PipesHub Service Tokens API
The credential a service account authenticates with. A service token is an OAuth access token, so signing, hashing, revocation and the `/mcp` path are the same machinery personal access tokens use. What differs is the policy around it: an administrator mints it *for* a service account rather than for themselves, scopes must be chosen explicitly, `agent:execute` is refused so version one is read-only, and it always expires. The raw token is shown once, in the create response, and never again. Only its hash is stored. Service tokens carry a `phsvc_` prefix rather than the `phpat_` used by personal access tokens, so a secret scanner and anyone reading a log can tell a shared machine credential from one person's.