A service account is an organization identity for automated tasks, Agents, and other non-human applications. It does not occupy a member seat.
Usage generated by each service account is tracked separately. You can limit the usage of an individual service account during a billing period by setting a Credits limit. Before using service accounts, an administrator must enable pay-as-you-go billing for service accounts in the organization.
Pay-as-you-go billing for service accounts is enabled at the Qoder organization level and charges only the usage generated by service accounts. After it is enabled, service account usage is billed by the actual number of Credits consumed and settled after use. Other Qoder features continue to use their existing billing methods.
The current pay-as-you-go price is shown below. The price displayed in the Alibaba Cloud console prevails.
Pay-as-you-go billing for service accounts is managed in Alibaba Cloud. The Qoder management console only displays the synchronized status. Service accounts and their credentials are unavailable until pay-as-you-go billing is enabled.
Open the ... menu at the end of a service account row to create a credential directly. You can also select Edit to view credential names and masked credential values under Existing credentials and manage individual credentials.
The service account list displays usage / limit for each account in Credits.
To adjust the limit, open the ... menu at the end of the service account row, select Edit, change the Credits limit, and save. The new limit takes effect immediately. Clear the field to remove the limit.
When a service account reaches its Credits limit for the current billing period, new calls are paused. Calls can resume within the current period after an administrator raises the limit. Usage resets at the beginning of the next billing period, while the configured limit remains in effect.
When a service account is no longer needed, open its action menu and select Archive.
An archived service account and all its credentials become unavailable and cannot be restored. Before archiving the account, stop related automation tasks or migrate them to another service account.
If calls fail, check the following items in order:
Available for: Teams, Enterprise, and Enterprise VPC
Before you begin
- Make sure your current account has administrator permissions for the Qoder organization.
- To enable or manage pay-as-you-go billing, prepare an Alibaba Cloud account that has permission to manage the corresponding Qoder organization.
- Prepare a server-side secret management tool for storing credentials.
Enable pay-as-you-go billing for service accounts
Pay-as-you-go billing for service accounts is enabled at the Qoder organization level and charges only the usage generated by service accounts. After it is enabled, service account usage is billed by the actual number of Credits consumed and settled after use. Other Qoder features continue to use their existing billing methods.
The current pay-as-you-go price is shown below. The price displayed in the Alibaba Cloud console prevails.
| Billing item | Price |
|---|---|
| Service account pay-as-you-go | CNY 0.046 per Credit |
Enable billing
- Sign in to the Alibaba Cloud console with an account that has the required permissions.
- Open the details page of the corresponding Qoder organization and locate Service account pay-as-you-go.
- Review the current unit price and billing information. The price displayed in the Alibaba Cloud console prevails.
- Enable service account pay-as-you-go billing and confirm the operation in the dialog box.
- Return to the Qoder management console, go to Members > Service accounts, refresh the page, and confirm that the status is updated.
Create a service account
- In the Qoder management console, go to Members > Service accounts.
- Click Create.
- Enter a name and description. Set a Credits limit as needed. Leave the field empty if you do not want to set a limit. Use a name that identifies the purpose and environment, such as
support-agent-prod. - Click Create.
Manage credentials
Open the ... menu at the end of a service account row to create a credential directly. You can also select Edit to view credential names and masked credential values under Existing credentials and manage individual credentials.
Create a credential
- Open the ... menu at the end of the service account row and select Create credential. Alternatively, select Edit and click Create credential in the Existing credentials section.
- Copy the new credential and save it in a server-side secret management tool.
- Configure the credential for the caller and verify that calls succeed.
Rotate a credential
- Open the service account's Edit page and locate the credential to rotate under Existing credentials.
- Open the ... menu at the end of the credential row and select Rotate credential.
- Follow the on-screen instructions, copy the new credential, and update the caller.
Revoke a credential
- Open the service account's Edit page and locate the credential to revoke under Existing credentials.
- Open the ... menu at the end of the credential row, select Revoke credential, review the impact, and confirm the operation.
View usage and adjust the limit
The service account list displays usage / limit for each account in Credits.
To adjust the limit, open the ... menu at the end of the service account row, select Edit, change the Credits limit, and save. The new limit takes effect immediately. Clear the field to remove the limit.
When a service account reaches its Credits limit for the current billing period, new calls are paused. Calls can resume within the current period after an administrator raises the limit. Usage resets at the beginning of the next billing period, while the configured limit remains in effect.
Archive a service account
When a service account is no longer needed, open its action menu and select Archive.
An archived service account and all its credentials become unavailable and cannot be restored. Before archiving the account, stop related automation tasks or migrate them to another service account.
Troubleshoot service accounts
If calls fail, check the following items in order:
- Confirm that service account pay-as-you-go billing is enabled for the organization and that Qoder shows the synchronized status as enabled.
- Confirm that the service account is not archived and that the current credential has not been revoked or rotated.
- Check whether usage has reached the Credits limit for the current billing period.
- If the Alibaba Cloud account has an overdue payment, add funds to the account. Service resumes automatically after the outstanding balance is paid. You do not need to enable service account pay-as-you-go billing again.