# Headless Authentication

<Callout type="info" title="Note">
  Creating service accounts requires a [Premium license](https://coder.com/pricing).
</Callout>

Service accounts are headless user accounts that cannot use the web UI to log in
to Coder. This is useful for creating accounts for automated systems, such as
CI/CD pipelines or for users who only consume Coder via another client/API. Service accounts do not have passwords or associated email addresses.

You must have the User Admin role or above to create service accounts.

## Create a service account [#create-a-service-account]

<Tabs items="[&#x22;CLI&#x22;, &#x22;UI&#x22;]" groupId="coder-docs-tab:cli-ui" persist="true">
  <Tab value="CLI">
    Use the `--service-account` flag to create a dedicated service account:

    ```sh
    coder users create \
      --username="coder-bot" \
      --service-account
    ```
  </Tab>

  <Tab value="UI">
    Navigate to **Deployment** > **Users** > **Create user**, then select
    **Service account** as the login type.

    ![Create a user via the UI](/beta-docs/images/admin/users/headless-user.png)
  </Tab>
</Tabs>

## Authenticate as a service account [#authenticate-as-a-service-account]

To make API or CLI requests on behalf of the headless user, learn how to
[generate API tokens on behalf of a user](/beta-docs/admin/users/sessions-tokens/#generate-a-long-lived-api-token-on-behalf-of-another-user).
