Skip to main content

Create an access key

Reviewed on

An AK/SK credential — an access key (AK) and its secret key (SK) — is a durable credential attached to a service account. It authenticates access to the Object Storage with a signature compatible with the AWS tooling, without exchanging a token at each session. For a temporary credential obtained from a token, see the Object Storage quickstart.

Permissions​

info

This action requires the following IAM (Identity and Access Management) permission:

  • iam.accessKey.create

API​

Generate a new access key and secret key for a service account, to authenticate access to the Object Storage.

info

Prerequisites: the service account must exist (create a service account ↗).

This operation requires an access token and the permissions listed at the top of the page.

POST https://api.eu-west-2.numspot.com/iam/organisations/{organisationId}/serviceAccounts/{serviceAccountId}/aksk

Full documentation for this endpoint ↗

Parameters​

ParameterLocationRequiredTypeExampleDescription
organisationIdpathyesUUID123e4567-e89b-12d3-a456-426614174000Organisation owning the service account
serviceAccountIdpathyesUUID123e4567-e89b-12d3-a456-426614174000Service account the credential is attached to
expiresInbodynostring720hValidity duration of the credential, between 1h and 8760h (1 year); one year by default

Example​

export TOKEN="{TOKEN}"

curl 'https://api.eu-west-2.numspot.com/iam/organisations/{ORGANISATION-ID}/serviceAccounts/{SERVICE-ACCOUNT-ID}/aksk' \
--request POST \
--header "Authorization: Bearer $TOKEN" \
--header 'Content-Type: application/json' \
--data '{
"expiresIn": "720h"
}'
VariableRepresentsWhere to find its value
{TOKEN}OAuth 2.0 access token of the requestGenerated by the API authentication flow (see Access token)
{ORGANISATION-ID}Organisation owning the service accountNumspot console (active organisation)
{SERVICE-ACCOUNT-ID}Service account receiving the access keyResponse of the List service accounts ↗ API

Response​

201 Created — the payload describes the created credential:

FieldTypeDescription
idstringCredential identifier
clientIdstringService account client ID
clientNamestringService account name
accessKeystringAccess key, AKIA prefix, 20 characters
secretKeystringSecret key, 40 characters — displayed only once, at creation
statusstringACTIVE or INACTIVE
createdBystringIdentifier of the identity that created the credential
createdAtstringCreation date
expiresAtstringExpiration date
{
"id": "019db8c2-1a7b-7de1-8a42-797176d8bbf0",
"clientId": "019db035-7560-7ded-8a42-797176d8bbf0",
"clientName": "backup-orchestrator",
"accessKey": "AKIAIOSFODNN7EXAMPLE",
"secretKey": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY",
"status": "ACTIVE",
"createdBy": "019da410-93c2-7cc2-b5f7-2f4e9a1c30d8",
"createdAt": "2026-10-07T10:15:30.485Z",
"expiresAt": "2027-10-07T10:15:30.485Z"
}
warning

The secret key is displayed only once, in the creation response. It cannot be retrieved later — store it in a secure location. If it is lost, delete the credential and create a new one.

A service account can hold at most two active AK/SK credentials: beyond that, the API returns an HTTP 409 error. Creating a new credential never revokes the existing ones — to rotate a credential, create the replacement key first, then delete the old one.

Main errors​

CodeCase
400Invalid body: expiresIn outside the 1h – 8760h range
401Access token missing, expired or invalid
403Missing iam.accessKey.create permission
404Unknown organisationId or serviceAccountId
409The service account already holds two active AK/SK credentials
500Internal service error — retry later