Security (Credentials)

Command

sas-viya dagentsrv security credentials create | set-password | delete | clean-vault
       [command options]

Description

The security credentials command collection is used to create credentials for use by SAS Data Agent. The credential name and attributes are stored in the SAS Viya infrastructure. Passwords are stored according to the type of deployment:

  • Credentials created for a remote deployment1 with a shadow domain: the password is stored locally.
  • Credentials created for a remote deployment with a password domain: the password is stored in the SAS Viya infrastructure.
  • Credentials created for a co-located deployment2 with a shadow domain: the password is stored in the SAS Viya infrastructure.

When credentials are issued for connection to customer databases that are local to the SAS Data Agent, the credentials are extracted by key from the SAS Secrets Manager (Vault) since they are not persisted in the SAS Viya Cloud. The CLI can be run from anywhere that has network access to the server or servers where SAS Data Agents reside.

Note: 1Formerly referred to as on-premises; 2 formerly referred to as cloud.

Creating a New Credential

Command

sas-viya dagentsrv security credentials create [command options]

Description

Use this command to create a local credential linked to the SAS Viya credentials service. If the password is not specified on the command line, the CLI prompts you for the password value.

Updating Credentials: Set Password

Command

sas-viya dagentsrv security credentials set-password [command options]

Description

The set-password command enables you to modify the password for an existing credential. The credential must be in the domain, and it must be associated with the identity of the user currently logged on. You must know the current password to be able to change it.

Deleting Credentials

Command

sas-viya dagentsrv security credentials delete [command options]

Description

You can delete a credential for the identity of the user who is currently logged on. If you are an administrator, you can delete the credentials for another user by specifying the --identity option.

Cleaning Vault

Command

sas-viya dagentsrv security credentials clean-vault --domain domain-name

Description

The clean-vault command is used to remove SAS Data Agent database passwords from the SAS Secrets Manager. Use this step when removing a SAS Data Agent deployment. This command can be used with domains of type “shadow”.

Last updated: August 14, 2026