# Service principals

Create a non-human identity to represent a service, application, or agent accessing Stripe.

A service principal is a non-human identity that represents an application, service or AI agent accessing Stripe. Service principals, much like human team members in the Dashboard, have a name, ID, authentication method, and permissions which determine their access within Stripe.

This creates a distinction between the durable identity of the application (who it represents) and its transient authentication method (how it authenticates to the Stripe API). This distinction is analogous to the difference between a human team member (such as “Jenny Rosen”) and their authentication method (such as a password, passkey, or single sign-on).

In private preview, service principals only support [Workload Identity Federation](https://docs.stripe.com/workload-identity-federation.md) as an authentication method.

Creating a service principal lets you authenticate an external application or service to Stripe, monitor its activity (even if its credentials change), and apply controls (such as [access policies](https://docs.stripe.com/keys.md#access-policies) or [two-party approval rules](https://docs.stripe.com/account/approvals.md)).

## Request access  (Private preview)

Service principals are in [private preview](https://docs.stripe.com/release-phases.md) and available to a limited number of users.

### Get early access to service principals and Workload Identity Federation

Enter your email to request access to the Workload Identity Federation private preview.

```bash
curl https://docs.stripe.com/preview/register \
  -X POST \
  -H "Content-Type: application/json" \
  -H "Referer: https://docs.stripe.com/service-principals" \
  -d '{"email": "EMAIL", "preview": "wif_private_preview"}'
```

## How it works 

You create a service principal in the Stripe Dashboard by giving it a name, configuring its authentication method ([Workload Identity Federation](https://docs.stripe.com/workload-identity-federation.md)), and assigning permissions (similar to an API key). After creating a service principal, Stripe generates an OAuth client ID, which your workload uses to request short-lived access tokens to the Stripe API.

## Create a service principal 

1. In the Stripe Dashboard, go to **Organization** > **Developers** > **API authentication** > [Service principals](https://dashboard.stripe.com/org/service-principals) and click **Create service principal**.
2. Add a name that identifies the service or application the service principal represents.
3. Select the service’s workload identity provider, or [add a new one](https://docs.stripe.com/workload-identity-federation.md#setup-wif).
4. Add a subject that matches your workload. For the subject format Stripe expects for your provider type, see [Set up Workload Identity Federation](https://docs.stripe.com/workload-identity-federation.md#setup-wif) instructions.
5. Assign permissions to the service principal in the same way you would when creating an API key.
6. Click **Create service principal**.

### Get the service principal’s client ID

After you create a service principal, copy its client ID. Your workload uses this ID to request short-lived access tokens for your service principal when calling the Stripe API.

## See also

- [Workload Identity Federation](https://docs.stripe.com/workload-identity-federation.md)
