Haijun Platform Docs
ID

List Workspaces

GET /v1/organizations/workspaces

List Workspaces

Query parameters

  • after_id: optional string

ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.

  • before_id: optional string

ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.

  • include_archived: optional boolean

Whether to include Workspaces that have been archived in the response

default: false

  • limit: optional number

Number of items to return per page.

Defaults to 20. Ranges from 1 to 1000.

default: 20, minimum: 1, maximum: 1000

Returns

  • data: array of BetaWorkspace
  • type: "workspace"

Object type.

For Workspaces, this is always "workspace".

default: workspace

  • id: string

ID of the Workspace.

  • archived_at: string or null

RFC 3339 datetime string indicating when the Workspace was archived, or null if the Workspace is not archived.

format: date-time

  • compartment_id: string

Identifier for this Workspace's encryption compartment. When you configure a customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Juglow enforces the compartment binding automatically; you do not need to reference this value in your key configuration. See the CMEK integration guide for the required key configuration; unless your organization is on Haijun Platform on AWS, it includes a separate value used during key validation. On Haijun Platform on AWS there is no separate validation value: the key is validated against this Workspace's own value when it is attached, so if your key policy uses the compartment condition, add this value to it before attaching the key.

  • created_at: string

RFC 3339 datetime string indicating when the Workspace was created.

format: date-time

  • data_residency: BetaDataResidency

Data residency configuration.

  • allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"

Permitted inference geo values. 'unrestricted' means all geos are allowed.

  • Geos = array of BetaAllowedInferenceGeo
  • "global"
  • "us"
  • Unrestricted = "unrestricted"
  • default_inference_geo: "global" or "us"

Default inference geo applied when requests omit the parameter.

  • "global"
  • "us"
  • workspace_geo: "us"

Geographic region for workspace data storage. Immutable after creation.

  • display_color: string

Hex color code representing the Workspace in the Juglow Console.

  • external_key_id: string or null

ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.

  • name: string

Name of the Workspace.

  • tags: map[string]

User-defined tags as string key-value pairs. Keys may not begin with juglow.

  • first_id: string or null

First ID in the data list. Can be used as the before_id for the previous page.

  • has_more: boolean

Indicates if there are more results in the requested page direction.

  • last_id: string or null

Last ID in the data list. Can be used as the after_id for the next page.

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "data": [
    {
      "id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
      "archived_at": "2024-11-01T23:59:27.427722Z",
      "compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
      "created_at": "2024-10-30T23:58:27.427722Z",
      "data_residency": {
        "allowed_inference_geos": "unrestricted",
        "default_inference_geo": "global",
        "workspace_geo": "us"
      },
      "display_color": "#6C5BB9",
      "external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
      "name": "Workspace Name",
      "tags": {
        "env": "prod",
        "team": "platform"
      },
      "type": "workspace"
    }
  ],
  "first_id": "first_id",
  "has_more": true,
  "last_id": "last_id"
}

Create Workspace

POST /v1/organizations/workspaces

Create Workspace

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"

Body parameters

  • name: string

Name of the Workspace.

minLength: 1, maxLength: 40

  • data_residency: optional BetaDataResidencyCreateConfig or null

Data residency configuration for the workspace. If omitted, defaults to workspace_geo: "us", allowed_inference_geos: "unrestricted", and default_inference_geo: "global".

  • allowed_inference_geos: optional array of BetaAllowedInferenceGeo or "unrestricted" or null

Permitted inference geo values. Defaults to 'unrestricted' if omitted, which allows all geos. Use the string 'unrestricted' to allow all geos, or a list of specific geos.

  • Geos = array of BetaAllowedInferenceGeo
  • "global"
  • "us"
  • Unrestricted = "unrestricted"
  • default_inference_geo: optional "global" or "us" or null

Default inference geo applied when requests omit the parameter. Defaults to 'global' if omitted. Must be a member of allowed_inference_geos unless allowed_inference_geos is "unrestricted".

  • "global"
  • "us"
  • workspace_geo: optional "us" or null

Geographic region for workspace data storage. Immutable after creation. Defaults to 'us' if omitted.

  • display_color: optional string or null

Hex color code representing the Workspace in the Juglow Console.

maxLength: 7, pattern: ^#[0-9A-Fa-f]{6}$

  • external_key_id: optional string or null

ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.

  • tags: optional map[string] or null

User-defined tags as string key-value pairs. Keys may not begin with juglow.

Returns

  • BetaWorkspace object
  • type: "workspace"

Object type.

For Workspaces, this is always "workspace".

default: workspace

  • id: string

ID of the Workspace.

  • archived_at: string or null

RFC 3339 datetime string indicating when the Workspace was archived, or null if the Workspace is not archived.

format: date-time

  • compartment_id: string

Identifier for this Workspace's encryption compartment. When you configure a customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Juglow enforces the compartment binding automatically; you do not need to reference this value in your key configuration. See the CMEK integration guide for the required key configuration; unless your organization is on Haijun Platform on AWS, it includes a separate value used during key validation. On Haijun Platform on AWS there is no separate validation value: the key is validated against this Workspace's own value when it is attached, so if your key policy uses the compartment condition, add this value to it before attaching the key.

  • created_at: string

RFC 3339 datetime string indicating when the Workspace was created.

format: date-time

  • data_residency: BetaDataResidency

Data residency configuration.

  • allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"

Permitted inference geo values. 'unrestricted' means all geos are allowed.

  • Geos = array of BetaAllowedInferenceGeo
  • "global"
  • "us"
  • Unrestricted = "unrestricted"
  • default_inference_geo: "global" or "us"

Default inference geo applied when requests omit the parameter.

  • "global"
  • "us"
  • workspace_geo: "us"

Geographic region for workspace data storage. Immutable after creation.

  • display_color: string

Hex color code representing the Workspace in the Juglow Console.

  • external_key_id: string or null

ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.

  • name: string

Name of the Workspace.

  • tags: map[string]

User-defined tags as string key-value pairs. Keys may not begin with juglow.

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{
          "name": "x",
          "display_color": "#6C5BB9",
          "external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
          "tags": {
            "env": "prod",
            "team": "platform"
          }
        }'

Response (200)

json
{
  "id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
  "archived_at": "2024-11-01T23:59:27.427722Z",
  "compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
  "created_at": "2024-10-30T23:58:27.427722Z",
  "data_residency": {
    "allowed_inference_geos": "unrestricted",
    "default_inference_geo": "global",
    "workspace_geo": "us"
  },
  "display_color": "#6C5BB9",
  "external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
  "name": "Workspace Name",
  "tags": {
    "env": "prod",
    "team": "platform"
  },
  "type": "workspace"
}

Get Workspace

GET /v1/organizations/workspaces/{workspace_id}

Get Workspace

Path parameters

  • workspace_id: string

ID of the Workspace.

Returns

  • BetaWorkspace object
  • type: "workspace"

Object type.

For Workspaces, this is always "workspace".

default: workspace

  • id: string

ID of the Workspace.

  • archived_at: string or null

RFC 3339 datetime string indicating when the Workspace was archived, or null if the Workspace is not archived.

format: date-time

  • compartment_id: string

Identifier for this Workspace's encryption compartment. When you configure a customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Juglow enforces the compartment binding automatically; you do not need to reference this value in your key configuration. See the CMEK integration guide for the required key configuration; unless your organization is on Haijun Platform on AWS, it includes a separate value used during key validation. On Haijun Platform on AWS there is no separate validation value: the key is validated against this Workspace's own value when it is attached, so if your key policy uses the compartment condition, add this value to it before attaching the key.

  • created_at: string

RFC 3339 datetime string indicating when the Workspace was created.

format: date-time

  • data_residency: BetaDataResidency

Data residency configuration.

  • allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"

Permitted inference geo values. 'unrestricted' means all geos are allowed.

  • Geos = array of BetaAllowedInferenceGeo
  • "global"
  • "us"
  • Unrestricted = "unrestricted"
  • default_inference_geo: "global" or "us"

Default inference geo applied when requests omit the parameter.

  • "global"
  • "us"
  • workspace_geo: "us"

Geographic region for workspace data storage. Immutable after creation.

  • display_color: string

Hex color code representing the Workspace in the Juglow Console.

  • external_key_id: string or null

ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.

  • name: string

Name of the Workspace.

  • tags: map[string]

User-defined tags as string key-value pairs. Keys may not begin with juglow.

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
  "archived_at": "2024-11-01T23:59:27.427722Z",
  "compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
  "created_at": "2024-10-30T23:58:27.427722Z",
  "data_residency": {
    "allowed_inference_geos": "unrestricted",
    "default_inference_geo": "global",
    "workspace_geo": "us"
  },
  "display_color": "#6C5BB9",
  "external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
  "name": "Workspace Name",
  "tags": {
    "env": "prod",
    "team": "platform"
  },
  "type": "workspace"
}

Update Workspace

POST /v1/organizations/workspaces/{workspace_id}

Update Workspace

Path parameters

  • workspace_id: string

Body parameters

  • data_residency: optional BetaDataResidencyUpdateConfig or null

Data residency configuration for the workspace.

  • allowed_inference_geos: optional array of BetaAllowedInferenceGeo or "unrestricted" or null

Permitted inference geo values. Use 'unrestricted' to allow all geos, or a list of specific geos.

  • Geos = array of BetaAllowedInferenceGeo
  • "global"
  • "us"
  • Unrestricted = "unrestricted"
  • default_inference_geo: optional "global" or "us" or null

Default inference geo applied when requests omit the parameter. Must be a member of allowed_inference_geos unless allowed_inference_geos is "unrestricted".

  • "global"
  • "us"
  • display_color: optional string

Hex color code representing the Workspace in the Juglow Console.

maxLength: 7, pattern: ^#[0-9A-Fa-f]{6}$

  • external_key_id: optional string

ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.

  • name: optional string

Name of the Workspace.

minLength: 1, maxLength: 40

  • tags: optional map[string] or null

User-defined tags as string key-value pairs. Keys may not begin with juglow.

Returns

  • BetaWorkspace object
  • type: "workspace"

Object type.

For Workspaces, this is always "workspace".

default: workspace

  • id: string

ID of the Workspace.

  • archived_at: string or null

RFC 3339 datetime string indicating when the Workspace was archived, or null if the Workspace is not archived.

format: date-time

  • compartment_id: string

Identifier for this Workspace's encryption compartment. When you configure a customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Juglow enforces the compartment binding automatically; you do not need to reference this value in your key configuration. See the CMEK integration guide for the required key configuration; unless your organization is on Haijun Platform on AWS, it includes a separate value used during key validation. On Haijun Platform on AWS there is no separate validation value: the key is validated against this Workspace's own value when it is attached, so if your key policy uses the compartment condition, add this value to it before attaching the key.

  • created_at: string

RFC 3339 datetime string indicating when the Workspace was created.

format: date-time

  • data_residency: BetaDataResidency

Data residency configuration.

  • allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"

Permitted inference geo values. 'unrestricted' means all geos are allowed.

  • Geos = array of BetaAllowedInferenceGeo
  • "global"
  • "us"
  • Unrestricted = "unrestricted"
  • default_inference_geo: "global" or "us"

Default inference geo applied when requests omit the parameter.

  • "global"
  • "us"
  • workspace_geo: "us"

Geographic region for workspace data storage. Immutable after creation.

  • display_color: string

Hex color code representing the Workspace in the Juglow Console.

  • external_key_id: string or null

ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.

  • name: string

Name of the Workspace.

  • tags: map[string]

User-defined tags as string key-value pairs. Keys may not begin with juglow.

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{
          "display_color": "#6C5BB9",
          "external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
          "tags": {
            "env": "prod",
            "team": "platform"
          }
        }'

Response (200)

json
{
  "id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
  "archived_at": "2024-11-01T23:59:27.427722Z",
  "compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
  "created_at": "2024-10-30T23:58:27.427722Z",
  "data_residency": {
    "allowed_inference_geos": "unrestricted",
    "default_inference_geo": "global",
    "workspace_geo": "us"
  },
  "display_color": "#6C5BB9",
  "external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
  "name": "Workspace Name",
  "tags": {
    "env": "prod",
    "team": "platform"
  },
  "type": "workspace"
}

Archive Workspace

POST /v1/organizations/workspaces/{workspace_id}/archive

Archive Workspace

Path parameters

  • workspace_id: string

Returns

  • BetaWorkspace object
  • type: "workspace"

Object type.

For Workspaces, this is always "workspace".

default: workspace

  • id: string

ID of the Workspace.

  • archived_at: string or null

RFC 3339 datetime string indicating when the Workspace was archived, or null if the Workspace is not archived.

format: date-time

  • compartment_id: string

Identifier for this Workspace's encryption compartment. When you configure a customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Juglow enforces the compartment binding automatically; you do not need to reference this value in your key configuration. See the CMEK integration guide for the required key configuration; unless your organization is on Haijun Platform on AWS, it includes a separate value used during key validation. On Haijun Platform on AWS there is no separate validation value: the key is validated against this Workspace's own value when it is attached, so if your key policy uses the compartment condition, add this value to it before attaching the key.

  • created_at: string

RFC 3339 datetime string indicating when the Workspace was created.

format: date-time

  • data_residency: BetaDataResidency

Data residency configuration.

  • allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"

Permitted inference geo values. 'unrestricted' means all geos are allowed.

  • Geos = array of BetaAllowedInferenceGeo
  • "global"
  • "us"
  • Unrestricted = "unrestricted"
  • default_inference_geo: "global" or "us"

Default inference geo applied when requests omit the parameter.

  • "global"
  • "us"
  • workspace_geo: "us"

Geographic region for workspace data storage. Immutable after creation.

  • display_color: string

Hex color code representing the Workspace in the Juglow Console.

  • external_key_id: string or null

ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.

  • name: string

Name of the Workspace.

  • tags: map[string]

User-defined tags as string key-value pairs. Keys may not begin with juglow.

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/archive \
    -X POST \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
  "archived_at": "2024-11-01T23:59:27.427722Z",
  "compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
  "created_at": "2024-10-30T23:58:27.427722Z",
  "data_residency": {
    "allowed_inference_geos": "unrestricted",
    "default_inference_geo": "global",
    "workspace_geo": "us"
  },
  "display_color": "#6C5BB9",
  "external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
  "name": "Workspace Name",
  "tags": {
    "env": "prod",
    "team": "platform"
  },
  "type": "workspace"
}

Domain types

Beta Allowed Inference Geo

  • BetaAllowedInferenceGeo = "global" or "us"
  • "global"
  • "us"

Beta Data Residency

  • BetaDataResidency object
  • allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"

Permitted inference geo values. 'unrestricted' means all geos are allowed.

  • Geos = array of BetaAllowedInferenceGeo
  • "global"
  • "us"
  • Unrestricted = "unrestricted"
  • default_inference_geo: "global" or "us"

Default inference geo applied when requests omit the parameter.

  • "global"
  • "us"
  • workspace_geo: "us"

Geographic region for workspace data storage. Immutable after creation.

Beta Data Residency Create Config

  • BetaDataResidencyCreateConfig object
  • allowed_inference_geos: optional array of BetaAllowedInferenceGeo or "unrestricted" or null

Permitted inference geo values. Defaults to 'unrestricted' if omitted, which allows all geos. Use the string 'unrestricted' to allow all geos, or a list of specific geos.

  • Geos = array of BetaAllowedInferenceGeo
  • "global"
  • "us"
  • Unrestricted = "unrestricted"
  • default_inference_geo: optional "global" or "us" or null

Default inference geo applied when requests omit the parameter. Defaults to 'global' if omitted. Must be a member of allowed_inference_geos unless allowed_inference_geos is "unrestricted".

  • "global"
  • "us"
  • workspace_geo: optional "us" or null

Geographic region for workspace data storage. Immutable after creation. Defaults to 'us' if omitted.

Beta Data Residency Update Config

  • BetaDataResidencyUpdateConfig object
  • allowed_inference_geos: optional array of BetaAllowedInferenceGeo or "unrestricted" or null

Permitted inference geo values. Use 'unrestricted' to allow all geos, or a list of specific geos.

  • Geos = array of BetaAllowedInferenceGeo
  • "global"
  • "us"
  • Unrestricted = "unrestricted"
  • default_inference_geo: optional "global" or "us" or null

Default inference geo applied when requests omit the parameter. Must be a member of allowed_inference_geos unless allowed_inference_geos is "unrestricted".

  • "global"
  • "us"

Beta No Billing Workspace Role

  • BetaNoBillingWorkspaceRole = "workspace_admin" or "workspace_developer" or "workspace_restricted_developer" or "workspace_user"
  • "workspace_admin"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"

Beta Workspace

  • BetaWorkspace object
  • type: "workspace"

Object type.

For Workspaces, this is always "workspace".

default: workspace

  • id: string

ID of the Workspace.

  • archived_at: string or null

RFC 3339 datetime string indicating when the Workspace was archived, or null if the Workspace is not archived.

format: date-time

  • compartment_id: string

Identifier for this Workspace's encryption compartment. When you configure a customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Juglow enforces the compartment binding automatically; you do not need to reference this value in your key configuration. See the CMEK integration guide for the required key configuration; unless your organization is on Haijun Platform on AWS, it includes a separate value used during key validation. On Haijun Platform on AWS there is no separate validation value: the key is validated against this Workspace's own value when it is attached, so if your key policy uses the compartment condition, add this value to it before attaching the key.

  • created_at: string

RFC 3339 datetime string indicating when the Workspace was created.

format: date-time

  • data_residency: BetaDataResidency

Data residency configuration.

  • allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"

Permitted inference geo values. 'unrestricted' means all geos are allowed.

  • Geos = array of BetaAllowedInferenceGeo
  • "global"
  • "us"
  • Unrestricted = "unrestricted"
  • default_inference_geo: "global" or "us"

Default inference geo applied when requests omit the parameter.

  • "global"
  • "us"
  • workspace_geo: "us"

Geographic region for workspace data storage. Immutable after creation.

  • display_color: string

Hex color code representing the Workspace in the Juglow Console.

  • external_key_id: string or null

ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.

  • name: string

Name of the Workspace.

  • tags: map[string]

User-defined tags as string key-value pairs. Keys may not begin with juglow.

Beta Workspace Member

  • BetaWorkspaceMember object
  • type: "workspace_member"

Object type.

For Workspace Members, this is always "workspace_member".

default: workspace_member

  • user_id: string

ID of the User.

  • workspace_id: string

ID of the Workspace.

  • workspace_role: BetaWorkspaceRole

Role of the Workspace Member.

  • "workspace_admin"
  • "workspace_billing"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"

Beta Workspace Role

  • BetaWorkspaceRole = "workspace_admin" or "workspace_billing" or "workspace_developer" or 2 more
  • "workspace_admin"
  • "workspace_billing"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"

Workspaces › Rate Limits

List Workspace Rate Limits

GET /v1/organizations/workspaces/{workspace_id}/rate_limits

List a workspace's rate limits.

By default, returns only the groups and limiter types that have a workspace-level override. With include_inherited=true, returns every group with organization-level limits the workspace can see, listing for each the values it inherits from the organization as well as its own overrides. Each value's source says which it is.

When limit is omitted, every matching entry is returned in a single page; when limit truncates the result, follow next_page to fetch the remaining entries.

Path parameters

  • workspace_id: string

The ID of the workspace.

Query parameters

  • group_type: optional "batch" or "files" or "model_group" or 3 more

Filter by group type.

  • "batch"
  • "files"
  • "model_group"
  • "tracks"
  • "token_count"
  • "web_search"
  • include_inherited: optional boolean

Also list the limiter values the workspace inherits from the organization, including groups with no workspace-level override.

default: false

  • limit: optional number

Maximum number of items to return per page. Ranges from 1 to 1000.

When omitted, every remaining entry is returned in a single page and next_page is null.

minimum: 1, maximum: 1000

  • page: optional string

Opaque cursor from a previous response's next_page.

Returns

  • data: array of BetaWorkspaceRateLimit

Rate-limit entries for the workspace: one per group with at least one override, or, with include_inherited set to true, one per group the workspace can see that has organization-level limits.

  • type: "workspace_rate_limit"

Object type. Always workspace_rate_limit for workspace rate-limit entries.

default: workspace_rate_limit

  • group: BetaOrganizationRateLimitModelGroup or BetaOrganizationRateLimitBatchGroup or BetaOrganizationRateLimitTokenCountGroup or 3 more

The rate-limit group this entry's limits apply to. Its type equals group_type.

  • BetaOrganizationRateLimitModelGroup object
  • type: "model_group"

Always model_group: a family of models.

default: model_group

  • id: string

Opaque identifier of the rate-limit group (for example, rlg_01VPTCmyiu5ZLsWkcxYG2pY8). It is the same in every organization and never changes, unlike the entry's own identifier, which differs per organization.

  • display_name: string

Human-readable name of the model group (for example, Haijun Sonnet 4.x). For display only; it may change.

  • BetaOrganizationRateLimitBatchGroup object
  • type: "batch"

Always batch: the Message Batches API.

default: batch

  • id: string

Opaque identifier of the rate-limit group (for example, rlg_01VPTCmyiu5ZLsWkcxYG2pY8). It is the same in every organization and never changes, unlike the entry's own identifier, which differs per organization.

  • BetaOrganizationRateLimitTokenCountGroup object
  • type: "token_count"

Always token_count: the Token Count API.

default: token_count

  • id: string

Opaque identifier of the rate-limit group (for example, rlg_01VPTCmyiu5ZLsWkcxYG2pY8). It is the same in every organization and never changes, unlike the entry's own identifier, which differs per organization.

  • BetaOrganizationRateLimitFilesGroup object
  • type: "files"

Always files: the Files API.

default: files

  • id: string

Opaque identifier of the rate-limit group (for example, rlg_01VPTCmyiu5ZLsWkcxYG2pY8). It is the same in every organization and never changes, unlike the entry's own identifier, which differs per organization.

  • BetaOrganizationRateLimitSkillsGroup object
  • type: "tracks"

Always tracks: the Tracks API.

default: tracks

  • id: string

Opaque identifier of the rate-limit group (for example, rlg_01VPTCmyiu5ZLsWkcxYG2pY8). It is the same in every organization and never changes, unlike the entry's own identifier, which differs per organization.

  • BetaOrganizationRateLimitWebSearchGroup object
  • type: "web_search"

Always web_search: the Messages API web search tool.

default: web_search

  • id: string

Opaque identifier of the rate-limit group (for example, rlg_01VPTCmyiu5ZLsWkcxYG2pY8). It is the same in every organization and never changes, unlike the entry's own identifier, which differs per organization.

  • limits: array of BetaWorkspaceRateLimitValue

The workspace's limiter values for this group. By default only the limiter types with a workspace-level override are listed. With include_inherited set to true, the limiter types the workspace inherits from the organization are listed too, each marked by source.

  • type: string

The limiter type (for example, requests_per_minute or input_tokens_per_minute).

  • org_limit: number or null

The organization-level value for the same limiter type, for reference. null when the organization has no limit configured for this limiter type.

  • source: BetaWorkspaceRateLimitWorkspaceSource or BetaWorkspaceRateLimitOrganizationSource

Where value comes from. organization values are listed only when include_inherited is true, and then value equals org_limit.

  • BetaWorkspaceRateLimitWorkspaceSource object
  • type: "workspace"

Always workspace: a workspace-level override is stored.

default: workspace

  • BetaWorkspaceRateLimitOrganizationSource object
  • type: "organization"

Always organization: no workspace-level override is stored, so the organization's value applies.

default: organization

  • value: number

The workspace's value for this limiter type: the workspace-level override when source.type is workspace, otherwise the organization's value.

  • models: array of string or null

Model names this entry's limits apply to, including aliases. null when group_type is not "model_group".

  • rate_limit_id: string

The id of the organization's RateLimit entry this entry applies to.

  • workspace_id: string

ID of the Workspace this entry applies to.

  • group_type: "batch" or "files" or "model_group" or 3 more

Deprecated: Use group.type instead. group_type is still returned and always equals group.type.

Deprecated: use group.type instead. The kind of rate-limit group this entry represents. model_group entries apply to a family of models (listed in models); other values apply to an API-surface category and have models set to null. Always equal to group.type.

  • "batch"
  • "files"
  • "model_group"
  • "tracks"
  • "token_count"
  • "web_search"
  • next_page: string or null

Opaque cursor for the next page of results, or null when no entries remain beyond this response.

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/rate_limits \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"
Response (200)
json
{
  "data": [
    {
      "group": {
        "id": "id",
        "display_name": "display_name",
        "type": "model_group"
      },
      "group_type": "batch",
      "limits": [
        {
          "org_limit": 0,
          "source": {
            "type": "workspace"
          },
          "type": "type",
          "value": 0
        }
      ],
      "models": [
        "string"
      ],
      "rate_limit_id": "rate_limit_id",
      "type": "workspace_rate_limit",
      "workspace_id": "workspace_id"
    }
  ],
  "next_page": "next_page"
}

Workspaces › Members

List Workspace Members

GET /v1/organizations/workspaces/{workspace_id}/members

List Workspace Members

Path parameters

  • workspace_id: string

ID of the Workspace.

Query parameters

  • after_id: optional string

ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.

  • before_id: optional string

ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.

  • limit: optional number

Number of items to return per page.

Defaults to 20. Ranges from 1 to 1000.

default: 20, minimum: 1, maximum: 1000

Returns

  • data: array of BetaWorkspaceMember
  • type: "workspace_member"

Object type.

For Workspace Members, this is always "workspace_member".

default: workspace_member

  • user_id: string

ID of the User.

  • workspace_id: string

ID of the Workspace.

  • workspace_role: BetaWorkspaceRole

Role of the Workspace Member.

  • "workspace_admin"
  • "workspace_billing"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"
  • first_id: string or null

First ID in the data list. Can be used as the before_id for the previous page.

  • has_more: boolean

Indicates if there are more results in the requested page direction.

  • last_id: string or null

Last ID in the data list. Can be used as the after_id for the next page.

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/members \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"
Response (200)
json
{
  "data": [
    {
      "type": "workspace_member",
      "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
      "workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
      "workspace_role": "workspace_admin"
    }
  ],
  "first_id": "first_id",
  "has_more": true,
  "last_id": "last_id"
}

Create Workspace Member

POST /v1/organizations/workspaces/{workspace_id}/members

Create Workspace Member

Path parameters

  • workspace_id: string

ID of the Workspace.

Body parameters

  • user_id: string

ID of the User.

  • workspace_role: BetaNoBillingWorkspaceRole

Role of the new Workspace Member. Cannot be workspace_billing.

  • "workspace_admin"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"

Returns

  • BetaWorkspaceMember object
  • type: "workspace_member"

Object type.

For Workspace Members, this is always "workspace_member".

default: workspace_member

  • user_id: string

ID of the User.

  • workspace_id: string

ID of the Workspace.

  • workspace_role: BetaWorkspaceRole

Role of the Workspace Member.

  • "workspace_admin"
  • "workspace_billing"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/members \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{
          "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
          "workspace_role": "workspace_admin"
        }'
Response (200)
json
{
  "type": "workspace_member",
  "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
  "workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
  "workspace_role": "workspace_admin"
}

Get Workspace Member

GET /v1/organizations/workspaces/{workspace_id}/members/{user_id}

Get Workspace Member

Path parameters

  • workspace_id: string

ID of the Workspace.

  • user_id: string

ID of the User.

Returns

  • BetaWorkspaceMember object
  • type: "workspace_member"

Object type.

For Workspace Members, this is always "workspace_member".

default: workspace_member

  • user_id: string

ID of the User.

  • workspace_id: string

ID of the Workspace.

  • workspace_role: BetaWorkspaceRole

Role of the Workspace Member.

  • "workspace_admin"
  • "workspace_billing"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"
Response (200)
json
{
  "type": "workspace_member",
  "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
  "workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
  "workspace_role": "workspace_admin"
}

Update Workspace Member

POST /v1/organizations/workspaces/{workspace_id}/members/{user_id}

Update Workspace Member

Path parameters

  • workspace_id: string

ID of the Workspace.

  • user_id: string

ID of the User.

Body parameters

  • workspace_role: BetaWorkspaceRole

New workspace role for the User.

  • "workspace_admin"
  • "workspace_billing"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"

Returns

  • BetaWorkspaceMember object
  • type: "workspace_member"

Object type.

For Workspace Members, this is always "workspace_member".

default: workspace_member

  • user_id: string

ID of the User.

  • workspace_id: string

ID of the Workspace.

  • workspace_role: BetaWorkspaceRole

Role of the Workspace Member.

  • "workspace_admin"
  • "workspace_billing"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{
          "workspace_role": "workspace_admin"
        }'
Response (200)
json
{
  "type": "workspace_member",
  "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
  "workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
  "workspace_role": "workspace_admin"
}

Delete Workspace Member

DELETE /v1/organizations/workspaces/{workspace_id}/members/{user_id}

Delete Workspace Member

Path parameters

  • workspace_id: string

ID of the Workspace.

  • user_id: string

ID of the User.

Returns

  • type: "workspace_member_deleted"

Deleted object type.

For Workspace Members, this is always "workspace_member_deleted".

default: workspace_member_deleted

  • user_id: string

ID of the User.

  • workspace_id: string

ID of the Workspace.

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \
    -X DELETE \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"
Response (200)
json
{
  "type": "workspace_member_deleted",
  "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
  "workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
}

Workspaces › Service Accounts

List Service Account Workspace Members

GET /v1/organizations/workspaces/{workspace_id}/service_accounts

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

List the service accounts that are members of a workspace.

Each entry includes the service account's workspace_role. Use limit and the next_page cursor to paginate. Archived workspaces return 400; use GET /service_accounts/{id}/workspaces to audit memberships of an archived workspace. The implicit default-workspace membership is not included in this list. Memberships of archived service accounts are omitted from the results.

Path parameters

  • workspace_id: string

ID of the workspace.

Query parameters

  • limit: optional number

Number of results per page.

default: 20, minimum: 1, maximum: 100

  • page: optional string

Opaque cursor from a previous response's next_page.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"

Returns

  • data: array of BetaServiceAccountWorkspaceMember
  • type: "service_account_workspace_member"

default: service_account_workspace_member

  • created_by_actor_id: string or null

Tagged ID (user_.../svac_...) of the actor who created this membership.

  • implicit: boolean or null

True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed.

  • service_account_id: string

Tagged service account ID (svac_...).

  • workspace_id: string

Tagged workspace ID (wrkspc_...).

  • workspace_role: BetaWorkspaceRole

Role of the service account in this workspace. Service accounts cannot hold the workspace_billing role.

  • "workspace_admin"
  • "workspace_billing"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"
  • next_page: string or null

Opaque cursor for the next page, or null if no more results.

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"
Response (200)
json
{
  "data": [
    {
      "created_by_actor_id": "created_by_actor_id",
      "implicit": true,
      "service_account_id": "service_account_id",
      "type": "service_account_workspace_member",
      "workspace_id": "workspace_id",
      "workspace_role": "workspace_admin"
    }
  ],
  "next_page": "next_page"
}

Create Service Account Workspace Member

POST /v1/organizations/workspaces/{workspace_id}/service_accounts

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Add a service account to a workspace with the given workspace_role.

The role determines what the service account can do in the workspace and which workspace-scoped permissions it can be granted when authenticating through federation. Every service account is already an implicit workspace_user member of the default workspace; adding it explicitly assigns a chosen role. If the service account is already an explicit member of the workspace, its workspace_role is replaced with the value supplied here. Archived workspaces return 400. Archived service accounts cannot be added and are rejected.

Path parameters

  • workspace_id: string

ID of the workspace.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"

Body parameters

  • service_account_id: string

Tagged service account ID to add.

  • workspace_role: BetaNoBillingWorkspaceRole

Role to assign to the service account in this workspace.

  • "workspace_admin"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"

Returns

  • BetaServiceAccountWorkspaceMember object
  • type: "service_account_workspace_member"

default: service_account_workspace_member

  • created_by_actor_id: string or null

Tagged ID (user_.../svac_...) of the actor who created this membership.

  • implicit: boolean or null

True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed.

  • service_account_id: string

Tagged service account ID (svac_...).

  • workspace_id: string

Tagged workspace ID (wrkspc_...).

  • workspace_role: BetaWorkspaceRole

Role of the service account in this workspace. Service accounts cannot hold the workspace_billing role.

  • "workspace_admin"
  • "workspace_billing"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{
          "service_account_id": "service_account_id",
          "workspace_role": "workspace_admin"
        }'
Response (200)
json
{
  "created_by_actor_id": "created_by_actor_id",
  "implicit": true,
  "service_account_id": "service_account_id",
  "type": "service_account_workspace_member",
  "workspace_id": "workspace_id",
  "workspace_role": "workspace_admin"
}

Get Service Account Workspace Member

GET /v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Retrieve a service account's membership in a workspace.

Returns the membership record, including the service account's workspace_role in this workspace. Archived workspaces return 400. For the default workspace, returns the implicit (implicit: true) membership when no explicit membership exists; an explicitly added membership is returned with its assigned role. An archived service account returns 404.

Path parameters

  • workspace_id: string

ID of the workspace.

  • service_account_id: string

ID of the service account.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"

Returns

  • BetaServiceAccountWorkspaceMember object
  • type: "service_account_workspace_member"

default: service_account_workspace_member

  • created_by_actor_id: string or null

Tagged ID (user_.../svac_...) of the actor who created this membership.

  • implicit: boolean or null

True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed.

  • service_account_id: string

Tagged service account ID (svac_...).

  • workspace_id: string

Tagged workspace ID (wrkspc_...).

  • workspace_role: BetaWorkspaceRole

Role of the service account in this workspace. Service accounts cannot hold the workspace_billing role.

  • "workspace_admin"
  • "workspace_billing"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"
Response (200)
json
{
  "created_by_actor_id": "created_by_actor_id",
  "implicit": true,
  "service_account_id": "service_account_id",
  "type": "service_account_workspace_member",
  "workspace_id": "workspace_id",
  "workspace_role": "workspace_admin"
}

Update Service Account Workspace Member

POST /v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Change a service account's role in a workspace.

The new workspace_role replaces the current one. Only explicit memberships can be updated; to set a role on the implicit default-workspace membership, add the service account explicitly with POST /workspaces/{workspace_id}/service_accounts. Archived workspaces return 400. Archived service accounts cannot be updated and are rejected.

Path parameters

  • workspace_id: string

ID of the workspace.

  • service_account_id: string

ID of the service account.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"

Body parameters

  • workspace_role: BetaNoBillingWorkspaceRole

New role for the service account in this workspace.

  • "workspace_admin"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"

Returns

  • BetaServiceAccountWorkspaceMember object
  • type: "service_account_workspace_member"

default: service_account_workspace_member

  • created_by_actor_id: string or null

Tagged ID (user_.../svac_...) of the actor who created this membership.

  • implicit: boolean or null

True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed.

  • service_account_id: string

Tagged service account ID (svac_...).

  • workspace_id: string

Tagged workspace ID (wrkspc_...).

  • workspace_role: BetaWorkspaceRole

Role of the service account in this workspace. Service accounts cannot hold the workspace_billing role.

  • "workspace_admin"
  • "workspace_billing"
  • "workspace_developer"
  • "workspace_restricted_developer"
  • "workspace_user"

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{
          "workspace_role": "workspace_admin"
        }'
Response (200)
json
{
  "created_by_actor_id": "created_by_actor_id",
  "implicit": true,
  "service_account_id": "service_account_id",
  "type": "service_account_workspace_member",
  "workspace_id": "workspace_id",
  "workspace_role": "workspace_admin"
}

Delete Service Account Workspace Member

DELETE /v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Remove a service account from a workspace.

Removal is idempotent (returns 200 even if the membership was already removed). A DELETE against the implicit default-workspace membership returns 200 but is a no-op and the membership persists; deleting an explicit default-workspace row reverts to the implicit workspace_user membership. Archived workspaces return 400.

Path parameters

  • workspace_id: string

ID of the workspace.

  • service_account_id: string

ID of the service account.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"

Returns

  • type: "service_account_workspace_member_deleted"

default: service_account_workspace_member_deleted

  • service_account_id: string

Tagged service account ID (svac_...) named in the delete request. Removal is idempotent; see the endpoint description for the implicit-membership no-op.

  • workspace_id: string

Tagged workspace ID (wrkspc_...) named in the delete request.

Example

bash
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
    -X DELETE \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"
Response (200)
json
{
  "service_account_id": "service_account_id",
  "type": "service_account_workspace_member_deleted",
  "workspace_id": "workspace_id"
}
On this page
List WorkspacesQuery parametersReturnsExampleResponse (200)Create WorkspaceHeadersBody parametersReturnsExampleResponse (200)Get WorkspacePath parametersReturnsExampleResponse (200)Update WorkspacePath parametersBody parametersReturnsExampleResponse (200)Archive WorkspacePath parametersReturnsExampleResponse (200)Domain typesBeta Allowed Inference GeoBeta Data ResidencyBeta Data Residency Create ConfigBeta Data Residency Update ConfigBeta No Billing Workspace RoleBeta WorkspaceBeta Workspace MemberBeta Workspace RoleWorkspaces › Rate LimitsList Workspace Rate LimitsPath parametersQuery parametersReturnsExampleWorkspaces › MembersList Workspace MembersPath parametersQuery parametersReturnsExampleCreate Workspace MemberPath parametersBody parametersReturnsExampleGet Workspace MemberPath parametersReturnsExampleUpdate Workspace MemberPath parametersBody parametersReturnsExampleDelete Workspace MemberPath parametersReturnsExampleWorkspaces › Service AccountsList Service Account Workspace MembersPath parametersQuery parametersHeadersReturnsExampleCreate Service Account Workspace MemberPath parametersHeadersBody parametersReturnsExampleGet Service Account Workspace MemberPath parametersHeadersReturnsExampleUpdate Service Account Workspace MemberPath parametersHeadersBody parametersReturnsExampleDelete Service Account Workspace MemberPath parametersHeadersReturnsExample