AIR Service Accounts
Machine credentials for a domain. Domain owners/admins create service accounts and mint bearer API keys for them. Active keys can be copied again via revealKey. Revoked keys fail authentication immediately.
List service accounts
Lists machine principals in the caller domain. Requires domain owner or admin role; members receive 403.
Create service account
Creates a service account for API integrations in the caller domain. Requires domain owner or admin role.
List API keys for a service account
Returns masked key metadata (pid, prefix, scopes, timestamps). Never includes raw secrets or hashes. Returns 404 for foreign service-account pids.
Create API key
Mints a bearer API key scoped to this domain. Requires a non-empty `scopes` array.
Reveal API key
Returns the full bearer token for an active API key. Requires domain owner or admin role.
Revoke API key
Revokes a key immediately; subsequent bearer requests with that key return 401. Returns 404 for foreign pids.