> ## Documentation Index
> Fetch the complete documentation index at: https://ona.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Service Account Token

> Creates a long-lived token for a service account.

`Unary` · [`Service Accounts`](/docs/api-reference/generated/service-account/overview)

Creates a long-lived token for a service account.

Use this method to:

* Create tokens for external automations
* Set up automation credentials
* Generate API access tokens

The token is returned only once and cannot be retrieved later.
Token validity is capped to the service account's expiry.

Requires impersonation: First obtain a short-lived access token via
CreateServiceAccountAccessToken, then use it to call this method.
The service account ID is derived from the caller's identity.

### Examples

* Create token with 90-day validity:

  ```yaml theme={null}
  description: "GitHub Actions"
  validFor: "7776000s"
  ```

## Endpoint

```text theme={null}
POST /api/gitpod.v1.ServiceAccountService/CreateServiceAccountToken
```

Send a Bearer token as described in [Authentication](/docs/api-reference#authenticate-requests). If your organization uses a custom management-plane domain, replace `https://app.ona.com` with that domain.

## Request example

<CodeGroup>
  ```bash cURL theme={null}
  export ONA_HOST=https://app.ona.com
  export ONA_API_KEY=<your-token>

  curl --request POST \
    --url "$ONA_HOST/api/gitpod.v1.ServiceAccountService/CreateServiceAccountToken" \
    --header "Authorization: Bearer $ONA_API_KEY" \
    --header "Content-Type: application/json" \
    --data '{
    "description": "<description>"
  }'
  ```

  ```python Python theme={null}
  import gitpod.v1.service_account_pb2 as service_account_pb2
  from ona_sdk import create_client_from_env

  ona = create_client_from_env()
  request = service_account_pb2.CreateServiceAccountTokenRequest(
      description="<description>",
  )
  response = ona.services.service_account.create_service_account_token(request)
  print(response)
  ```

  ```typescript TypeScript theme={null}
  import { create } from "@bufbuild/protobuf";
  import { createClientFromEnv } from "@gitpod/sdk";
  import { CreateServiceAccountTokenRequestSchema } from "@gitpod/sdk/gitpod/v1/service_account_pb";

  async function main() {
    const ona = createClientFromEnv();
    const request = create(CreateServiceAccountTokenRequestSchema, {
      description: "<description>",
    });
    const response = await ona.services.serviceAccount.createServiceAccountToken(request);
    console.log(response);
  }

  main().catch(console.error);
  ```

  ```go Go theme={null}
  package main

  import (
  	"context"
  	"fmt"
  	"log"

  	"connectrpc.com/connect"
  	"github.com/gitpod-io/gitpod-sdk-go/sdk"
  	gitpodpb "github.com/gitpod-io/gitpod-sdk-go/v1"
  )

  func main() {
  	ona, err := sdk.NewFromEnv()
  	if err != nil {
  		log.Fatal(err)
  	}

  	request := connect.NewRequest(&gitpodpb.CreateServiceAccountTokenRequest{
  		Description: "<description>",
  	})
  	response, err := ona.Services.ServiceAccount.CreateServiceAccountToken(context.Background(), request)
  	if err != nil {
  		log.Fatal(err)
  	}
  	fmt.Println(response.Msg)
  }
  ```

  ```json Request body theme={null}
  {
    "description": "<description>"
  }
  ```
</CodeGroup>

## Request

`gitpod.v1.CreateServiceAccountTokenRequest`

| Field         | Type            | Required | Description                                                                                                                                                                                                                                      |
| ------------- | --------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `description` | string          | No       |                                                                                                                                                                                                                                                  |
| `validFor`    | duration string | No       | valid\_for specifies how long the token should be valid. A large value (e.g. reaching year 2099) represents "no expiry". The actual expiry is always capped to the service account's own expiry. Constraints: `duration.lte.seconds=2524608000`. |

## Response

`gitpod.v1.CreateServiceAccountTokenResponse`

| Field                 | Type                                                         | Required | Description                                                                                                    |
| --------------------- | ------------------------------------------------------------ | -------- | -------------------------------------------------------------------------------------------------------------- |
| `token`               | string                                                       | Yes      | token is the actual JWT token value. This is only returned once during creation. Constraints: `required=true`. |
| `serviceAccountToken` | [ServiceAccountToken](#type-gitpod-v1-service-account-token) | No       | service\_account\_token contains the token metadata.                                                           |

## Related types

<a id="type-gitpod-v1-service-account-token" />

<Accordion title="ServiceAccountToken">
  ServiceAccountToken represents metadata about a service account token.
  The actual token value is only returned once during creation.

  `gitpod.v1.ServiceAccountToken`

  | Field              | Type                               | Required | Description                      |
  | ------------------ | ---------------------------------- | -------- | -------------------------------- |
  | `id`               | string                             | No       | Constraints: `string.uuid=true`. |
  | `serviceAccountId` | string                             | No       | Constraints: `string.uuid=true`. |
  | `description`      | string                             | No       |                                  |
  | `creator`          | [Subject](#type-gitpod-v1-subject) | No       |                                  |
  | `createdAt`        | RFC 3339 timestamp                 | No       |                                  |
  | `expiresAt`        | RFC 3339 timestamp                 | No       |                                  |
  | `lastUsed`         | RFC 3339 timestamp                 | No       |                                  |
</Accordion>

<a id="type-gitpod-v1-subject" />

<Accordion title="Subject">
  `gitpod.v1.Subject`

  | Field       | Type                                   | Required | Description                                                                      |
  | ----------- | -------------------------------------- | -------- | -------------------------------------------------------------------------------- |
  | `id`        | string                                 | No       | id is the UUID of the subject Constraints: `ignore=1, string.uuid=true`.         |
  | `principal` | [Principal](#enum-gitpod-v1-principal) | No       | Principal is the principal of the subject Constraints: `enum.defined_only=true`. |
</Accordion>

<a id="enum-gitpod-v1-principal" />

<Accordion title="Principal">
  | Value                       | Number | Description |
  | --------------------------- | -----: | ----------- |
  | `PRINCIPAL_UNSPECIFIED`     |      0 |             |
  | `PRINCIPAL_ACCOUNT`         |      1 |             |
  | `PRINCIPAL_USER`            |      2 |             |
  | `PRINCIPAL_RUNNER`          |      3 |             |
  | `PRINCIPAL_ENVIRONMENT`     |      4 |             |
  | `PRINCIPAL_SERVICE_ACCOUNT` |      5 |             |
  | `PRINCIPAL_RUNNER_MANAGER`  |      6 |             |
</Accordion>
