Service Accounts
api/admin/workspaces/service_accounts
History
api/admin/workspaces/service_accounts Changed · +8 / -8 lines
- `implicit: boolean or null` - True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed. + True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed. - `service_account_id: string`
- `implicit: boolean or null` - True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed. + True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed. - `service_account_id: string`
- `implicit: boolean or null` - True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed. + True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed. - `service_account_id: string`
- `implicit: boolean or null` - True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed. + True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed. - `service_account_id: string`
- `implicit: boolean or null` - True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed. + True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed. - `service_account_id: string`
- `implicit: boolean or null` - True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed. + True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed. - `service_account_id: string`
- `implicit: boolean or null` - True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed. + True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed. - `service_account_id: string`
- `implicit: boolean or null` - True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed. + True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed. - `service_account_id: string`
api/admin/workspaces/service_accounts Changed · +47 / -50 lines
### Path parameters ### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ### Path parameters ### Query parameters ### Headers #### Response (200) ### Path parameters ### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ## Domain types ### Path Parameters ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Path Parameters ### Query Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ## Domain Types
---- -title: Service Accounts -url: https://platform.claude.com/docs/en/api/admin/workspaces/service_accounts ---- - # Service Accounts ## Create Service Account Workspace Member -**post** `/v1/organizations/workspaces/{workspace_id}/service_accounts` +**POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts` Add a service account to a workspace with the given `workspace_role`.
accounts cannot be added and are rejected. Requires an OAuth bearer or Console session; Admin API keys are not accepted. -### Path Parameters +### Path parameters - `workspace_id: string` ID of the workspace. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Body Parameters +### Body parameters - `service_account_id: string`
- `type: "service_account_workspace_member"` - - `"service_account_workspace_member"` + default: service_account_workspace_member - `workspace_id: string`
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +#### Response (200) ```json {
## Get Service Account Workspace Member -**get** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` Retrieve a service account's membership in a workspace.
membership is returned with its assigned role. An archived service account returns 404. -### Path Parameters +### Path parameters - `workspace_id: string`
ID of the service account. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
- `type: "service_account_workspace_member"` - - `"service_account_workspace_member"` + default: service_account_workspace_member - `workspace_id: string`
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## List Service Account Workspace Members -**get** `/v1/organizations/workspaces/{workspace_id}/service_accounts` +**GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts` List the service accounts that are members of a workspace.
included in this list. Memberships of archived service accounts are omitted from the results. -### Path Parameters +### Path parameters - `workspace_id: string` ID of the workspace. -### Query Parameters +### Query parameters - `limit: optional number` Number of results per page. + default: 20, maximum: 100, minimum: 1 + - `page: optional string` Opaque cursor from a previous response's `next_page`. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
### Returns -- `data: array of object { created_by_actor_id, implicit, service_account_id, 3 more }` +- `data: array of object` - `created_by_actor_id: string or null`
- `type: "service_account_workspace_member"` - - `"service_account_workspace_member"` + default: service_account_workspace_member - `workspace_id: string`
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Update Service Account Workspace Member -**post** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` Change a service account's role in a workspace.
rejected. Requires an OAuth bearer or Console session; Admin API keys are not accepted. -### Path Parameters +### Path parameters - `workspace_id: string`
ID of the service account. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Body Parameters +### Body parameters - `workspace_role: "workspace_admin" or "workspace_developer" or "workspace_restricted_developer" or "workspace_user"`
- `type: "service_account_workspace_member"` - - `"service_account_workspace_member"` + default: service_account_workspace_member - `workspace_id: string`
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +#### Response (200) ```json {
## Delete Service Account Workspace Member -**delete** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**DELETE** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` Remove a service account from a workspace.
membership. Archived workspaces return 400. Requires an OAuth bearer or Console session; Admin API keys are not accepted. -### Path Parameters +### Path parameters - `workspace_id: string`
ID of the service account. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
- `type: "service_account_workspace_member_deleted"` - - `"service_account_workspace_member_deleted"` + default: service_account_workspace_member_deleted - `workspace_id: string`
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
} ``` -## Domain Types +## Domain types ### Service Account Create Response -- `ServiceAccountCreateResponse object { created_by_actor_id, implicit, service_account_id, 3 more }` +- `ServiceAccountCreateResponse object` - `created_by_actor_id: string or null`
- `type: "service_account_workspace_member"` - - `"service_account_workspace_member"` + default: service_account_workspace_member - `workspace_id: string`
### Service Account Retrieve Response -- `ServiceAccountRetrieveResponse object { created_by_actor_id, implicit, service_account_id, 3 more }` +- `ServiceAccountRetrieveResponse object` - `created_by_actor_id: string or null`
- `type: "service_account_workspace_member"` - - `"service_account_workspace_member"` + default: service_account_workspace_member - `workspace_id: string`
### Service Account List Response -- `ServiceAccountListResponse object { created_by_actor_id, implicit, service_account_id, 3 more }` +- `ServiceAccountListResponse object` - `created_by_actor_id: string or null`
- `type: "service_account_workspace_member"` - - `"service_account_workspace_member"` + default: service_account_workspace_member - `workspace_id: string`
### Service Account Update Response -- `ServiceAccountUpdateResponse object { created_by_actor_id, implicit, service_account_id, 3 more }` +- `ServiceAccountUpdateResponse object` - `created_by_actor_id: string or null`
- `type: "service_account_workspace_member"` - - `"service_account_workspace_member"` + default: service_account_workspace_member - `workspace_id: string`
### Service Account Delete Response -- `ServiceAccountDeleteResponse object { service_account_id, type, workspace_id }` +- `ServiceAccountDeleteResponse object` - `service_account_id: string`
- `type: "service_account_workspace_member_deleted"` - - `"service_account_workspace_member_deleted"` + default: service_account_workspace_member_deleted - `workspace_id: string`
api/admin/workspaces/service_accounts First recorded · 650 lines, first recorded
# Service Accounts ## Create Service Account Workspace Member ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response ## Get Service Account Workspace Member ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## List Service Account Workspace Members ### Path Parameters ### Query Parameters ### Header Parameters ### Returns ### Example #### Response ## Update Service Account Workspace Member ### Path Parameters ### Header Parameters ### Body Parameters ### Returns ### Example #### Response ## Delete Service Account Workspace Member ### Path Parameters ### Header Parameters ### Returns ### Example #### Response ## Domain Types ### Service Account Create Response ### Service Account Retrieve Response ### Service Account List Response ### Service Account Update Response ### Service Account Delete Response
The first capture of this source. The page was already there, and this is what it said.
---
title: Service Accounts
url: https://platform.claude.com/docs/en/api/admin/workspaces/service_accounts
---
# Service Accounts
## Create Service Account Workspace Member
**post** `/v1/organizations/workspaces/{workspace_id}/service_accounts`
Add a service account to a workspace with the given `workspace_role`.
The role determines what the service account can do in the workspace and
which workspace-scoped permissions it can be granted when authenticating
through federation. Every service account is already an implicit
`workspace_user` member of the default workspace; adding it explicitly
assigns a chosen role. If the service account is already an explicit
member of the workspace, its `workspace_role` is replaced with the
value supplied here. Archived workspaces return 400. Archived service
accounts cannot be added and are rejected. Requires an OAuth bearer or
Console session; Admin API keys are not accepted.
### Path Parameters
- `workspace_id: string`
ID of the workspace.
### Header Parameters
- `"anthropic-beta": optional array of string`
Optional header to specify the beta version(s) you want to use.
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta.
### Body Parameters
- `service_account_id: string`
Tagged service account ID to add.
- `workspace_role: "workspace_admin" or "workspace_developer" or "workspace_restricted_developer" or "workspace_user"`
Role to assign to the service account in this workspace.
- `"workspace_admin"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
### Returns
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `type: "service_account_workspace_member"`
- `"service_account_workspace_member"`
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: "workspace_admin" or "workspace_billing" or "workspace_developer" or 2 more`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
### Example
```http
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \
-d '{
"service_account_id": "service_account_id",
"workspace_role": "workspace_admin"
}'
```
#### Response
```json
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
```
## Get Service Account Workspace Member
**get** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}`
Retrieve a service account's membership in a workspace.
Returns the membership record, including the service account's
`workspace_role` in this workspace. Archived workspaces return 400. For
the default workspace, returns the implicit (`implicit: true`)
membership when no explicit membership exists; an explicitly added
membership is returned with its assigned role. An archived service
account returns 404.
### Path Parameters
- `workspace_id: string`
ID of the workspace.
- `service_account_id: string`
ID of the service account.
### Header Parameters
- `"anthropic-beta": optional array of string`
Optional header to specify the beta version(s) you want to use.
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta.
### Returns
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `type: "service_account_workspace_member"`
- `"service_account_workspace_member"`
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: "workspace_admin" or "workspace_billing" or "workspace_developer" or 2 more`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
### Example
```http
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
```
#### Response
```json
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
```
## List Service Account Workspace Members
**get** `/v1/organizations/workspaces/{workspace_id}/service_accounts`
List the service accounts that are members of a workspace.
Each entry includes the service account's `workspace_role`. Use `limit`
and the `next_page` cursor to paginate. Archived workspaces return 400;
use `GET /service_accounts/{id}/workspaces` to audit memberships of an
archived workspace. The implicit default-workspace membership is not
included in this list. Memberships of archived service accounts are
omitted from the results.
### Path Parameters
- `workspace_id: string`
ID of the workspace.
### Query Parameters
- `limit: optional number`
Number of results per page.
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
### Header Parameters
- `"anthropic-beta": optional array of string`
Optional header to specify the beta version(s) you want to use.
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta.
### Returns
- `data: array of object { created_by_actor_id, implicit, service_account_id, 3 more }`
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `type: "service_account_workspace_member"`
- `"service_account_workspace_member"`
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: "workspace_admin" or "workspace_billing" or "workspace_developer" or 2 more`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
- `next_page: string or null`
Opaque cursor for the next page, or null if no more results.
### Example
```http
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \
-H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN"
```
#### Response
```json
{
"data": [
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
Cut at 300 lines.