Authenticating in the Yandex Cloud CLI as a service account
Note
Warning
Creating service accounts and their keys may be prohibited by access policies at the folder, cloud, or organization level.
Learn how to get authenticated in the Yandex Cloud CLI:
-
As a service account using impersonation
Using impersonation is the recommended and most secure way to get authenticated in the Yandex Cloud CLI.
This method is not suitable for servers without a GUI because the user first needs to get authenticated to the CLI with a Yandex account, federated account, or local user account through the browser.
-
As a service account using an authorized key
You can create an authorized key with an unlimited lifetime and continuously use it to authenticate in the Yandex Cloud CLI. Using a long-lived key is less secure than using impersonation.
To get an authorized key, you must initially authenticate in the CLI using a Yandex account, federated account, or local user account from a device that has a browser and GUI. Further CLI operations can be performed on a server without a GUI.
-
As a service account from inside a VM
Using a service account attached to the Yandex Compute Cloud VM is the recommended method of authentication in the Yandex Cloud CLI when using a VM.
This method does not require initial CLI authentication with a Yandex account, federated account, or local user account, nor does it require the server to have a browser or GUI.
Service accounts are different from Yandex user accounts, federated user accounts, or local user accounts. You cannot use a service account to log in to the management console
Getting started
If you do not have a service account yet, create one and configure access permissions for it.
Tip
If your organization uses a proxy server to access Yandex Cloud, configure the CLI connection to the proxy server before running the yc init command.
Perform actions as a service account using impersonation
Using impersonation is the recommended and most secure way to get authenticated in the Yandex Cloud CLI.
This method is not suitable for servers without a GUI because the user first needs to get authenticated to the CLI with a Yandex account, federated account, or local user account through the browser.
Note
To use impersonation, the user must have the iam.serviceAccounts.tokenCreator role for the service account.
To perform an action on behalf of a service account:
-
Authenticate in the CLI as a Yandex user, federated user, or local user.
-
Get a list of service accounts that exist in your cloud:
yc iam service-account --folder-id <folder_ID> listWhere
--folder-idis the folder ID.Result:
+----------------------+------------+--------+---------------------+-----------------------+ | ID | NAME | LABELS | CREATED AT | LAST AUTHENTICATED AT | +----------------------+------------+--------+---------------------+-----------------------+ | ajeg2b2et02f******** | my-robot | | 2024-09-08 18:59:45 | 2025-08-21 06:40:00 | | ajegtlf2q28a******** | default-sa | | 2023-06-27 16:18:18 | 2025-08-21 06:30:00 | +----------------------+------------+--------+---------------------+-----------------------+ -
When running Yandex Cloud CLI commands, use impersonation of your service account by specifying its ID in the
--impersonate-service-account-idparameter.For example, to create a bucket named
my-sample-bucketin the default folder on behalf of a service account, run this command:yc storage bucket create \ --name my-sample-bucket \ --impersonate-service-account-id <service_account_ID>Where
--impersonate-service-account-idis the service account ID you got earlier.
Some commands require that you specify unique IDs for your cloud and folder. You can run such commands with the --cloud-id and --folder-id parameters.
Get authenticated as a service account using an authorized key
You can create an authorized key with an unlimited lifetime and continuously use it to authenticate in the Yandex Cloud CLI. Using a long-lived key is less secure than using impersonation.
To get an authorized key, you must initially authenticate in the CLI using a Yandex account, federated account, or local user account from a device that has a browser and GUI. Further CLI operations can be performed on a server without a GUI.
-
Authenticate in the CLI as a Yandex user, federated user, or local user.
Warning
To get authenticated in the CLI with a Yandex account, federated account, or local user account, you need a browser and a GUI.
To use a service account on a server without a GUI, first complete the preparation steps on a device with a GUI and a browser.
-
Create an authorized key and use it to get authenticated in the CLI:
-
Get a list of service accounts that exist in your cloud:
yc iam service-account --folder-id <folder_ID> listWhere
--folder-idis the folder ID.Result:
+----------------------+------------+--------+---------------------+-----------------------+ | ID | NAME | LABELS | CREATED AT | LAST AUTHENTICATED AT | +----------------------+------------+--------+---------------------+-----------------------+ | ajeg2b2et02f******** | my-robot | | 2024-09-08 18:59:45 | 2025-08-21 06:40:00 | | ajegtlf2q28a******** | default-sa | | 2023-06-27 16:18:18 | 2025-08-21 06:30:00 | +----------------------+------------+--------+---------------------+-----------------------+ -
Create an authorized key for the service account and save it to a file named
key.json:yc iam key create \ --service-account-name default-sa \ --output key.json \ --folder-id <folder_ID>Where:
--service-account-name: Name of the service account you got earlier.--output: Name of the file to save the authorized key to.--folder-id: ID of the folder with the service account.
Result:
id: aje83v701b1u******** service_account_id: aje3932acd0c******** created_at: "2019-08-26T12:31:25Z" key_algorithm: RSA_2048 -
If you created an authorized key on your local machine and want to use it to authenticate in the CLI on a VM, copy it over SCP beforehand.
-
Add the service account authorized key to the CLI profile.
-
Create a new CLI profile:
yc config profile create sa-profile -
Add an authorized key:
yc config set service-account-key key.json
-
-
Make sure the parameters for the service account are added correctly:
yc config listResult:
service-account-key: id: aje83v701b1u******** service_account_id: aje3932acd0c******** created_at: "2019-08-26T12:31:25Z" key_algorithm: RSA_2048 public_key: | -----BEGIN PUBLIC KEY----- MIIBIjANBg... -----END PUBLIC KEY----- private_key: | -----BEGIN PRIVATE KEY----- MIIEvwIBAD... -----END PRIVATE KEY----- -
Configure your profile to run commands.
Some commands require that you specify unique IDs for your cloud and folder. You can specify their details in the profile or use a specific flag for these commands.
-
Specify the cloud in your profile:
yc config set cloud-id <cloud_ID>You can also use the
--cloud-idparameter to run commands.For more information, see Getting a cloud ID.
-
Specify a folder in the profile:
yc config set folder-id <folder_ID>You can also use the
--folder-idparameter to run commands.For more information, see Getting the folder ID.
All operations in this profile will be performed on behalf of the linked service account. You can change the profile parameters or switch to another profile.
-
-
Authenticate as a service account from inside a VM
Using a service account attached to the Yandex Compute Cloud VM is the recommended method of authentication in the Yandex Cloud CLI when using a VM.
This method does not require initial CLI authentication with a Yandex account, federated account, or local user account, nor does it require the server to have a browser or GUI.
The authentication process from inside a VM is simplified for a service account:
-
Link your service account to a VM.
-
Authenticate from inside a VM:
-
Connect to the VM over SSH.
-
Create a new profile:
yc config profile create my-robot-profile
-
-
Configure your profile to run commands.
Some commands require that you specify unique IDs for your cloud and folder. You can specify their details in the profile or use a specific flag for these commands.
-
Specify the cloud in your profile:
yc config set cloud-id <cloud_ID>You can also use the
--cloud-idparameter to run commands.For more information, see Getting a cloud ID.
-
Specify a folder in the profile:
yc config set folder-id <folder_ID>You can also use the
--folder-idparameter to run commands.For more information, see Getting the folder ID.
All operations in this profile will be performed on behalf of the linked service account. You can change the profile parameters or switch to another profile.
-
Read more about working with Yandex Cloud from a VM in Using Yandex Cloud from within a VM.