How to create application credentials
Coming from another cloud?
▸AWS·IAM Access Keys
This Quake AI feature maps to AWS’s IAM Access Keys.
▸DigitalOcean·Personal Access Tokens
Personal Access Tokens (PATs) and OAuth2 applications
- DigitalOcean PATs are account-scoped (access all resources across all projects for that account) with a choice of read or read/write scope. OpenStack application credentials are project-scoped and tied to a specific set of roles.
- DO supports OAuth2 for third-party app authorization (apps request access on behalf of a user). OpenStack Keystone supports OAuth1.0 for delegated token issuance; full OAuth2 support depends on the Keystone deployment.
- DO PATs can be set to expire (custom expiry date) or be non-expiring. Keystone token TTL is server-configured, not per-credential.
- DO does not support service accounts independent of a user identity. OpenStack application credentials survive user password changes and can be restricted to specific API operations via access rules.
▸Hetzner·API Token
API Tokens (project-scoped Bearer tokens)
- Hetzner API tokens are project-scoped: each token is valid only for the project it was created in and must be separately generated per project. OpenStack Keystone application credentials are user-scoped and can be used across projects when the user has appropriate roles.
- Hetzner has no OAuth2/OIDC integration for API access; all programmatic access requires a static bearer token. Keystone supports OIDC federation, LDAP backends, and federated identity (SAML2).
- Hetzner tokens have no built-in expiry and must be manually rotated; there is no token TTL or refresh concept. Keystone tokens have configurable TTLs (default 1 hour) and support re-authentication.
- Hetzner tokens are either read-only or read-write with no fine-grained scope. OpenStack roles (admin, member, reader) provide service-level access control per project.
How to create application credentials
Create application credentials to authenticate against the OpenStack API without using your account password. Application credentials are the recommended authentication method for CI/CD pipelines, automation scripts, Terraform, and the OpenStack CLI.
Each credential is scoped to a single project and can be restricted to specific roles. Unlike API tokens, application credentials do not expire after 24 hours; you control the lifetime.
Prerequisites
- ConsoleLogged in to the Quake AI console
- CLIOpenStack CLI installed and authenticated (
clouds.yamloropenrcsourced)
Windows: CLI examples use bash. Set up a Linux CLI environment on Windows before proceeding.
- A Quake AI project with at least one active service
Create an application credential#
Available roles#
The roles in the Roles field depend on your project. The create dialog lists the roles you can assign to a credential. Commonly available roles include:
| Role | Typical use |
|---|---|
member | Standard read and write access to project resources. The most common choice. |
reader | Read-only access to project resources. |
s3_member | Access S3-compatible object storage. |
heat_stack_owner | Create and manage orchestration stacks (Heat). |
Leave Roles empty to inherit the roles from your current token. Pass a role name to the CLI with --role, for example --role member.
Configure clouds.yaml#
After creating an application credential, configure your OpenStack CLI and SDKs by placing a clouds.yaml file at ~/.config/openstack/clouds.yaml:
clouds:
quakeai:
auth:
auth_url: https://keystone.rumble.cloud/v3
application_credential_id: YOUR_CREDENTIAL_ID
application_credential_secret: YOUR_CREDENTIAL_SECRET
auth_type: v3applicationcredential
region_name: us-east-1 # us-east-1 | us-east-2 | us-west-1
interface: public
identity_api_version: 3Then select the cloud in your shell:
export OS_CLOUD=quakeai
openstack server listThe CLI discovers service endpoints from the Keystone catalog automatically; you do not need to configure individual service URLs.
Use the openrc.sh file#
If you downloaded the openrc.sh file from the console, source it to set environment variables:
source openrc-MY_CREDENTIAL.sh
openstack server listThe openrc.sh approach is equivalent to clouds.yaml; it uses shell environment variables instead of a configuration file. Choose whichever fits your workflow. clouds.yaml supports multiple clouds and is preferred for projects that interact with more than one OpenStack deployment.
Security considerations#
- Prefer restricted credentials. Leave the Unrestricted checkbox unchecked unless you specifically need to manage trusts, create other credentials, or provision Kubernetes clusters. Restricted credentials limit blast radius.
- Set expiration dates for credentials used in temporary environments (staging, testing, demos).
- Rotate credentials periodically. Delete old credentials and create new ones; there is no "rotate" action. Create a replacement before deleting the old one.
- One credential per service. Use separate credentials for CI/CD, Terraform, monitoring, and interactive use. This makes revocation granular.
See also#
- API access console reference: overview of the API section in the console
- App credentials reference: console reference for the credentials view
- Service Endpoints: all 12 service base URLs with
clouds.yamlexample - How to get an API token: quick ad-hoc tokens for testing
- S3 credentials: separate credentials for S3-compatible object storage access
- Install OpenStack client: CLI installation
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
For the full policy, see Usage Guidelines.
Last validated: 22.06.2026
