PipesHub Service Accounts API
Machine identities that automation authenticates as, so a script reads with its own permissions rather than borrowing a person's. A service account is an ordinary user record with `kind: "service"`. It appears in the permission graph the same way people do, so "what can this account see" is answered by the same code that answers it for a colleague. It can never sign in, and it is always a member, never an administrator. Every route is admin-only, and for OAuth tokens and personal access tokens the scopes below are enforced as well — creating a service account grants access to the organisation's documents, so a narrowly scoped credential cannot do it merely because its owner is an admin.