> ## Documentation Index
> Fetch the complete documentation index at: https://ona.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Service Account

> Creates a new service account in an organization.

`Unary` · [`Service Accounts`](/docs/api-reference/generated/service-account/overview)

Creates a new service account in an organization.

Use this method to:

* Create service accounts for automation
* Set up external automation credentials
* Configure programmatic access

### Examples

* Create service account:

  Creates a service account for automation.

  ```yaml theme={null}
  name: "ci-pipeline"
  description: "CI/CD Pipeline"
  validUntil: "2025-12-31T23:59:59Z"
  ```

## Endpoint

```text theme={null}
POST /api/gitpod.v1.ServiceAccountService/CreateServiceAccount
```

Send a Bearer token as described in [Authentication](/docs/api-reference#authenticate-requests). If your organization uses a custom management-plane domain, replace `https://app.ona.com` with that domain.

## Request example

<CodeGroup>
  ```bash cURL theme={null}
  export ONA_HOST=https://app.ona.com
  export ONA_API_KEY=<your-token>

  curl --request POST \
    --url "$ONA_HOST/api/gitpod.v1.ServiceAccountService/CreateServiceAccount" \
    --header "Authorization: Bearer $ONA_API_KEY" \
    --header "Content-Type: application/json" \
    --data '{
    "validUntil": "2026-01-01T00:00:00Z"
  }'
  ```

  ```python Python theme={null}
  import gitpod.v1.service_account_pb2 as service_account_pb2
  import google.protobuf.timestamp_pb2 as timestamp_pb2
  from ona_sdk import create_client_from_env

  ona = create_client_from_env()
  request = service_account_pb2.CreateServiceAccountRequest(
      valid_until=timestamp_pb2.Timestamp(seconds=1767225600),
  )
  response = ona.services.service_account.create_service_account(request)
  print(response)
  ```

  ```typescript TypeScript theme={null}
  import { create } from "@bufbuild/protobuf";
  import { createClientFromEnv } from "@gitpod/sdk";
  import { CreateServiceAccountRequestSchema } from "@gitpod/sdk/gitpod/v1/service_account_pb";
  import { timestampFromDate } from "@bufbuild/protobuf/wkt";

  async function main() {
    const ona = createClientFromEnv();
    const request = create(CreateServiceAccountRequestSchema, {
      validUntil: timestampFromDate(new Date("2026-01-01T00:00:00Z")),
    });
    const response = await ona.services.serviceAccount.createServiceAccount(request);
    console.log(response);
  }

  main().catch(console.error);
  ```

  ```go Go theme={null}
  package main

  import (
  	"context"
  	"fmt"
  	"log"

  	"connectrpc.com/connect"
  	"github.com/gitpod-io/gitpod-sdk-go/sdk"
  	gitpodpb "github.com/gitpod-io/gitpod-sdk-go/v1"
  	timestamppb "google.golang.org/protobuf/types/known/timestamppb"
  )

  func main() {
  	ona, err := sdk.NewFromEnv()
  	if err != nil {
  		log.Fatal(err)
  	}

  	request := connect.NewRequest(&gitpodpb.CreateServiceAccountRequest{
  		ValidUntil: &timestamppb.Timestamp{Seconds: 1767225600},
  	})
  	response, err := ona.Services.ServiceAccount.CreateServiceAccount(context.Background(), request)
  	if err != nil {
  		log.Fatal(err)
  	}
  	fmt.Println(response.Msg)
  }
  ```

  ```json Request body theme={null}
  {
    "validUntil": "2026-01-01T00:00:00Z"
  }
  ```
</CodeGroup>

## Request

`gitpod.v1.CreateServiceAccountRequest`

| Field         | Type               | Required | Description                                                                                                                                                                                                                             |
| ------------- | ------------------ | -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`        | string             | No       | Constraints: `string.max_len=64, string.min_len=1`.                                                                                                                                                                                     |
| `description` | string             | No       | Constraints: `string.max_len=500`.                                                                                                                                                                                                      |
| `validUntil`  | RFC 3339 timestamp | Yes      | valid\_until specifies when this service account expires. Note: In the current design, the service account itself has an expiry. All authentication using this service account will fail after this time. Constraints: `required=true`. |

## Response

`gitpod.v1.CreateServiceAccountResponse`

| Field            | Type                                              | Required | Description                   |
| ---------------- | ------------------------------------------------- | -------- | ----------------------------- |
| `serviceAccount` | [ServiceAccount](#type-gitpod-v1-service-account) | Yes      | Constraints: `required=true`. |

## Related types

<a id="type-gitpod-v1-service-account" />

<Accordion title="ServiceAccount">
  `gitpod.v1.ServiceAccount`

  | Field            | Type                               | Required | Description                                                                                                                                         |
  | ---------------- | ---------------------------------- | -------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
  | `id`             | string                             | No       | Constraints: `string.uuid=true`.                                                                                                                    |
  | `organizationId` | string                             | No       | Constraints: `string.uuid=true`.                                                                                                                    |
  | `name`           | string                             | No       |                                                                                                                                                     |
  | `description`    | string                             | No       |                                                                                                                                                     |
  | `creator`        | [Subject](#type-gitpod-v1-subject) | No       |                                                                                                                                                     |
  | `createdAt`      | RFC 3339 timestamp                 | No       |                                                                                                                                                     |
  | `validUntil`     | RFC 3339 timestamp                 | No       |                                                                                                                                                     |
  | `suspended`      | boolean                            | No       | suspended indicates whether the service account has been deleted (soft-delete). Suspended service accounts cannot be used for authentication.       |
  | `systemManaged`  | boolean                            | No       | system\_managed indicates whether this is a system-managed service account. System-managed service accounts cannot be modified or deleted by users. |
</Accordion>

<a id="type-gitpod-v1-subject" />

<Accordion title="Subject">
  `gitpod.v1.Subject`

  | Field       | Type                                   | Required | Description                                                                      |
  | ----------- | -------------------------------------- | -------- | -------------------------------------------------------------------------------- |
  | `id`        | string                                 | No       | id is the UUID of the subject Constraints: `ignore=1, string.uuid=true`.         |
  | `principal` | [Principal](#enum-gitpod-v1-principal) | No       | Principal is the principal of the subject Constraints: `enum.defined_only=true`. |
</Accordion>

<a id="enum-gitpod-v1-principal" />

<Accordion title="Principal">
  | Value                       | Number | Description |
  | --------------------------- | -----: | ----------- |
  | `PRINCIPAL_UNSPECIFIED`     |      0 |             |
  | `PRINCIPAL_ACCOUNT`         |      1 |             |
  | `PRINCIPAL_USER`            |      2 |             |
  | `PRINCIPAL_RUNNER`          |      3 |             |
  | `PRINCIPAL_ENVIRONMENT`     |      4 |             |
  | `PRINCIPAL_SERVICE_ACCOUNT` |      5 |             |
  | `PRINCIPAL_RUNNER_MANAGER`  |      6 |             |
</Accordion>
