> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.getunleash.io/api/create-service-account/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.getunleash.io/_mcp/server. # Create a service account. POST https://app.unleash-instance.example.com/api/admin/service-account Content-Type: application/json **Enterprise feature** Creates a new service account. Reference: https://docs.getunleash.io/api/create-service-account ## Authentication - `Authorization` header (required) — API key needed to access this API - `Authorization` header (bearer token, required) — API key needed to access this API, in Bearer token format ## Request ### Body (application/json) This endpoint expects a createServiceAccountSchema. - `username` (string, required) — The username of the service account - `name` (string, required) — The name of the service account - `rootRole` (integer, required) — The id of the root role for the service account ## Response ### 201 The resource was successfully created. - `id` (double, required) — The service account id - `name` (string, optional) — The name of the service account - `username` (string, optional) — The service account username - `imageUrl` (string, optional) — The service account image url - `rootRole` (integer, optional) — The root role id associated with the service account - `createdAt` (string, optional) — The service account creation date - `tokens` (list of patSchema, optional) — The list of tokens associated with the service account - `isAPI` (boolean, optional, deprecated) — Deprecated: for internal use only, should not be exposed through the API - `email` (string, optional, deprecated) — Deprecated: service accounts don't have emails associated with them - `inviteLink` (string, optional, deprecated) — Deprecated: service accounts cannot be invited via an invitation link - `loginAttempts` (double, optional, deprecated) — Deprecated: service accounts cannot log in to Unleash - `emailSent` (boolean, optional, deprecated) — Deprecated: internal use only - `seenAt` (string, optional, nullable, deprecated) — Deprecated. This property is always `null`. To find out when a service account was last seen, check its `tokens` list and refer to each token's `lastSeen` property instead. ## Errors ### 400 Bad Request Error The request data does not match what we expect. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 401 Unauthorized Error Authorization information is missing or invalid. Provide a valid API token as the `authorization` header, e.g. `authorization:*.*.my-admin-token`. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 403 Forbidden Error The provided user credentials are valid, but the user does not have the necessary permissions to perform this operation - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 409 Conflict Error The provided resource can not be created or updated because it would conflict with the current state of the resource or with an already existing resource, respectively. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 415 Unsupported Media Type Error The operation does not support request payloads of the provided type. Please ensure that you're using one of the listed payload types and that you have specified the right content type in the "content-type" header. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ## Types ### patSchema Describes a [personal access token](https://docs.getunleash.io/concepts/api-tokens-and-client-keys#personal-access-tokens), or PAT. PATs are automatically scoped to the authenticated user. - `id` (integer, required) — The PAT's ID. PAT IDs are incrementing integers. In other words, a more recently created PAT will always have a higher ID than an older one. - `createdAt` (string, required) — The date and time of when the PAT was created. - `description` (string, required) — The PAT's description. - `expiresAt` (string, required) — The PAT's expiration date. - `secret` (string, optional) — The token used for authentication. It is automatically generated by Unleash when the PAT is created and that is the only time this property is returned. - `seenAt` (string, optional, nullable) — When the PAT was last seen/used to authenticate with. `null` if it has not been used yet. - `userId` (integer, optional) — The ID of the user this PAT belongs to. - `expiryWarning` (enum, optional) — A warning about the expiration of this PAT, absent when there is nothing to warn about. `expires-soon` means the PAT is past the middle of its lifetime and expires within one of the configured `tokenExpiryNotificationDays` lead times; `expired` means it is no longer usable. - Allowed values: `expires-soon`, `expired` ## Examples **Request** ```json { "username": "service-account-1", "name": "Service Account 1", "rootRole": 1 } ``` **Response** ```json { "id": 54321, "name": "My Service Account", "username": "my-service-account", "imageUrl": "https://example.com/my-service-account.png", "rootRole": 1, "createdAt": "2021-01-01T00:00:00.000Z", "tokens": [ { "id": 1, "createdAt": "2023-04-19T08:15:14.000Z", "description": "user:xyzrandomstring", "expiresAt": "2023-04-19T08:15:14.000Z", "secret": "user:xyzrandomstring", "seenAt": "2023-04-19T08:15:14.000Z", "userId": 1337, "expiryWarning": "expires-soon" } ], "isAPI": false, "email": "noemail@getunleash.io", "inviteLink": "https://example.com/invite-link", "loginAttempts": 0, "emailSent": false, "seenAt": null } ``` **SDK Code** ```python import requests url = "https://app.unleash-instance.example.com/api/admin/service-account" payload = { "username": "service-account-1", "name": "Service Account 1", "rootRole": 1 } headers = { "Authorization": "", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://app.unleash-instance.example.com/api/admin/service-account'; const options = { method: 'POST', headers: {Authorization: '', 'Content-Type': 'application/json'}, body: '{"username":"service-account-1","name":"Service Account 1","rootRole":1}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://app.unleash-instance.example.com/api/admin/service-account" payload := strings.NewReader("{\n \"username\": \"service-account-1\",\n \"name\": \"Service Account 1\",\n \"rootRole\": 1\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Authorization", "") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://app.unleash-instance.example.com/api/admin/service-account") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = '' request["Content-Type"] = 'application/json' request.body = "{\n \"username\": \"service-account-1\",\n \"name\": \"Service Account 1\",\n \"rootRole\": 1\n}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://app.unleash-instance.example.com/api/admin/service-account") .header("Authorization", "") .header("Content-Type", "application/json") .body("{\n \"username\": \"service-account-1\",\n \"name\": \"Service Account 1\",\n \"rootRole\": 1\n}") .asString(); ``` ```php request('POST', 'https://app.unleash-instance.example.com/api/admin/service-account', [ 'body' => '{ "username": "service-account-1", "name": "Service Account 1", "rootRole": 1 }', 'headers' => [ 'Authorization' => '', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://app.unleash-instance.example.com/api/admin/service-account"); var request = new RestRequest(Method.POST); request.AddHeader("Authorization", ""); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"username\": \"service-account-1\",\n \"name\": \"Service Account 1\",\n \"rootRole\": 1\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "Authorization": "", "Content-Type": "application/json" ] let parameters = [ "username": "service-account-1", "name": "Service Account 1", "rootRole": 1 ] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://app.unleash-instance.example.com/api/admin/service-account")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```