Claude Platform Docs

Create Service Account Workspace Member

$ ant beta:organization:workspaces:service-accounts add
POST/v1/organizations/workspaces/{workspace_id}/service_accounts

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Add a service account to a workspace with the given workspace_role.

The role determines what the service account can do in the workspace and which workspace-scoped permissions it can be granted when authenticating through federation. Every service account is already an implicit workspace_user member of the default workspace; adding it explicitly assigns a chosen role. If the service account is already an explicit member of the workspace, its workspace_role is replaced with the value supplied here. Archived workspaces return 400. Archived service accounts cannot be added and are rejected.

Parameters
--workspace-id: string

Path param: ID of the workspace.

--service-account-id: string

Body param: Tagged service account ID to add.

--workspace-role: "workspace_admin" or "workspace_developer" or "workspace_restricted_developer" or "workspace_user"

Body param: Role to assign to the service account in this workspace.

--beta: optional array of AnthropicBeta

Header param: Optional header to specify the beta version(s) you want to use.

Returns
beta_service_account_workspace_member: object{ created_by_actor_id, implicit, service_account_id, 3 more }
created_by_actor_id: string

Tagged ID (user_.../svac_...) of the actor who created this membership.

implicit: boolean

True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed.

service_account_id: string

Tagged service account ID (svac_...).

type: "service_account_workspace_member"
workspace_id: string

Tagged workspace ID (wrkspc_...).

workspace_role: "workspace_admin" or "workspace_billing" or "workspace_developer" or 2 more

Role of the service account in this workspace. Service accounts cannot hold the workspace_billing role.

One of the following:
"workspace_admin"
"workspace_billing"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"

Create Service Account Workspace Member

ant beta:organization:workspaces:service-accounts add \
  --api-key my-anthropic-api-key \
  --workspace-id workspace_id \
  --service-account-id service_account_id \
  --workspace-role workspace_admin
{
  "created_by_actor_id": "created_by_actor_id",
  "implicit": true,
  "service_account_id": "service_account_id",
  "type": "service_account_workspace_member",
  "workspace_id": "workspace_id",
  "workspace_role": "workspace_admin"
}
Returns Examples
{
  "created_by_actor_id": "created_by_actor_id",
  "implicit": true,
  "service_account_id": "service_account_id",
  "type": "service_account_workspace_member",
  "workspace_id": "workspace_id",
  "workspace_role": "workspace_admin"
}