A service account is a login for a script, a server or a build: a Vallkey account of its own, with its own keys, that opens only the vaults you share with it. Its token goes in your CI’s secrets. Nobody’s master password does.
Make one
In the web vault, open Account, Service accounts, New service account. Say what it’s for, and for each of your vaults choose Nothing, Read, or Read and save.
Or from the command line:
vallkey service-account create --name Deploys --vault Production --vault Staging:editor
The token is shown once. Keep it in your CI’s secret store.
Use it
export VALLKEY_SERVICE_ACCOUNT_TOKEN=vlk_sa_…
vallkey run -- ./deploy.sh
vallkey read vallkey://Production/Registry/password
With the token set, the command line keeps nothing on the machine: each command logs the service account in, keeps the vault in memory, and logs out when it’s done.
Give it more, or take it all back
Share another vault with the service account’s address, listed under Service accounts, as you would with a person. It picks the vault up at its next run.
Delete it to take everything back at once: its account goes, with its sessions, and the token opens nothing.
What to know
- The token is the account. Whoever has it reads what it reads. If it leaks, delete the service account. Tokens start with
vlk_sa_, so secret scanners can catch one. - It accepts vaults only from you. Anyone else who shares a vault with it is ignored.
- Your own vaults only. An organization’s vaults can’t be granted to a service account.
- Up to 50 for each account. Deleting your own account deletes them with it.
- They’re made in the web vault and from the command line, not in the phone or desktop apps.
Last updated October 4, 2026