Service accounts
A service account is a superglue user that works only through its API key. Create one service account for each of your customers when your product runs superglue tools against your customers’ own accounts, such as their Ramp or Jira. Each service account holds only that customer’s credentials, so a key never reaches another customer’s data.
What a service account can do
Section titled “What a service account can do”A service account key can:
- Run the tools that the Service account role can view.
- Create, read, update, and delete its own credentials.
- Connect a customer’s account through OAuth for a system that the Service account role can view.
A service account cannot log in, use the agent or MCP, read run history, change tools or systems, or see other users’ credentials.
Set up access
Section titled “Set up access”- Create the systems and tools your customers use. All service accounts share them.
- Create your first service account. This adds the Service account role to Access Rules.
- In Access Rules, open the Service account role. Grant Viewer on each system and tool that service accounts need. Viewer lets a service account use a tool without changing it.
These grants apply to every service account, including ones you create later.
Create a service account
Section titled “Create a service account”Admins can create a service account in two ways:
- On Organization, open the Invite users menu and choose Create service account.
- With the API and an admin API key:
curl -X POST https://api.superglue.cloud/v1/service-accounts \ -H "Authorization: Bearer <admin-api-key>" \ -H "Content-Type: application/json" \ -d '{ "name": "Acme Inc" }'The response contains data.serviceAccount.id and data.apiKey.
Self-hosted deployments use their own API and web app URLs in place of api.superglue.cloud and app.superglue.cloud.
Connect a customer’s account
Section titled “Connect a customer’s account”With OAuth
Section titled “With OAuth”-
Set up the system with your own OAuth app: client ID, client secret, authorization URL, token URL, and scopes. In the provider’s app settings, add
https://app.superglue.cloud/api/auth/callbackas a redirect URI. Skip this step when the system uses a superglue managed OAuth app. -
When the customer clicks connect in your product, start the connection with the customer’s API key:
Terminal window curl -X POST https://api.superglue.cloud/v1/oauth/exchanges \-H "Authorization: Bearer <customer-api-key>" \-H "Content-Type: application/json" \-d '{ "systemId": "<system-id>" }' -
Open
data.authorizationUrlin a popup right away. The link expires after 5 minutes. -
The customer approves access with the provider. superglue stores the tokens and closes the popup.
-
Check the connection with
GET /v1/credentials?systemId=<system-id>and the customer’s API key. The customer is connected whencredentialKeyscontainsaccess_tokenwithhasValue: true.
superglue refreshes the tokens when they expire. To reconnect a customer, repeat these steps.
With an API key or token
Section titled “With an API key or token”Collect the customer’s secrets in your product and store them with the customer’s API key. This example stores a Jira email and API token:
curl -X POST https://api.superglue.cloud/v1/credentials \ -H "Authorization: Bearer <customer-api-key>" \ -H "Content-Type: application/json" \ -d '{ "systemId": "<jira-system-id>", "url": "https://acme.atlassian.net", "credentials": { "email": "it@acme.com", "api_token": "<customer-api-token>" } }'Use the secret names that your system expects. url replaces the system’s URL for this customer only, for example their own Jira site. data.missingRequiredCredentialKeys is empty when all required secrets are set.
Run tools
Section titled “Run tools”Run a tool with the customer’s API key. The run uses that customer’s credentials.
curl -X POST https://api.superglue.cloud/v1/tools/<tool-id>/run \ -H "Authorization: Bearer <customer-api-key>" \ -H "Content-Type: application/json" \ -d '{ "inputs": { "fromDate": "2026-09-01", "toDate": "2026-09-30" } }'The response contains status, data, and error. Save the result. A service account cannot read past runs.
For long runs, add "options": { "async": true, "webhookUrl": "https://<your-endpoint>" } to the body. superglue posts the finished run to your URL.
Delete a service account
Section titled “Delete a service account”Delete a service account from Organization, or with an admin API key:
curl -X DELETE https://api.superglue.cloud/v1/service-accounts/<service-account-id> \ -H "Authorization: Bearer <admin-api-key>"This also deletes its API key and all of its credentials.