Manage MondooManage Access to MondooGrant Services, Scripts, and Apps Access to Mondoo

Create and Manage Service Accounts

Set up service account credentials to authenticate CI pipelines and external services with Mondoo APIs.

Service accounts let external services (such as CI pipelines) authenticate with Mondoo Platform APIs. Unlike team member accounts, service accounts are designed for programmatic access by scripts, automation tools, and applications. Each service account has specific permissions that control what actions it can perform.

Service accounts can access either a single space or all spaces within an organization. Space service accounts are scoped to the space where you create them and can't access any other space in the organization. Organization service accounts are scoped to the organization where you create them and can access all spaces in that organization but not any other organization.

For example, in a CI/CD workflow where worker nodes test builds of infrastructure and applications, you can create a service account that accesses the policies in a space and executes them on builds to assess security risks.

To create service accounts, you need the Editor or Admin role, or the Service Account Creator permission. To delete them, you need the Service Account Manager permission, which Editor and Admin include.

Service account permissions

When you create a service account, check one or more of these roles:

RoleWhat programs using the service account can do
ViewerRead-only access to assets, findings, vulnerabilities, policies, compliance, dashboards, and reports.
EditorDay-to-day administration of policies, integrations, assets, workflows, and content. Cannot create or delete organizations and spaces, manage billing, review exceptions, or configure SSO.
OwnerFull administrative control of the organization or space, including user, policy, integration, and billing management.
AgentRegister, report health, sync assets, resolve assigned policies, and upload scan results. Use this for cnspec agents and for registering cnspec in a pipeline.
Export RunnerRead assets, findings, scores, and reports across the space hierarchy. Use this for tools that export Mondoo data.

Neither Viewer, Editor, nor Owner lets a program report scan results. Check Agent for that.

Create a service account

The procedure is the same for space and organization service accounts. Start from the scope you want the service account to access.

  1. Navigate to the space or organization in which you want to create a service account.

  2. In the left navigation, select Settings, then Identity & Access.

  3. Select the Service accounts group, then select CREATE SERVICE ACCOUNT.

    The Generate a new service account form in the Mondoo App, with name, description, and Viewer, Editor, Owner, Agent, and Export Runner permissions

  4. Enter a unique Name and a Description that help you recognize the service account's purpose.

  5. Under Permissions, check the roles you want to grant. See Service account permissions for what each one allows.

  6. Select GENERATE SERVICE ACCOUNT.

  7. Save the credentials. You won't be able to see them again.

    • To download the credentials as a .json file, select DOWNLOAD CREDENTIALS.

    • To copy the credentials, select the copy icon in the Plain .JSON box.

    • If you plan to pass the credentials to a CI/CD service as an environment variable, select the copy icon in the Base64 box instead.

  8. Select FINALIZE.

Decrypt base64 service account to use with cnspec

echo <base64_credentials> | base64 -d > mondoo.json

Configure cnspec to use the mondoo.json file by either passing the --config /path/to/mondoo.json flag or by setting the MONDOO_CONFIG_PATH environment variable.

Change a service account's permissions

  1. Navigate to the organization or space containing the service account.

  2. In the left navigation, select Settings, then Identity & Access.

  3. Select the Service accounts group.

    The Service accounts group on the space Identity & Access page, listing service accounts with their created and last used times and space role

  4. In the service account's row, select its current role in the Space role or Organization role column. To switch roles, select Viewer, Editor, or Admin and confirm. To pick individual permissions, select Customize, make your changes, and select SAVE CHANGES.

Service accounts with the Agent or Export Runner role show Custom in the role column. Changing the role or permissions of such a service account from the Identity & Access page replaces all of its roles, and the console can't add Agent or Export Runner back. To give an agent or export service account different permissions, create a new service account with the roles you need.

To see when a service account was created and last used, select its name.

Delete a service account

  1. Navigate to the organization or space containing the service account.

  2. In the left navigation, select Settings, then Identity & Access.

  3. Select the Service accounts group.

  4. Select the checkbox next to each service account you want to delete.

  5. In the bar at the bottom of the page, select DELETE, then confirm. Deleting a service account is permanent, and programs using its credentials can no longer authenticate.

On this page