# Authentication / Programmatic API Access

You can authenticate programmatically using your existing github-deployer service account in your Namespace (for example, d11355-new-agent). You have two options.


# Option A: Permanent Service Account Token

Create a token secret using your admin role:

apiVersion: v1
kind: Secret
metadata:
  name: github-deployer-token
  namespace: d11355-new-agent
  annotations:
    kubernetes.io/service-account.name: github-deployer
type: kubernetes.io/service-account-token

Retrieve the decoded token:

oc get secret github-deployer-token -n d11355-new-agent -o jsonpath='{.data.token}' | base64 -d

# Option B: Time-bound Token

Generate a temporary token directly:

oc create token github-deployer -n d11355-new-agent --duration=<duration>

# Connecting to the cluster

Log in using the generated token:

oc login --token=<TOKEN> --server=https://api.ai-3.kvant.cloud:6443

Note: For interactive user authentication via browser, you can also run oc login --server=https://api.ai-3.kvant.cloud:6443 -w