Skip to main content
POST
Add service-account SSH key
Requires the IAM action iam:ManageCredentials. See IAM permissions for the full list, what each one covers, and an example policy.

Authorizations

Authorization
string
header
required

An OAuth 2.0 bearer token, sent as Authorization: Bearer <token>. This is the recommended way to authenticate.

Get one by exchanging a service account's access key pair at POST /v1/oauth/token with grant_type=client_credentials. It is the standard client-credentials grant, so any OAuth-aware library will obtain and refresh it for you.

Tokens last an hour by default. The same access key pair is separately your AWS SigV4 credential for the S3-compatible object endpoint, which speaks nothing else.

Path Parameters

service_account_id
string<uuid>
required

Service Account ID

Body

application/json
name
string
required
Required string length: 1 - 128
public_key
string
required

One OpenSSH public key. Ed25519, ECDSA, security-key variants, and RSA of at least 2048 bits are supported. Private keys, certificates, multiple keys and authorized_keys options are rejected.

Required string length: 1 - 16384
expires_at
string<date-time>

Optional expiry at least one minute in the future. Rotation requires a new credential and revocation of the old one.

Response

SSH key added

ssh_key
object
required