MCP endpoint. They are never a CLI login method
and the CLI never persists them.