Grant Services, Scripts, and Apps Access to Mondoo - Overview
Configure service accounts, identity providers, and API tokens for automated and programmatic Mondoo access.
When something other than a person needs to talk to Mondoo (a CI pipeline, an agent, a script, an integration), it needs its own credentials. Choose the option that fits:
- Service accounts: the most common choice. Returns a JSON credential file that cnspec, CI/CD pipelines, and integrations can use. You create them on the Identity & Access settings page.
- API tokens: bare bearer tokens for direct calls to the Mondoo GraphQL API.
- Workload identity federation (WIF): keyless authentication backed by an external identity provider (AWS, Azure, Google Cloud, GitHub Actions, or any OIDC provider). No long-lived secrets to store or rotate.
If you're not sure, start with a service account. Use API tokens only for direct calls to the GraphQL API, and WIF when your workload runs somewhere with a native identity provider (AWS, Azure, Google Cloud, or GitHub Actions) and you want to avoid storing secrets.
To register the cnspec CLI on a server or in a pipeline, create a service account and use its credentials, or use a registration token. To learn how, read Register cnspec with Mondoo Platform.
Integrations that connect Mondoo to other services store their third-party secrets as credentials, which you can test, rotate, rename, and delete in one place.