Skip to main content
Reference
Owners and admins need the workspace-scoped service_credentials.manage permission.
Each grant is project-scoped and must name a project inside the owning workspace. Available grants are project-read, project-write, query-read, and query-write; write requires its matching read. Creation displays the secret once. Updates never reveal or rotate it. Service credentials authenticate headless API/MCP automation. They are never a CLI login method and the CLI never persists them.