# Application Credentials

Source: https://docs.quake.ai/docs/tools/app-credentials
Markdown: https://docs.quake.ai/docs/tools/app-credentials.md

---

# Application credentials

Select **API** > **App Credentials** (`{CONSOLE_REGION_URL}/papi/application-credentials`) to manage application credentials for your current project.

Application credentials authenticate the OpenStack CLI, SDKs, and Terraform without your account password. Each credential is scoped to a single project. You can restrict it to specific roles and set an expiration date.

<Figure caption="Application Credentials page showing the credential table">
  <img src="https://object.us-east-1.rumble.cloud/77e78aa9c0e04ed0b9d1a3f0626a8c4d:developer-platform-images/images/console/api/app-credentials-acccc48d.png" alt="Application Credentials console page showing the credential table with columns for ID/Name, Project, Description, Expires At, Unrestricted, and Roles" />
</Figure>

## Credential fields

| Field | Description |
|-------|-------------|
| **ID/Name** | Unique identifier and the name you assign at creation |
| **Project Id/Name** | The project this credential is scoped to |
| **Description** | Optional description of the credential's purpose |
| **Expires At** | Expiration timestamp, if set during creation |
| **Unrestricted** | When enabled, allows managing trusts, other credentials, and Kubernetes clusters |
| **Roles** | Roles assigned to this credential (empty inherits all your roles) |

## Available actions

| Action | Description |
|--------|-------------|
| **Create Application Credential** | Generate a new credential ID / secret pair |
| **CLI / API Files** | Download CLI and API configuration files (such as `clouds.yaml` and `openrc.sh`) for the project |
| **Delete** | Permanently revoke the credential |

The list toolbar also includes icon buttons to refresh the table, view a selected credential's details, download its files, and open inline help.



The credential secret is displayed only once during creation. If you lose it, delete the credential and create a new one.



## Using credentials

Application credentials can be used in two ways:

- **`clouds.yaml`**: recommended for the OpenStack CLI and SDKs. See the configuration example in [How to create application credentials](/docs/tools/generate-app-credentials#configure-cloudsyaml).
- **`openrc.sh`**: downloadable from the creation dialog. Source it in your shell to set environment variables.

## CLI commands

### Create an application credential

```bash
openstack application credential create \
  --description "CI pipeline credential" \
  --role member \
  --expiration 2026-12-31T23:59:59 \
  MY_APP_CREDENTIAL
```

- `--role`: Restrict to specific roles (repeat for multiple). Omit to inherit all your current roles. See [Roles reference](#roles-reference) for the available role names.
- `--expiration`: Optional expiration timestamp in ISO 8601 format.
- `--secret`: Provide your own secret instead of generating one.
- `--unrestricted`: Allow the credential to create trusts, other credentials, and Kubernetes clusters. Use sparingly. Required for [Heat stack creation via the CLI](/docs/automation/how-to/create-heat-stack), which needs a Keystone trust.


The command output displays the secret only once. Save it immediately. If you lose it, delete the credential and create a new one.


### List application credentials

```bash
openstack application credential list
```

### Show application credential details

```bash
openstack application credential show MY_APP_CREDENTIAL
```

### Delete an application credential

```bash
openstack application credential delete MY_APP_CREDENTIAL
```

## Roles reference

The `--role` flag (CLI) and the role checkboxes (console) restrict a credential to specific roles. The available roles depend on your project; a project's RBAC policy defines what each role grants. A standard us-east-1 project exposes the following roles:

| Role | Typical use |
|------|-------------|
| `member` | Standard read and write access to project resources |
| `reader` | Read-only access to project resources |
| `s3_member` | Access S3-compatible object storage |
| `heat_stack_owner` | Create and manage Heat orchestration stacks |

Pass the exact role name to `--role`.

## Access rules

Access rules restrict an application credential to specific API paths. When you set access rules, the credential can only make requests that match them.

### List access rules

```bash
openstack access rule list
```

### Show access rule details

```bash
openstack access rule show ACCESS_RULE_ID
```

### Delete an access rule

```bash
openstack access rule delete ACCESS_RULE_ID
```

Create access rules as part of `application credential create` using the `--access-rules` flag with a JSON array:

```bash
openstack application credential create \
  --access-rules '[{"path": "/v2.1/servers", "method": "GET", "service": "compute"}]' \
  READ_ONLY_CREDENTIAL
```

## See also

- [How to create application credentials](/docs/tools/generate-app-credentials): step-by-step guide with security best practices
- [API access console reference](/docs/tools/api-access-console): overview of the API section
- [Service Endpoints](/docs/tools/service-endpoints): `clouds.yaml` example and endpoint discovery
- [Install OpenStack client](/docs/tools/install-openstack-client)
