---
title: "Create Service Account"
method: POST
path: "/v1/organizations/service_accounts?beta=true"
---

# Create Service Account

`POST /v1/organizations/service_accounts?beta=true`

**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).

Create a service account.

A service account is a named workload identity that federation rules
target. `organization_role` is `developer` (default) or `admin`; a rule
may only be created or retargeted to grant `org:admin` scope when the
target's `organization_role` is `admin`. Creating an `admin`-role service
account requires an interactive credential (a user OAuth token or a
Console session) — a workload may only create `developer`-role service
accounts.

## Headers

- `anthropic-beta` string — Optional header to specify the beta version(s) you want to use. To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta.
- `anthropic-version` string — The version of the Claude API you want to use. Read more about versioning and our version history [here](https://platform.claude.com/docs/en/api/versioning).

## Request body

- BetaServiceAccountCreateParams
  - `description` string, nullable — Optional free-text description.
  - `name` string, required — Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.
  - `organization_role` 'admin' | 'developer' — Org-level role. Defaults to `developer`.

## Response `200`

Successful Response

- BetaServiceAccount — Named non-human identity within the caller's organization. A service account is a pure identity: name + org. Authorization lives on whatever references it (federation rules).
  - `archived_at` string, date-time, nullable, required — If set, this service account is archived.
  - `archived_by_actor_id` string, nullable, required — Tagged ID (`user_`/`svac_`) of the actor that archived this service account.
  - `created_at` string, date-time, required — When this service account was created.
  - `created_by_actor_id` string, nullable, required — Tagged ID (`user_`/`svac_`) of the actor that created this service account.
  - `description` string, nullable, required — Optional free-text description.
  - `id` string, required — Tagged ID of the service account.
  - `name` string, required — Admin-chosen slug identifier.
  - `organization_role` 'admin' | 'developer', required — Org-level role. A federation rule may only be created or retargeted to grant `org:admin` scope when this is `admin`. A rule granting `org:admin` whose target is later demoted to `developer` is rejected at token exchange. Rules granting `org:admin` are managed in the Console.
  - `type` 'service_account', required
  - `updated_at` string, date-time, required — When this service account was last updated.
  - `updated_by_actor_id` string, nullable, required — Tagged ID (`user_`/`svac_`) of the actor that last updated this service account.

## Other responses

- `400` — Invalid argument - The client specified an invalid argument
- `401` — Unauthenticated - The request does not have valid authentication credentials
- `403` — Permission denied - The caller does not have permission to execute the specified operation
- `404` — Not found - Some requested entity was not found
- `408` — Deadline exceeded - The deadline expired before the operation could complete
- `409` — Aborted - The operation was aborted due to concurrency issue
- `412` — Failed precondition - Operation was rejected because the system is not in required state
- `413` — Out of range - Operation was attempted past the valid range
- `429` — Resource exhausted - Some resource has been exhausted (rate limiting)
- `431` — Request header fields too large - Request metadata was too large
- `499` — Cancelled - The operation was cancelled by the client
- `500` — Internal - Internal server error
- `501` — Unimplemented - The operation is not implemented or supported
- `503` — Unavailable - The service is currently unavailable
- `504` — Deadline exceeded - Upstream service did not respond in time
- `529` — Overloaded - The service is temporarily overloaded

## Changes

- **2026-09-02** `4789294140a2` — 16 info
  - added the non-success response with the status `400`
  - added the non-success response with the status `401`
  - added the non-success response with the status `403`
  - added the non-success response with the status `404`
  - …12 more
- **2026-08-26** `942a11636c42` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/anthropics/apis/anthropic-api/changes/v1/organizations/service_accounts?beta=true/post.md)

---

[API](https://skmtc.dev/anthropics/apis/anthropic-api.md) · [All operations](https://skmtc.dev/anthropics/apis/anthropic-api/llms.txt) · [OpenAPI document](https://skmtc.dev/anthropics/apis/anthropic-api/revisions/1bb7c7a0a4a9?raw)
