Service Agents

Service agents are non-human Eden identities for automation that needs a stable control-plane principal. Use one identity per independently operated deployment, environment, or ownership boundary.

Create, rotate, inspect, and revoke service-agent credentials through the IAM agent APIs. Grant only the organization and resource permissions the automation needs; do not reuse a human token for unattended work.

Last updated: July 10, 2026