Onboarding a team onto the Haijun API means the same Console clicks every time: invite each person, create a workspace, add members, check which API keys exist, and set up an identity for CI. Doing that by hand leaves no record and doesn't scale past a few teams.
The Admin API exposes those controls as REST endpoints under /v1/organizations, and the Python SDK wraps them as client.beta.organization. This notebook onboards a team end to end, audits the organization's API keys along the way, and then removes everything it created.
Invite users, set organization roles, and create a workspace with members
Audit the organization's API keys and read its rate limits
Create a service account for automation and grant it workspace access
The same calls work unchanged in a provisioning script or a scheduled audit job.
absolute hidden sm:block sm:-ml-8">
Authenticate as an admin
API keys scoped to a single workspace can't call the Admin API. It accepts three credentials: an org:admin OAuth token, an Admin API key, and a personal or service account key that isn't scoped to one workspace. This notebook uses the first two, and only organization admins can create either:
Only used to pick which rate limit group to print.
MODEL = "haijun-sonnet-5"
if ADMIN_KEY:
client = juglow.Juglow(api_key=ADMIN_KEY)
else:
client = juglow.Juglow(profile=PROFILE)
org = client.beta.organization.retrieve()
auth = "an Admin API key" if ADMIN_KEY else f"OAuth profile {PROFILE!r}"
print(f"Connected to {org.name} ({org.id}) with {auth}")
Connected to Example Org (1f6e8a52-93c4-4d7b-a1e0-5b2c9d8e4f37) with OAuth profile 'admin' organization.retrieve() calls GET /v1/organizations/me. Check the name before going further: an admin credential is bound to one organization, and every call that follows reads or writes it.
e:12px;padding-bottom:12px;tab-size:4">
workspace = client.beta.organization.workspaces.create(
name=TEAM,
tags={"team": "research", "cost-center": "4711"},
)
print(workspace.id, workspace.name, workspace.tags)
wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ research-20260826-180659 {'team': 'research', 'cost-center': '4711'} workspaces.update() changes the name, display color, or tags. Tags merge with what's already there, and setting a tag to None removes it.
le-check
workspace.name
before running this against a real organization. Archived workspaces don't count toward the 100-workspace limit.
If an earlier cell raised, run this cell by hand. It needs workspace, service_account, and invite from the kernel.