Create an access key
Reviewed on
An AK/SK credential — an access key (AK) and its secret key (SK) — is a durable credential attached to a service account. It authenticates access to the Object Storage with a signature compatible with the AWS tooling, without exchanging a token at each session. For a temporary credential obtained from a token, see the Object Storage quickstart.
Permissions
This action requires the following IAM (Identity and Access Management) permission:
- iam.accessKey.create
- API
API
Generate a new access key and secret key for a service account, to authenticate access to the Object Storage.
Prerequisites: the service account must exist (create a service account ↗).
This operation requires an access token and the permissions listed at the top of the page.
POST https://api.eu-west-2.numspot.com/iam/organisations/{organisationId}/serviceAccounts/{serviceAccountId}/aksk
Full documentation for this endpoint ↗
Parameters
| Parameter | Location | Required | Type | Example | Description |
|---|---|---|---|---|---|
organisationId | path | yes | UUID | 123e4567-e89b-12d3-a456-426614174000 | Organisation owning the service account |
serviceAccountId | path | yes | UUID | 123e4567-e89b-12d3-a456-426614174000 | Service account the credential is attached to |
expiresIn | body | no | string | 720h | Validity duration of the credential, between 1h and 8760h (1 year); one year by default |
Example
export TOKEN="{TOKEN}"
curl 'https://api.eu-west-2.numspot.com/iam/organisations/{ORGANISATION-ID}/serviceAccounts/{SERVICE-ACCOUNT-ID}/aksk' \
--request POST \
--header "Authorization: Bearer $TOKEN" \
--header 'Content-Type: application/json' \
--data '{
"expiresIn": "720h"
}'
| Variable | Represents | Where to find its value |
|---|---|---|
{TOKEN} | OAuth 2.0 access token of the request | Generated by the API authentication flow (see Access token) |
{ORGANISATION-ID} | Organisation owning the service account | Numspot console (active organisation) |
{SERVICE-ACCOUNT-ID} | Service account receiving the access key | Response of the List service accounts ↗ API |
Response
201 Created — the payload describes the created credential:
| Field | Type | Description |
|---|---|---|
id | string | Credential identifier |
clientId | string | Service account client ID |
clientName | string | Service account name |
accessKey | string | Access key, AKIA prefix, 20 characters |
secretKey | string | Secret key, 40 characters — displayed only once, at creation |
status | string | ACTIVE or INACTIVE |
createdBy | string | Identifier of the identity that created the credential |
createdAt | string | Creation date |
expiresAt | string | Expiration date |
{
"id": "019db8c2-1a7b-7de1-8a42-797176d8bbf0",
"clientId": "019db035-7560-7ded-8a42-797176d8bbf0",
"clientName": "backup-orchestrator",
"accessKey": "AKIAIOSFODNN7EXAMPLE",
"secretKey": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY",
"status": "ACTIVE",
"createdBy": "019da410-93c2-7cc2-b5f7-2f4e9a1c30d8",
"createdAt": "2026-10-07T10:15:30.485Z",
"expiresAt": "2027-10-07T10:15:30.485Z"
}
The secret key is displayed only once, in the creation response. It cannot be retrieved later — store it in a secure location. If it is lost, delete the credential and create a new one.
A service account can hold at most two active AK/SK credentials: beyond that, the API returns an HTTP 409 error. Creating a new credential never revokes the existing ones — to rotate a credential, create the replacement key first, then delete the old one.
Main errors
| Code | Case |
|---|---|
| 400 | Invalid body: expiresIn outside the 1h – 8760h range |
| 401 | Access token missing, expired or invalid |
| 403 | Missing iam.accessKey.create permission |
| 404 | Unknown organisationId or serviceAccountId |
| 409 | The service account already holds two active AK/SK credentials |
| 500 | Internal service error — retry later |