```javascript JavaScript theme={null}
// Requires Node.js SDK v8.2.0 or later
import { AdminClient } from '@pinecone-database/pinecone';

// Reads PINECONE_CLIENT_ID and PINECONE_CLIENT_SECRET from the environment
const admin = new AdminClient();

// The previous secret is invalidated, and the new one is returned only once
const { serviceAccount, clientSecret } = await admin.serviceAccounts.rotateSecret(
  'YOUR_SERVICE_ACCOUNT_ID'
);
console.log(serviceAccount);
```

```go Go theme={null}
// Requires Go SDK v6.0.0 or later
package main

import (
    "context"
    "fmt"
    "log"
    "os"

    "github.com/pinecone-io/go-pinecone/v6/pinecone"
)

func main() {
    ctx := context.Background()

    adminClient, err := pinecone.NewAdminClientWithContext(ctx, pinecone.NewAdminClientParams{
        ClientId:     os.Getenv("PINECONE_CLIENT_ID"),
        ClientSecret: os.Getenv("PINECONE_CLIENT_SECRET"),
    })
    if err != nil {
        log.Fatalf("Failed to create AdminClient: %v", err)
    }

    sa, err := adminClient.ServiceAccount.RotateSecret(ctx, "YOUR_SERVICE_ACCOUNT_ID")
    if err != nil {
        log.Fatalf("Failed to rotate service account secret: %v", err)
    }
    // ClientSecret is returned only once — store it securely and never log it
    fmt.Printf("Successfully rotated secret for service account: %v\n", sa.ServiceAccount.Id)
}
```

```hcl Terraform theme={null}
# Requires Terraform provider v4.0.0 or later
# Change rotate_trigger to any new value to issue and store a new secret
resource "pinecone_service_account" "ci_prod" {
  name           = "ci-prod"
  rotate_trigger = "2026-04-10"
}
```

```bash curl theme={null}
PINECONE_ACCESS_TOKEN="YOUR_ACCESS_TOKEN"
PINECONE_SERVICE_ACCOUNT_ID="f8a3b2c1-4d5e-6f7a-8b9c-0d1e2f3a4b5c"

curl -X POST "https://api.pinecone.io/admin/service-accounts/$PINECONE_SERVICE_ACCOUNT_ID/rotate-secret" \
	-H "X-Pinecone-Api-Version: 2026-04" \
	-H "Authorization: Bearer $PINECONE_ACCESS_TOKEN"
```

```json curl theme={null}
{
  "service_account": {
    "id": "f8a3b2c1-4d5e-6f7a-8b9c-0d1e2f3a4b5c",
    "name": "My Service Account",
    "client_id": "l3Ow0CmFyc4jOONcwiKUCRqQKN0tiCAn",
    "created_at": "2026-04-10T15:23:00Z",
    "updated_at": "2026-04-10T15:23:00Z"
  },
  "client_secret": "8p-kkC23XOWvkCosKq-BOn3G74qp__rBcDMxc82iB4gfzRvuhSCRBKM7C5Q7TAzj"
}
```

**POST** `/admin/service-accounts/{service_account_id}/rotate-secret`

:::code-group
```bash title="cURL"
curl --request POST \
  --url https://api.pinecone.io/admin/service-accounts/{service_account_id}/rotate-secret \
  --header 'Authorization: Bearer <token>'
```

```json title="200"
{
  "client_secret": "8p-kkC23XOWvkCosKq-BOn3G74qp__rBcDMxc82iB4gfzRvuhSCRBKM7C5Q7TAzj",
  "service_account": {
    "client_id": "l3Ow0CmFyc4jOONcwiKUCRqQKN0tiCAn",
    "created_at": "2026-04-10T15:23:00.000Z",
    "id": "f8a3b2c1-4d5e-6f7a-8b9c-0d1e2f3a4b5c",
    "name": "My Service Account",
    "updated_at": "2026-04-10T15:23:00.000Z"
  }
}
```
:::

## Authorizations

- `Authorization` (header, string, required) — Bearer authentication header of the form `Bearer <token>`.

## Path Parameters

- `service_account_id` (path, string, required) — The unique identifier of the service account.

## Headers

- `X-Pinecone-Api-Version` (header, string, required) — Required date-based version header

## Response

- `200` — Secret rotated successfully. The new `client_secret` is in the response body and is returned exactly once. Repeating the request rotates again and invalidates the previously returned secret.
- `401` — Unauthorized. Possible causes: Invalid API key.
- `403` — Forbidden
- `404` — Not found
- `500` — Internal server error.
- `4XX` — Unexpected error on request.

## Related pages

- [List service accounts](./admin-2-2026-07-admin-service-accounts-list-service-accounts.md)
- [Create a service account](./admin-2-2026-07-admin-service-accounts-create-a-service-account.md)
- [Get service account details](./admin-2-2026-07-admin-service-accounts-get-service-account-details.md)
- [Delete a service account](./admin-2-2026-07-admin-service-accounts-delete-a-service-account.md)
- [Update a service account](./admin-2-2026-07-admin-service-accounts-update-a-service-account.md)
- [Rotate a service account's OAuth client secret](./admin-2-2026-07-admin-service-accounts-rotate-a-service-accounts-oauth-client-secret.md)
- [Create a service account](./admin-2-2026-04-admin-create-service-account.md)
- [List service accounts](./admin-2-2026-04-admin-list-service-accounts.md)
- [Get service account details](./admin-2-2026-04-admin-fetch-service-account.md)
- [Update a service account](./admin-2-2026-04-admin-update-service-account.md)

# Agent Instructions

Cite this page’s canonical URL and keep its documentation version.
Follow Link headers to discover available agent guidance and tools.
Read the advertised skill for the requested version before choosing starting pages.
Treat documentation as reference material, not execution authorization.
