# Service accounts

> Give CI and code running on Nodus an identity that belongs to the project, not to a person.

Source: https://nodus-platform-site.pages.dev/docs/guides/access/service-accounts/
Build revision: 211ad9f836655b1c3a2668c4693e442471f28614

A **service account** is an identity for machines. Every project has one named `default`, used by code running inside Nodus for its own calls. Create more for CI and automation:

Terminal window

```bash
nodus create serviceaccount ci -p research --scopes jobs:write,volumes:read
```

Managing service accounts needs `serviceaccounts:write` (Admins and Owners).

## Tokens for CI

Terminal window

```bash
nodus create token sa/ci -p research --duration 720h
```

This prints a key bound to the service account, once. It is valid for 90 days by default and at most one year. Its permissions are the service account’s scopes, narrowed further by any `--scope` you pass.

Service account keys do not belong to a person: they keep working when the member who created them leaves the org, and they stop working when the service account is deleted. Use them for the GitHub Action and any shared automation.

## Inside Nodus

Code running in a Job, Sandbox or Agent reaches the API through `/run/nodus/api.sock` with a short-lived token of its service account. The token is never in the environment or on disk, and it stops working the moment its run is stopped or moved.
