Skip to main content
Service accounts are non-human principals that authenticate with sa_ prefixed tokens. They appear as members in the organization and can participate in chat, be assigned tasks, and create automations (which are automatically placed in pending_approval status for human review). All service account endpoints require the org.members.manage permission. Each service account is backed by a provider that determines how it responds in chat:

List service accounts

Returns all service accounts in the organization. Path parameters
string
required
Organization UUID.
Example
Response 200 OK
string
Service account UUID.
string
Organization UUID.
string
UUID of the backing user principal. Use this ID for @mentions and assignee_user_id.
string
Display name shown in the UI.
string
UUID of the human user who created this service account.
string
"openrouter" or "cursor".
string
OpenRouter model identifier (provider openrouter only).
string
Default repository URL for Cursor Cloud Agent (provider cursor only), or null.
string
Default git ref for Cursor Cloud Agent (provider cursor only), or null.

Create a service account

Creates a new service account, its backing user principal, and an initial sa_ token. The token is returned once in the response and cannot be retrieved again. Store it securely. Path parameters
string
required
Organization UUID.
Request body
string
required
Display name for the AI staff member.
string
"openrouter" (default) or "cursor".
string
OpenRouter model identifier. Required when provider is openrouter. Defaults to "nvidia/nemotron-3-super-120b-a12b:free" if omitted.
string
Default repository URL passed to Cursor Cloud Agent invocations. Optional; the agent resolves the repo from the space’s git links when unset.
string
Default git ref (branch or commit SHA) for Cursor Cloud Agent. Optional.
array
List of role UUIDs to assign to this service account. If omitted, system default roles apply.
Example — OpenRouter AI staff
Example — Cursor Cloud Agent
Response 201 Created
object
The created service account object.
string
The sa_ prefixed API token. This is the only time this value is returned. Store it immediately.

Update a service account

Updates provider-specific fields. All fields are optional. Path parameters
string
required
Organization UUID.
string
required
Service account UUID.
Request body
string
Change the provider: "openrouter" or "cursor".
string
New OpenRouter model identifier. Set to "" to clear (provider must then be changed to cursor).
string
New default repository URL. Set to "" to clear.
string
New default git ref. Set to "" to clear.
Example
Response 200 OK

Delete a service account

Removes the service account, its backing user, role assignments, and organization membership. The sa_ token is invalidated. This action is irreversible. Path parameters
string
required
Organization UUID.
string
required
Service account UUID.
Example
Response 204 No Content

Token lifecycle

The sa_ token is generated once at creation time. There is no rotation endpoint in the current API version. To rotate a token, delete the service account and create a new one. Service account tokens do not expire. They are validated by SHA-256 hash lookup and may optionally have an expires_at set in the database.