Skip to content

Service accounts

A service account is a superglue user that works only through its API key. Create one service account for each of your customers when your product runs superglue tools against your customers’ own accounts, such as their Ramp or Jira. Each service account holds only that customer’s credentials, so a key never reaches another customer’s data.

A service account key can:

  • Run the tools that the Service account role can view.
  • Create, read, update, and delete its own credentials.
  • Connect a customer’s account through OAuth for a system that the Service account role can view.

A service account cannot log in, use the agent or MCP, read run history, change tools or systems, or see other users’ credentials.

  1. Create the systems and tools your customers use. All service accounts share them.
  2. Create your first service account. This adds the Service account role to Access Rules.
  3. In Access Rules, open the Service account role. Grant Viewer on each system and tool that service accounts need. Viewer lets a service account use a tool without changing it.

These grants apply to every service account, including ones you create later.

Admins can create a service account in two ways:

  • On Organization, open the Invite users menu and choose Create service account.
  • With the API and an admin API key:
Terminal window
curl -X POST https://api.superglue.cloud/v1/service-accounts \
-H "Authorization: Bearer <admin-api-key>" \
-H "Content-Type: application/json" \
-d '{ "name": "Acme Inc" }'

The response contains data.serviceAccount.id and data.apiKey.

Self-hosted deployments use their own API and web app URLs in place of api.superglue.cloud and app.superglue.cloud.

  1. Set up the system with your own OAuth app: client ID, client secret, authorization URL, token URL, and scopes. In the provider’s app settings, add https://app.superglue.cloud/api/auth/callback as a redirect URI. Skip this step when the system uses a superglue managed OAuth app.

  2. When the customer clicks connect in your product, start the connection with the customer’s API key:

    Terminal window
    curl -X POST https://api.superglue.cloud/v1/oauth/exchanges \
    -H "Authorization: Bearer <customer-api-key>" \
    -H "Content-Type: application/json" \
    -d '{ "systemId": "<system-id>" }'
  3. Open data.authorizationUrl in a popup right away. The link expires after 5 minutes.

  4. The customer approves access with the provider. superglue stores the tokens and closes the popup.

  5. Check the connection with GET /v1/credentials?systemId=<system-id> and the customer’s API key. The customer is connected when credentialKeys contains access_token with hasValue: true.

superglue refreshes the tokens when they expire. To reconnect a customer, repeat these steps.

Collect the customer’s secrets in your product and store them with the customer’s API key. This example stores a Jira email and API token:

Terminal window
curl -X POST https://api.superglue.cloud/v1/credentials \
-H "Authorization: Bearer <customer-api-key>" \
-H "Content-Type: application/json" \
-d '{
"systemId": "<jira-system-id>",
"url": "https://acme.atlassian.net",
"credentials": { "email": "it@acme.com", "api_token": "<customer-api-token>" }
}'

Use the secret names that your system expects. url replaces the system’s URL for this customer only, for example their own Jira site. data.missingRequiredCredentialKeys is empty when all required secrets are set.

Run a tool with the customer’s API key. The run uses that customer’s credentials.

Terminal window
curl -X POST https://api.superglue.cloud/v1/tools/<tool-id>/run \
-H "Authorization: Bearer <customer-api-key>" \
-H "Content-Type: application/json" \
-d '{ "inputs": { "fromDate": "2026-09-01", "toDate": "2026-09-30" } }'

The response contains status, data, and error. Save the result. A service account cannot read past runs.

For long runs, add "options": { "async": true, "webhookUrl": "https://<your-endpoint>" } to the body. superglue posts the finished run to your URL.

Delete a service account from Organization, or with an admin API key:

Terminal window
curl -X DELETE https://api.superglue.cloud/v1/service-accounts/<service-account-id> \
-H "Authorization: Bearer <admin-api-key>"

This also deletes its API key and all of its credentials.