---
title: "Create Credential"
method: POST
path: "/api/v1/service_principals/{service_principal_id}/credentials"
tags: ["Service Principal"]
---

# Create Credential

`POST /api/v1/service_principals/{service_principal_id}/credentials`

CreateCredential creates a new client credential for a service principal.

## Path parameters

- `service_principal_id` string, required — The service principal ID to create the credential for.

## Request body

- C1ApiServicePrincipalV1ServicePrincipalServiceCreateCredentialRequestInput — The ServicePrincipalServiceCreateCredentialRequest message.
  - `allowSourceCidrs` string[], nullable — A list of CIDRs to restrict this credential to. Accepts IPv4 (e.g. 10.0.0.0/24) or IPv6 (e.g. 2001:db8::/32) CIDRs.
  - `displayName` string — The display name for the new credential.
  - `expires` string, duration, nullable
  - `requireDpop` boolean — If true, requires DPoP proof-of-possession for token exchange using this credential.
  - `scopedRoles` string[], nullable — The list of roles to restrict the credential to.

## Response `200`

Successful response

- C1ApiServicePrincipalV1ServicePrincipalServiceCreateCredentialResponse — The ServicePrincipalServiceCreateCredentialResponse message.
  - `clientSecret` string — The client secret. Shown exactly once at creation -- cannot be retrieved again.
  - `credential` C1ApiServicePrincipalV1ServicePrincipalCredential — ServicePrincipalCredential represents a client credential for a service principal.
    - `allowSourceCidrs` string[], nullable — CIDR restrictions for this credential.
    - `clientId` string — The full client ID in format: ${cutename}@${tenant}.${installation}/spc
    - `createdAt` string, date-time, nullable
    - `displayName` string — The display name of the credential.
    - `expiresAt` string, date-time, nullable
    - `id` string — The unique ID of the credential (cutename format).
    - `lastUsedAt` string, date-time, nullable
    - `requireDpop` boolean — Whether DPoP proof-of-possession is required for this credential.
    - `scopedRoleIds` string[], nullable — Scoped role IDs for this credential (intersection with SP roles at token issuance).
    - `servicePrincipalId` string — The service principal user ID this credential belongs to.

## Changes

- **2026-08-21** `f2cf3228f366` — 4 breaking, 10 warning, 1 info
  - the request property `allowSourceCidrs` became not nullable
  - the request property `scopedRoles` became not nullable
  - added `#/components/schemas/c1.api.service_principal.v1.ServicePrincipalCredential, subschema #2` to the `credential` response property `oneOf` list for the response status `200`
  - the `credential` response's property type changed from `object` to no type for status `200`
  - …11 more
- **2026-03-10** `7fa698b04b81` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/conductorone/apis/c1-api/changes/api/v1/service_principals/:service_principal_id/credentials/post.md)

---

[API](https://skmtc.dev/conductorone/apis/c1-api.md) · [All operations](https://skmtc.dev/conductorone/apis/c1-api/llms.txt) · [OpenAPI document](https://skmtc.dev/conductorone/apis/c1-api/revisions/f76d07868c0c?raw)
