Independent machine users
Service principals are independent platform identities with their own credentials, expiry, scope, and authorization assignments.
Create independent service-principal identities, scope access to tenants, resource groups, or components, and use short-lived API tokens or guarded MCP authentication for supported operations.
Capabilities
Service principals are independent platform identities with their own credentials, expiry, scope, and authorization assignments.
Grant access at tenant, resource-group, or component level. Higher-level grants flow to lower-level resources within the hierarchy.
Use L1 for read access, L2 for read plus selected controls, and L3 for full administration within the granted scope.
Exchange a service-principal client ID and secret for a short-lived JWT before calling supported platform APIs.
Supported APIs are progressively exposed as MCP tools for provisioning, backup, restore, inspection, and configuration workflows.
Core access changes, authorization events, configuration updates, and deployments are logged for relevant tenant administrators.
APIs and MCP tools do not permit creation of new service principals, authorization grants, or payment-method changes. These sensitive actions require human portal involvement.
API and MCP coverage is being rolled out. The documentation site is the source of truth for currently available endpoints and tools.
Ready to move forward?