Add user
Users can be added by the Account Owner or users with the iam.admin role.
You can add a user with control panel access or add a service user for programmatic access; see the User Types guide for more information.
If there are any problems when adding a user, create a ticket.
Add a user with access to the control panel
You can create users with access to the control panel, who will authenticate using one of the following methods:
-
by login and password;
-
or by SSO, if you use federations.
If you enabled automatic user creation when creating a federation on the Servercore side and you have group mapping configured, users will be created automatically upon initial SSO authentication — in this case, you do not need to add them manually.
Login and password
SSO
-
In the control panel, click IAM on the top menu.
-
Go to the Users section.
-
Click Add user.
-
In the User details block:
4.1. If the Login method field is available, select Control panel.
4.2. In the Email field, enter an email address.
4.3. Optional: enter a user description.
-
In the Access settings block:
5.1. Configure the permission by selecting:
- access scope. If you selected the Projects access scope, select the required projects; ;
- role. To add users with the
memberrole, the account balance must contain funds.
5.2. Optional: to assign an additional permission to the user, click Add permission and repeat step 5.1.
5.3. Optional: select a group for the user.
-
Click Add user.
The user will be added to the list on the Users page with the
Not activatedstatus. A link will be sent to their email for invitation-based registration. The account will be activated after the email is verified and registration is complete.
Add a service user
-
In the control panel, in the top menu, click IAM.
-
Go to the Service users section.
-
Click Add service user.
-
In the Service user details block:
4.1. Enter a username. It will be used for authorization.
4.2. Enter a password for the user or generate one. After the user is created, the password cannot be viewed — it can only be changed. The password must be at least 20 characters long and include at least:
- one uppercase and one lowercase Latin letter (
A-Z,a-z); - one digit (
0-9); - one special character from the ASCII Printable 7-Bit Special Characters list:
!"#$%&'()*+,-./:;<=>?@[]^_{|}~.
4.3. Optional: enter a description for the user.
- one uppercase and one lowercase Latin letter (
-
In the Account access block:
5.1. Configure permissions by selecting:
- access scope. If you selected the Projects access scope, select the required projects;
- role. To add users with the
memberrole, your account balance must have funds.
5.2. Optional: to assign an additional permission to the user, click Add permission and repeat step 5.1.
5.3. Optional: select a group for the user.
-
Click Add user. They will be added to the list on the Service users page. The account will be active immediately.
View service user identifier
- In the control panel, click IAM on the top menu.
- Go to the Service users section.
- In the service user's row, view the value of the UID field.