Only organization admins can manage service accounts.
Create a service account
- Open your organization and click Service accounts in the sidebar.
- Click New service account.
- Enter a Name. Name it after the integration that will use it, for example
Customer portal. Names must be unique in the organization. - Click Create. The service account’s page opens.
Give it access to knowledge stores
A service account can only reach the stores you add it to.- On the service account’s page, under Knowledge stores, click Add store.
- Select the Knowledge store.
- Choose a profile: Technical User (the default), Contributor, or User. See User management.
- Choose its permissions:
- DataReader and Admin, as for any user. See User management.
- Impersonate: lets the integration act on behalf of a member of the store. See Act on behalf of a user.
- Click Save.
Create an API key
- On the service account’s page, under API keys, click Create key.
- Enter a Name, for example
production. - Set Expires on. It defaults to one year from today. Leave it empty for a key that never expires.
- Click Create, then copy the key.
cfk_. Store the key in your integration’s secret manager: anyone holding it can act as the service account. Organization admins can show an active key again later with Reveal on the key’s row.
Authenticate with a key
Send the key as a bearer token on Clarifeye REST API requests:eu.app.clarifeye.ai with your own server if you’re on another environment or a dedicated deployment.
A request with a revoked, expired, or invalid key, or with a key of a disabled service account, is refused with HTTP 403.
Act on behalf of a user
With the Impersonate permission on a store, an integration can act as a specific member of that store by adding theX-Impersonate-Email header:
Rotate a key
Several keys can be active at once, so you can rotate without downtime:- Create a new key.
- Switch your integration to the new key.
- Click Revoke on the old key’s row.
Set a usage limit
Under Usage limit, choose:- Organization default: the per-user limits set on the Usage page.
- Custom limit for this service account: set Notify them at and Block them at, in CCU.
- No limit.