Service Accounts changedapi/organization/workspaces/service_accounts
Nearest release: v2.1.286, published 6 hours before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
# Service Accounts ## List Service Account Workspace Members ### Path parameters ### Query parameters ### Returns ### Example #### Response (200) ## Create Service Account Workspace Member ### Path parameters ### Body parameters ### Returns ### Example #### Response (200) ## Get Service Account Workspace Member ### Path parameters ### Returns ### Example #### Response (200) ## Update Service Account Workspace Member ### Path parameters ### Body parameters ### Returns ### Example #### Response (200) ## Delete Service Account Workspace Member ### Path parameters ### Returns ### Example #### Response (200) ## Domain types ### Service Account Remove Response
The whole hunk
473 lines, new pageA whole new page. There's nothing to diff it against, so here is what it says.
---
title: Service Accounts
url: https://platform.claude.com/docs/en/api/organization/workspaces/service_accounts
---
# Service Accounts
## List Service Account Workspace Members
**GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
List the service accounts that are members of a workspace.
Each entry includes the service account's `workspace_role`. Use `limit`
and the `next_page` cursor to paginate. Archived workspaces return 400;
use `GET /service_accounts/{id}/workspaces` to audit memberships of an
archived workspace. The implicit default-workspace membership is not
included in this list. Memberships of archived service accounts are
omitted from the results.
### Path parameters
- `workspace_id: string`
ID of the workspace.
### Query parameters
- `limit: optional number`
Number of results per page.
default: 20, minimum: 1, maximum: 100
- `page: optional string`
Opaque cursor from a previous response's `next_page`.
### Returns
- `data: array of ServiceAccountWorkspaceMember`
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: WorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
- `next_page: string or null`
Opaque cursor for the next page, or null if no more results.
### Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"data": [
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
],
"next_page": "next_page"
}
```
## Create Service Account Workspace Member
**POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Add a service account to a workspace with the given `workspace_role`.
The role determines what the service account can do in the workspace and
which workspace-scoped permissions it can be granted when authenticating
through federation. Every service account is already an implicit
`workspace_user` member of the default workspace; adding it explicitly
assigns a chosen role. If the service account is already an explicit
member of the workspace, its `workspace_role` is replaced with the
value supplied here. Archived workspaces return 400. Archived service
accounts cannot be added and are rejected.
### Path parameters
- `workspace_id: string`
ID of the workspace.
### Body parameters
- `service_account_id: string`
Tagged service account ID to add.
- `workspace_role: NoBillingWorkspaceRole`
Role to assign to the service account in this workspace.
- `"workspace_admin"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
### Returns
- `ServiceAccountWorkspaceMember object`
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: WorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
### Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"service_account_id": "service_account_id",
"workspace_role": "workspace_admin"
}'
```
#### Response (200)
```json
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
```
## Get Service Account Workspace Member
**GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Retrieve a service account's membership in a workspace.
Returns the membership record, including the service account's
`workspace_role` in this workspace. Archived workspaces return 400. For
the default workspace, returns the implicit (`implicit: true`)
membership when no explicit membership exists; an explicitly added
membership is returned with its assigned role. An archived service
account returns 404.
### Path parameters
- `workspace_id: string`
ID of the workspace.
- `service_account_id: string`
ID of the service account.
### Returns
- `ServiceAccountWorkspaceMember object`
- `type: "service_account_workspace_member"`
default: service_account_workspace_member
- `created_by_actor_id: string or null`
Tagged ID (`user_...`/`svac_...`) of the actor who created this membership.
- `implicit: boolean or null`
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role `workspace_user` and cannot be removed.
- `service_account_id: string`
Tagged service account ID (`svac_...`).
- `workspace_id: string`
Tagged workspace ID (`wrkspc_...`).
- `workspace_role: WorkspaceRole`
Role of the service account in this workspace. Service accounts cannot hold the `workspace_billing` role.
- `"workspace_admin"`
- `"workspace_billing"`
- `"workspace_developer"`
- `"workspace_restricted_developer"`
- `"workspace_user"`
### Example
```bash
curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
#### Response (200)
```json
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
```
## Update Service Account Workspace Member
**POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}`
Cut at 300 lines. The page has the rest.
No line in this hunk matches that.