> ## Documentation Index
> Fetch the complete documentation index at: https://docs.clarifeye.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a service account (org admin)

> Creates a member (role `member`) of the organization that cannot log in and never
receives emails. It has no store access until one is added with
`POST .../service-accounts/{user_id}/stores/`, and no key until one is minted with
`POST /organization-api-keys/`.




## OpenAPI

````yaml /api-reference/openapi-full.yaml post /organizations/{id}/service-accounts/
openapi: 3.0.3
info:
  title: Clarifeye Platform API — Full API Documentation
  description: >
    Complete REST API reference for the Clarifeye Platform.


    Documents every endpoint exposed by the platform — the public surface plus

    the advanced surface: pipeline customization (extraction flows, pipeline

    runs, warehouse tables, document tag/metadata configuration), the pre-MCP

    AI surface (agent settings, playground conversations, conversation-scoped

    feedback views, notifications), and the impersonation header. New AI

    integrations should consume knowledge via MCP rather than the

    conversation/agent-settings endpoints documented here.


    ## Authentication

    All endpoints require authentication. Include the Authorization header in
    every request using either format:

    - `Authorization: Token <token_key>`

    - `Authorization: Bearer <token_key>`


    ## Service accounts and API keys

    Integrations authenticate with an **API key** of a **service account**:

    - `Authorization: Bearer <key>` (keys start with `cfk_`)


    A service account is an ordinary member (role `member`) of one organization
    that cannot log

    in. Organization admins create it and mint its keys on the organization's
    *Service

    accounts* page (`/organizations/{id}/service-accounts/`,
    `/organization-api-keys/`), and

    give it access to knowledge stores with ordinary store permissions. A key is
    valid on every

    endpoint and acts as its service account: it reaches exactly the stores,
    with exactly the

    rights, the account was given. An account can hold several keys (each with
    its own name,

    optional expiry and revocation), so a key can be rotated without changing
    identity.


    A refused key answers **403** with one of: `Invalid API key.`, `API key
    revoked.`,

    `API key expired.`, `API key disabled.` (the service account is disabled).


    Any valid key may also call `POST /organizations/{id}/provision-user/` and

    `POST /organizations/{id}/deprovision-user/` for its own organization (the
    `{id}` in the

    path must be the key's organization). The email domains these may pre-create
    accounts for

    are configured by Clarifeye on the organization
    (`allowed_provisioning_domains`).


    ## Impersonation


    Certain endpoints support user impersonation for creating or listing data on
    behalf of other users.

    This is useful for integrating external systems that need to attribute
    actions to specific users.


    **Header:** `X-Impersonate-Email`


    **Required Permission:** `CAN_IMPERSONATE_OTHER_USERS` (for a person,
    contact Clarifeye to enable it; org admins grant it to a service account on
    the organization's Service accounts page)


    **Behavior:**

    - If the header is provided and the impersonator has the required
    permission, the action is performed as the target user

    - If the target user is not found, the request proceeds as the original
    authenticated user

    - If the target user does not have access to the project, the request
    proceeds as the original authenticated user

    - If the impersonator lacks the `CAN_IMPERSONATE_OTHER_USERS` permission,
    the header is ignored


    **With an API key** the request fails instead (**403**) whenever
    impersonation cannot

    happen: missing permission, unknown target, target without access to the
    store, target that

    is itself a service account, or an endpoint outside a store. A key never
    silently acts as

    its own service account when impersonation was asked for.
  version: 1.0.0
  contact:
    name: Clarifeye Support
servers:
  - url: https://eu.app.clarifeye.ai/api/v1
    description: EU
  - url: https://us.app.clarifeye.ai/api/v1
    description: US
security:
  - BearerAuth: []
  - TokenAuth: []
tags:
  - name: Users
    description: Manage users within a project
  - name: Invitations
    description: Manage project invitations
  - name: Documents
    description: Manage documents within a project
  - name: Agent Settings
    description: Manage AI agent configurations
  - name: Conversations
    description: Create and interact with AI-powered conversations
  - name: Interviews
    description: Assign and review structured interview conversations
  - name: Meetings
    description: >-
      Meetings Clara attends as a bot (Recall.ai) — live transcript, live
      insights, recording, and calendar scheduling (CLA-1843). Store admins
      only.
  - name: Feedback
    description: >-
      Submit and review feedback — standalone (content-only), agent-submitted
      (MCP), or linked to a conversation message
  - name: Tools
    description: Execute configured AI tools with custom parameters
  - name: Tables
    description: Perform CRUD operations on warehouse tables
  - name: Notifications
    description: Manage project-scoped notifications for users
  - name: Extraction Flows
    description: >-
      Manage extraction flows (auto-sync DAGs) — list, run, inspect statistics,
      update, and publish
  - name: Object Extractors
    description: |
      Extract structured data (instances of a Pydantic model) from chunks or
      blocks of documents. Update auto-creates a new `ObjectExtractorVersion`
      when version-bearing fields change.
  - name: Tag Extractors
    description: |
      Apply hierarchical metadata tags to chunks or documents using an LLM.
      Update auto-creates a new `TagExtractorVersion` when version-bearing
      fields change.
  - name: Chunks Extractors
    description: |
      Segment parsed documents into chunks for downstream processing.
      Update auto-creates a new `ChunksExtractorVersion` when version-bearing
      fields change.
  - name: Parsing Extractors
    description: |
      Convert source documents to text blocks via the parsing pipeline.
      Update auto-creates a new `ParsingExtractorVersion` when version-bearing
      fields change.
  - name: Document Filter Extractors
    description: |
      Restrict a downstream pipeline branch to documents matching a filter.
      Update auto-creates a new version when the filter changes.
  - name: Chunk Tag Filter Extractors
    description: |
      Restrict a downstream pipeline branch to chunks carrying specific tags.
      Update auto-creates a new version when the filter changes.
  - name: Document Tag Extractors
    description: |
      Apply a flat set of metadata tags to each document. Update auto-creates
      a new version when version-bearing fields change.
  - name: Tag Alerts Extractors
    description: |
      Run LLM-based alerts over already-extracted tag rows. Update auto-creates
      a new version when version-bearing fields change.
  - name: Object Alerts Extractors
    description: >
      Run LLM-based alerts over already-extracted object rows. Update
      auto-creates

      a new version when version-bearing fields change.
  - name: Imported Object Extractors
    description: |
      Hold objects imported from an external system (rather than extracted by
      an LLM). Useful for hydrating the warehouse with data produced outside
      the platform.
  - name: Pipeline Runs
    description: >-
      Inspect pipeline runs queued by extraction flows or other pipeline
      triggers — list runs and fetch the details/status of a single run
  - name: User Provisioning
    description: >
      Pre-create and de-provision org users via an org-scoped API key

      (`Authorization: Bearer <key>`). The organization is resolved from the
      key.
  - name: Organization API Keys
    description: >
      Superuser management of org-scoped provisioning API keys. Minting and
      revoking

      are superuser-only; org admins can list/retrieve/reveal their own org's
      keys.
  - name: Design System Templates
    description: Reference/example files attached to a design template.
  - name: Artifacts
    description: |
      Knowledge-store artifact catalog — list artifacts, create/edit custom
      artifacts, manage scope membership, read and publish versions, configure
      the cohesion guide, and export/import the whole catalog. For type-aware
      reads and edits of artifact content, prefer the
      `read-write-*-artifact` tool endpoints.
paths:
  /organizations/{id}/service-accounts/:
    parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
          format: uuid
    post:
      tags:
        - Service Accounts
      summary: Create a service account (org admin)
      description: >
        Creates a member (role `member`) of the organization that cannot log in
        and never

        receives emails. It has no store access until one is added with

        `POST .../service-accounts/{user_id}/stores/`, and no key until one is
        minted with

        `POST /organization-api-keys/`.
      operationId: createServiceAccount
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - name
              properties:
                name:
                  type: string
                  maxLength: 255
                  description: Unique in the organization (case-insensitive).
      responses:
        '201':
          description: Created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceAccount'
        '400':
          description: Missing name, or the name is already used in this organization.
        '403':
          description: Caller is not an admin of the organization.
components:
  schemas:
    ServiceAccount:
      type: object
      properties:
        id:
          type: string
          format: uuid
          description: The service account's user id.
        name:
          type: string
        is_active:
          type: boolean
        stores_count:
          type: integer
          description: Stores of this organization the account can access.
        keys_count:
          type: integer
          description: Active (not revoked, not expired) keys.
        last_used_at:
          type: string
          format: date-time
          nullable: true
        created_at:
          type: string
          format: date-time
        user_usage_limit_mode:
          type: string
          enum:
            - inherit
            - unlimited
            - custom
        user_usage_alert_ccu:
          type: number
          nullable: true
        user_usage_block_ccu:
          type: number
          nullable: true
        effective_alert_ccu:
          type: number
          nullable: true
        effective_block_ccu:
          type: number
          nullable: true
        period_ccu:
          type: number
          nullable: true
        alerted_this_period:
          type: boolean
        blocked:
          type: boolean
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >
        Use `Authorization: Bearer <token>`. The token is either a user token /
        OAuth access

        token, or a service-account API key (`cfk_...`). A key is valid on every
        endpoint and

        acts as its service account, an organization member with per-store
        permissions.

        Refused keys answer 403 with `Invalid API key.`, `API key revoked.`,

        `API key expired.` or `API key disabled.`.
    TokenAuth:
      type: apiKey
      in: header
      name: Authorization
      description: 'Use Authorization: Token <token>'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.