Skip to content
Back to Knowledge Base

Service Accounts

Applies to CoCoCo platform v1.0.0-rc.31. Every step below was run on that version.

A service account is an identity for a machine — an integration, a script, a webhook. It has its own policies and its own API tokens, separate from any person. Why that matters is explained in Service Identities for Integrations.

Before you start: you need the permission to see and create accounts (user:list, user:write), to assign policies (iam:attachPolicy) and to issue tokens (apitoken:write). Taking a policy away, revoking a token and deleting the account need iam:detachPolicy, apitoken:revoke and user:delete. The policy the account should get must already exist — see How to Create an IAM Policy.

  1. In the sidebar, under Identity & Access, click Service accounts.
  2. Click Add service account. The page New service account opens.
  3. Enter an Email that says what the account is for, for example shipping-webhook@example.com. Name is optional.
  4. Click Save in the top right corner. The message Service account created appears and the account’s page opens.

A new service account can do nothing until it has a policy.

  1. Under Policies, tick the policy the account should have. The card is marked Assigned and the counter shows (unsaved).
  2. Click Save in the top right corner. The message Service account updated appears. Nothing is changed before you save.

To take a policy away, untick it and click Save again.

  1. Under API Tokens, enter a Token name. Expiration (optional) can stay empty — the token then stays valid until you revoke it.
  2. Click Create token. The box New token created shows the token. It is shown only once: copy it now and store it where the integration keeps its secrets.

The token acts as the service account: it can do exactly what the account’s policies allow, and nothing else.

  1. On the account’s page, under API Tokens, click Revoke next to the token.
  2. Confirm Revoke this API token? This action cannot be undone. with Revoke.

The token is marked Revoked and is refused from then on.

  1. In the list Service accounts, click Delete next to the account (in a short list, a bin icon).
  2. Confirm Delete service account? with Delete.