# OVHcloud + Lutril: setup guide

> Lutril connects to OVHcloud with a service account, using the OAuth2 client credentials flow, and governs the IAM users of your account: the people who can reach the Manager and the API. It reads every user with the privilege their IAM groups carry, and it time boxes access two ways. A request from somebody with no account creates one, and the deadline disables it; a request from somebody who already has an account adds them to one IAM group for the life of the grant, and the deadline removes that membership and nothing else. OVHcloud users are disabled, never deleted, so a second request to the same person re enables the account they already had.

Source: https://www.lutril.com/fr/integrations/ovh
Category: Infrastructure
Auth: service_account
Last verified: 2026-10-08

---

## Setup

1. [object Object]
2. Create the service account, name it something like Lutril, and copy the client ID and the client secret straight away. OVHcloud shows the secret once and will not display it again.
3. [object Object]
4. Note the region your OVHcloud account was created in: Europe, Canada or United States. Accounts are not shared between regions and a service account created in one is refused by the others.
5. In Lutril, connect OVHcloud, paste the client ID and the client secret, then pick the matching region.
6. [object Object]
7. Lutril never deletes an OVHcloud user. Deleting one would destroy its personal access tokens and the IAM URN every policy referencing it points at, so a deadline only ever disables an account Lutril created, or removes the one group membership a grant added. Anybody who already held the group they asked for is left exactly as they were.

## Access requested

- account:apiovh:me/identity/user/* (read the IAM users, create one, enable or disable one)
- account:apiovh:me/identity/group/* (read the groups and their privilege, add or remove a membership)

## References

- [OVHcloud documentation](https://docs.ovhcloud.com/en/guides/manage-and-operate/api/manage-service-account)
- [OVHcloud console](https://www.ovh.com/manager/)
- [Create and manage a service account](https://docs.ovhcloud.com/en/guides/manage-and-operate/api/manage-service-account)
- [Authenticate on the OVHcloud API with a service account](https://docs.ovhcloud.com/en/guides/account-and-service-management/account-information/authenticate-api-with-service-account)
- [Create and manage local users](https://docs.ovhcloud.com/en/guides/account-and-service-management/account-information/ovhcloud-users-management)
- [Use IAM policies with the OVHcloud API](https://docs.ovhcloud.com/en/guides/account-and-service-management/account-information/iam-policies-api)
- [Permission groups managed by OVHcloud](https://docs.ovhcloud.com/en/guides/account-and-service-management/account-information/iam-permission-groups)
- [OVHcloud API console](https://api.eu.ovhcloud.com/console/)
