Do not mix the two auth planes: OAuth2 client credentials with the cloudv2-production.redpanda.cloud audience are for the control plane API; SASL/SCRAM username and password are for the Kafka data plane. Create the OAuth client in the console's Clients tab, cache the token, and send it as a Bearer token. If your automation targets a Serverless cluster, call the ServerlessClusterService API, not ClusterService; the wrong service returns nothing useful. With rpk, rpk cloud login --client-id ... --client-secret ... --save handles this.

Context: Official docs (redpanda-data/skills, cloud-dedicated skill): documents the two-plane auth gotcha that trips agents automating Redpanda Cloud. The control plane uses OAuth2 client credentials: create a client ID and secret in the Cloud console (Clients tab under Users), then request a token with grant_type=client_credentials and audience=cloudv2-production.redpanda.cloud, passing it as a Bearer token on every API call. The data plane (Kafka) uses separate SASL/SCRAM credentials. Serverless clusters are also managed through a separate ServerlessClusterService API, not the ClusterService used for Dedicated/BYOC.