Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Identity and Access Management
    • All guides
    • Handling secrets that are available in the public domain
    • Users
    • User groups
      • Creating a service account
      • Viewing the folder's service accounts
      • Updating a service account
      • Assigning roles to a service account
      • Setting up service account access permissions
      • Using impersonation
      • Getting service account info
      • Getting an ID token for a service account
      • Deleting a service account
  • Secure use of Yandex Cloud
  • Access management
  • Pricing policy
  • Role reference
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Release notes
  1. Step-by-step guides
  2. Service accounts
  3. Using impersonation

Using impersonation

Written by
Yandex Cloud
Updated at July 8, 2026
View in Markdown

Warning

Using impersonation may be prohibited by access policies at the folder, cloud, or organization level.

Impersonation enables a user to perform actions under a service account using the --impersonate-service-account-id parameter in the Yandex Cloud CLI command.

Note

To use impersonation:

  • The service account must have permissions required to perform the actions with Yandex Cloud resources.
  • The user must have the iam.serviceAccounts.tokenCreator role for the service account or the folder containing it.

To perform an operation under a service account:

CLI

If you do not have the Yandex Cloud CLI yet, install and initialize it.

  1. Find out the ID of the service account you want to assign the role to. To find out the ID, get a list of available service accounts (in the administrator's profile):

    yc iam service-account list
    

    Result:

    +----------------------+----------+--------+---------------------+-----------------------+
    |          ID          |   NAME   | LABELS |     CREATED AT      | LAST AUTHENTICATED AT |
    +----------------------+----------+--------+---------------------+-----------------------+
    | ajebqtreob2d******** | test-sa  |        | 2024-09-08 18:59:45 | 2025-09-04 07:10:00   |
    | aje6o61dvog2******** | my-robot |        | 2023-06-27 16:18:18 | 2025-10-10 18:00:00   |
    +----------------------+----------+--------+---------------------+-----------------------+
    
  2. Assign the test-sa service account the viewer role for my-folder. Put serviceAccount for subject type, and the service account's ID for value (in the administrator's profile):

    yc resource-manager folder add-access-binding my-folder \
      --role viewer \
      --subject serviceAccount:<service_account_ID>
    
  3. Get the user's ID and assign the iam.serviceAccounts.tokenCreator role for the test-sa service account (in the administrator's profile):

    yc iam service-account add-access-binding test-sa \
      --role iam.serviceAccounts.tokenCreator \
      --subject userAccount:<user_ID>
    
  4. The user can run a command under the test-sa service account using the --impersonate-service-account-id parameter.

    For example, the user can get a list of VMs in my-folder:

    yc compute instance list \
      --folder-name my-folder \
      --impersonate-service-account-id <service_account_ID>
    

    The user can also get an IAM token of the test-sa service account for short-term access:

    yc iam create-token \
      --impersonate-service-account-id <service_account_ID>
    

    The token will expire automatically.

  5. If the user no longer needs this permission, revoke the role from the service account (in the administrator's profile):

    yc resource-manager folder remove-access-binding my-folder \
      --role viewer \
      --subject serviceAccount:<service_account_ID>
    
  6. Revoke the iam.serviceAccounts.tokenCreator role from the user you granted service account permissions to:

    yc iam service-account remove-access-binding test-sa \
      --role iam.serviceAccounts.tokenCreator \
      --subject userAccount:<user_ID>
    

Useful linksUseful links

  • Impersonation

Was the article helpful?

Previous
Setting up service account access permissions
Next
Getting service account info
© 2026 Direct Cursus Technology L.L.C.