List Workspaces
GET /v1/organizations/workspaces
List Workspaces
Query parameters
after_id: optional string
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.
before_id: optional string
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.
include_archived: optional boolean
Whether to include Workspaces that have been archived in the response
default: false
limit: optional number
Number of items to return per page.
Defaults to 20. Ranges from 1 to 1000.
default: 20, minimum: 1, maximum: 1000
Returns
data: array of BetaWorkspace
type: "workspace"
Object type.
For Workspaces, this is always "workspace".
default: workspace
id: string
ID of the Workspace.
archived_at: string or null
RFC 3339 datetime string indicating when the Workspace was archived, or null if the Workspace is not archived.
format: date-time
compartment_id: string
Identifier for this Workspace's encryption compartment. When you configure a customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Juglow enforces the compartment binding automatically; you do not need to reference this value in your key configuration. See the CMEK integration guide for the required key configuration; unless your organization is on Haijun Platform on AWS, it includes a separate value used during key validation. On Haijun Platform on AWS there is no separate validation value: the key is validated against this Workspace's own value when it is attached, so if your key policy uses the compartment condition, add this value to it before attaching the key.
created_at: string
RFC 3339 datetime string indicating when the Workspace was created.
format: date-time
data_residency: BetaDataResidency
Data residency configuration.
allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"
Permitted inference geo values. 'unrestricted' means all geos are allowed.
Geos = array of BetaAllowedInferenceGeo
"global"
"us"
Unrestricted = "unrestricted"
default_inference_geo: "global" or "us"
Default inference geo applied when requests omit the parameter.
"global"
"us"
workspace_geo: "us"
Geographic region for workspace data storage. Immutable after creation.
display_color: string
Hex color code representing the Workspace in the Juglow Console.
external_key_id: string or null
ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.
name: string
Name of the Workspace.
tags: map[string]
User-defined tags as string key-value pairs. Keys may not begin with juglow.
first_id: string or null
First ID in the data list. Can be used as the before_id for the previous page.
has_more: boolean
Indicates if there are more results in the requested page direction.
last_id: string or null
Last ID in the data list. Can be used as the after_id for the next page.
Example
curl https://haijun.my.id/v1/organizations/workspaces \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"data": [
{
"id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"archived_at": "2024-11-01T23:59:27.427722Z",
"compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
"created_at": "2024-10-30T23:58:27.427722Z",
"data_residency": {
"allowed_inference_geos": "unrestricted",
"default_inference_geo": "global",
"workspace_geo": "us"
},
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"name": "Workspace Name",
"tags": {
"env": "prod",
"team": "platform"
},
"type": "workspace"
}
],
"first_id": "first_id",
"has_more": true,
"last_id": "last_id"
}Create Workspace
POST /v1/organizations/workspaces
Create Workspace
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
Body parameters
name: string
Name of the Workspace.
minLength: 1, maxLength: 40
data_residency: optional BetaDataResidencyCreateConfig or null
Data residency configuration for the workspace. If omitted, defaults to workspace_geo: "us", allowed_inference_geos: "unrestricted", and default_inference_geo: "global".
allowed_inference_geos: optional array of BetaAllowedInferenceGeo or "unrestricted" or null
Permitted inference geo values. Defaults to 'unrestricted' if omitted, which allows all geos. Use the string 'unrestricted' to allow all geos, or a list of specific geos.
Geos = array of BetaAllowedInferenceGeo
"global"
"us"
Unrestricted = "unrestricted"
default_inference_geo: optional "global" or "us" or null
Default inference geo applied when requests omit the parameter. Defaults to 'global' if omitted. Must be a member of allowed_inference_geos unless allowed_inference_geos is "unrestricted".
"global"
"us"
workspace_geo: optional "us" or null
Geographic region for workspace data storage. Immutable after creation. Defaults to 'us' if omitted.
display_color: optional string or null
Hex color code representing the Workspace in the Juglow Console.
maxLength: 7, pattern: ^#[0-9A-Fa-f]{6}$
external_key_id: optional string or null
ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.
tags: optional map[string] or null
User-defined tags as string key-value pairs. Keys may not begin with juglow.
Returns
BetaWorkspace object
type: "workspace"
Object type.
For Workspaces, this is always "workspace".
default: workspace
id: string
ID of the Workspace.
archived_at: string or null
RFC 3339 datetime string indicating when the Workspace was archived, or null if the Workspace is not archived.
format: date-time
compartment_id: string
Identifier for this Workspace's encryption compartment. When you configure a customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Juglow enforces the compartment binding automatically; you do not need to reference this value in your key configuration. See the CMEK integration guide for the required key configuration; unless your organization is on Haijun Platform on AWS, it includes a separate value used during key validation. On Haijun Platform on AWS there is no separate validation value: the key is validated against this Workspace's own value when it is attached, so if your key policy uses the compartment condition, add this value to it before attaching the key.
created_at: string
RFC 3339 datetime string indicating when the Workspace was created.
format: date-time
data_residency: BetaDataResidency
Data residency configuration.
allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"
Permitted inference geo values. 'unrestricted' means all geos are allowed.
Geos = array of BetaAllowedInferenceGeo
"global"
"us"
Unrestricted = "unrestricted"
default_inference_geo: "global" or "us"
Default inference geo applied when requests omit the parameter.
"global"
"us"
workspace_geo: "us"
Geographic region for workspace data storage. Immutable after creation.
display_color: string
Hex color code representing the Workspace in the Juglow Console.
external_key_id: string or null
ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.
name: string
Name of the Workspace.
tags: map[string]
User-defined tags as string key-value pairs. Keys may not begin with juglow.
Example
curl https://haijun.my.id/v1/organizations/workspaces \
-H 'Content-Type: application/json' \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY" \
-d '{
"name": "x",
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"tags": {
"env": "prod",
"team": "platform"
}
}'Response (200)
{
"id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"archived_at": "2024-11-01T23:59:27.427722Z",
"compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
"created_at": "2024-10-30T23:58:27.427722Z",
"data_residency": {
"allowed_inference_geos": "unrestricted",
"default_inference_geo": "global",
"workspace_geo": "us"
},
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"name": "Workspace Name",
"tags": {
"env": "prod",
"team": "platform"
},
"type": "workspace"
}Get Workspace
GET /v1/organizations/workspaces/{workspace_id}
Get Workspace
Path parameters
workspace_id: string
ID of the Workspace.
Returns
BetaWorkspace object
type: "workspace"
Object type.
For Workspaces, this is always "workspace".
default: workspace
id: string
ID of the Workspace.
archived_at: string or null
RFC 3339 datetime string indicating when the Workspace was archived, or null if the Workspace is not archived.
format: date-time
compartment_id: string
Identifier for this Workspace's encryption compartment. When you configure a customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Juglow enforces the compartment binding automatically; you do not need to reference this value in your key configuration. See the CMEK integration guide for the required key configuration; unless your organization is on Haijun Platform on AWS, it includes a separate value used during key validation. On Haijun Platform on AWS there is no separate validation value: the key is validated against this Workspace's own value when it is attached, so if your key policy uses the compartment condition, add this value to it before attaching the key.
created_at: string
RFC 3339 datetime string indicating when the Workspace was created.
format: date-time
data_residency: BetaDataResidency
Data residency configuration.
allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"
Permitted inference geo values. 'unrestricted' means all geos are allowed.
Geos = array of BetaAllowedInferenceGeo
"global"
"us"
Unrestricted = "unrestricted"
default_inference_geo: "global" or "us"
Default inference geo applied when requests omit the parameter.
"global"
"us"
workspace_geo: "us"
Geographic region for workspace data storage. Immutable after creation.
display_color: string
Hex color code representing the Workspace in the Juglow Console.
external_key_id: string or null
ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.
name: string
Name of the Workspace.
tags: map[string]
User-defined tags as string key-value pairs. Keys may not begin with juglow.
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"archived_at": "2024-11-01T23:59:27.427722Z",
"compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
"created_at": "2024-10-30T23:58:27.427722Z",
"data_residency": {
"allowed_inference_geos": "unrestricted",
"default_inference_geo": "global",
"workspace_geo": "us"
},
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"name": "Workspace Name",
"tags": {
"env": "prod",
"team": "platform"
},
"type": "workspace"
}Update Workspace
POST /v1/organizations/workspaces/{workspace_id}
Update Workspace
Path parameters
workspace_id: string
Body parameters
data_residency: optional BetaDataResidencyUpdateConfig or null
Data residency configuration for the workspace.
allowed_inference_geos: optional array of BetaAllowedInferenceGeo or "unrestricted" or null
Permitted inference geo values. Use 'unrestricted' to allow all geos, or a list of specific geos.
Geos = array of BetaAllowedInferenceGeo
"global"
"us"
Unrestricted = "unrestricted"
default_inference_geo: optional "global" or "us" or null
Default inference geo applied when requests omit the parameter. Must be a member of allowed_inference_geos unless allowed_inference_geos is "unrestricted".
"global"
"us"
display_color: optional string
Hex color code representing the Workspace in the Juglow Console.
maxLength: 7, pattern: ^#[0-9A-Fa-f]{6}$
external_key_id: optional string
ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.
name: optional string
Name of the Workspace.
minLength: 1, maxLength: 40
tags: optional map[string] or null
User-defined tags as string key-value pairs. Keys may not begin with juglow.
Returns
BetaWorkspace object
type: "workspace"
Object type.
For Workspaces, this is always "workspace".
default: workspace
id: string
ID of the Workspace.
archived_at: string or null
RFC 3339 datetime string indicating when the Workspace was archived, or null if the Workspace is not archived.
format: date-time
compartment_id: string
Identifier for this Workspace's encryption compartment. When you configure a customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Juglow enforces the compartment binding automatically; you do not need to reference this value in your key configuration. See the CMEK integration guide for the required key configuration; unless your organization is on Haijun Platform on AWS, it includes a separate value used during key validation. On Haijun Platform on AWS there is no separate validation value: the key is validated against this Workspace's own value when it is attached, so if your key policy uses the compartment condition, add this value to it before attaching the key.
created_at: string
RFC 3339 datetime string indicating when the Workspace was created.
format: date-time
data_residency: BetaDataResidency
Data residency configuration.
allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"
Permitted inference geo values. 'unrestricted' means all geos are allowed.
Geos = array of BetaAllowedInferenceGeo
"global"
"us"
Unrestricted = "unrestricted"
default_inference_geo: "global" or "us"
Default inference geo applied when requests omit the parameter.
"global"
"us"
workspace_geo: "us"
Geographic region for workspace data storage. Immutable after creation.
display_color: string
Hex color code representing the Workspace in the Juglow Console.
external_key_id: string or null
ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.
name: string
Name of the Workspace.
tags: map[string]
User-defined tags as string key-value pairs. Keys may not begin with juglow.
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID \
-H 'Content-Type: application/json' \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY" \
-d '{
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"tags": {
"env": "prod",
"team": "platform"
}
}'Response (200)
{
"id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"archived_at": "2024-11-01T23:59:27.427722Z",
"compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
"created_at": "2024-10-30T23:58:27.427722Z",
"data_residency": {
"allowed_inference_geos": "unrestricted",
"default_inference_geo": "global",
"workspace_geo": "us"
},
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"name": "Workspace Name",
"tags": {
"env": "prod",
"team": "platform"
},
"type": "workspace"
}Archive Workspace
POST /v1/organizations/workspaces/{workspace_id}/archive
Archive Workspace
Path parameters
workspace_id: string
Returns
BetaWorkspace object
type: "workspace"
Object type.
For Workspaces, this is always "workspace".
default: workspace
id: string
ID of the Workspace.
archived_at: string or null
RFC 3339 datetime string indicating when the Workspace was archived, or null if the Workspace is not archived.
format: date-time
compartment_id: string
Identifier for this Workspace's encryption compartment. When you configure a customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Juglow enforces the compartment binding automatically; you do not need to reference this value in your key configuration. See the CMEK integration guide for the required key configuration; unless your organization is on Haijun Platform on AWS, it includes a separate value used during key validation. On Haijun Platform on AWS there is no separate validation value: the key is validated against this Workspace's own value when it is attached, so if your key policy uses the compartment condition, add this value to it before attaching the key.
created_at: string
RFC 3339 datetime string indicating when the Workspace was created.
format: date-time
data_residency: BetaDataResidency
Data residency configuration.
allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"
Permitted inference geo values. 'unrestricted' means all geos are allowed.
Geos = array of BetaAllowedInferenceGeo
"global"
"us"
Unrestricted = "unrestricted"
default_inference_geo: "global" or "us"
Default inference geo applied when requests omit the parameter.
"global"
"us"
workspace_geo: "us"
Geographic region for workspace data storage. Immutable after creation.
display_color: string
Hex color code representing the Workspace in the Juglow Console.
external_key_id: string or null
ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.
name: string
Name of the Workspace.
tags: map[string]
User-defined tags as string key-value pairs. Keys may not begin with juglow.
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/archive \
-X POST \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"archived_at": "2024-11-01T23:59:27.427722Z",
"compartment_id": "f8a7b6c5-4d3e-4f1a-8b9c-0d1e2f3a4b5c",
"created_at": "2024-10-30T23:58:27.427722Z",
"data_residency": {
"allowed_inference_geos": "unrestricted",
"default_inference_geo": "global",
"workspace_geo": "us"
},
"display_color": "#6C5BB9",
"external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
"name": "Workspace Name",
"tags": {
"env": "prod",
"team": "platform"
},
"type": "workspace"
}Domain types
Beta Allowed Inference Geo
BetaAllowedInferenceGeo = "global" or "us"
"global"
"us"
Beta Data Residency
BetaDataResidency object
allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"
Permitted inference geo values. 'unrestricted' means all geos are allowed.
Geos = array of BetaAllowedInferenceGeo
"global"
"us"
Unrestricted = "unrestricted"
default_inference_geo: "global" or "us"
Default inference geo applied when requests omit the parameter.
"global"
"us"
workspace_geo: "us"
Geographic region for workspace data storage. Immutable after creation.
Beta Data Residency Create Config
BetaDataResidencyCreateConfig object
allowed_inference_geos: optional array of BetaAllowedInferenceGeo or "unrestricted" or null
Permitted inference geo values. Defaults to 'unrestricted' if omitted, which allows all geos. Use the string 'unrestricted' to allow all geos, or a list of specific geos.
Geos = array of BetaAllowedInferenceGeo
"global"
"us"
Unrestricted = "unrestricted"
default_inference_geo: optional "global" or "us" or null
Default inference geo applied when requests omit the parameter. Defaults to 'global' if omitted. Must be a member of allowed_inference_geos unless allowed_inference_geos is "unrestricted".
"global"
"us"
workspace_geo: optional "us" or null
Geographic region for workspace data storage. Immutable after creation. Defaults to 'us' if omitted.
Beta Data Residency Update Config
BetaDataResidencyUpdateConfig object
allowed_inference_geos: optional array of BetaAllowedInferenceGeo or "unrestricted" or null
Permitted inference geo values. Use 'unrestricted' to allow all geos, or a list of specific geos.
Geos = array of BetaAllowedInferenceGeo
"global"
"us"
Unrestricted = "unrestricted"
default_inference_geo: optional "global" or "us" or null
Default inference geo applied when requests omit the parameter. Must be a member of allowed_inference_geos unless allowed_inference_geos is "unrestricted".
"global"
"us"
Beta No Billing Workspace Role
BetaNoBillingWorkspaceRole = "workspace_admin" or "workspace_developer" or "workspace_restricted_developer" or "workspace_user"
"workspace_admin"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
Beta Workspace
BetaWorkspace object
type: "workspace"
Object type.
For Workspaces, this is always "workspace".
default: workspace
id: string
ID of the Workspace.
archived_at: string or null
RFC 3339 datetime string indicating when the Workspace was archived, or null if the Workspace is not archived.
format: date-time
compartment_id: string
Identifier for this Workspace's encryption compartment. When you configure a customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Juglow enforces the compartment binding automatically; you do not need to reference this value in your key configuration. See the CMEK integration guide for the required key configuration; unless your organization is on Haijun Platform on AWS, it includes a separate value used during key validation. On Haijun Platform on AWS there is no separate validation value: the key is validated against this Workspace's own value when it is attached, so if your key policy uses the compartment condition, add this value to it before attaching the key.
created_at: string
RFC 3339 datetime string indicating when the Workspace was created.
format: date-time
data_residency: BetaDataResidency
Data residency configuration.
allowed_inference_geos: array of BetaAllowedInferenceGeo or "unrestricted"
Permitted inference geo values. 'unrestricted' means all geos are allowed.
Geos = array of BetaAllowedInferenceGeo
"global"
"us"
Unrestricted = "unrestricted"
default_inference_geo: "global" or "us"
Default inference geo applied when requests omit the parameter.
"global"
"us"
workspace_geo: "us"
Geographic region for workspace data storage. Immutable after creation.
display_color: string
Hex color code representing the Workspace in the Juglow Console.
external_key_id: string or null
ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the referenced key. Create key configurations with the External Keys API. On Haijun Platform on AWS the value is the AWS KMS key ARN, and the key must be a single-Region key in the same AWS account and Region as the Workspace. On that platform the key is validated against this Workspace when it is attached, so a key-policy problem is reported as an error on this request. This field is write-once: once a key is attached to a Workspace it cannot be detached or replaced. To rotate key material, rotate the underlying key on your cloud KMS; the external_key_id stays the same.
name: string
Name of the Workspace.
tags: map[string]
User-defined tags as string key-value pairs. Keys may not begin with juglow.
Beta Workspace Member
BetaWorkspaceMember object
type: "workspace_member"
Object type.
For Workspace Members, this is always "workspace_member".
default: workspace_member
user_id: string
ID of the User.
workspace_id: string
ID of the Workspace.
workspace_role: BetaWorkspaceRole
Role of the Workspace Member.
"workspace_admin"
"workspace_billing"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
Beta Workspace Role
BetaWorkspaceRole = "workspace_admin" or "workspace_billing" or "workspace_developer" or 2 more
"workspace_admin"
"workspace_billing"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
Workspaces › Rate Limits
List Workspace Rate Limits
GET /v1/organizations/workspaces/{workspace_id}/rate_limits
List a workspace's rate limits.
By default, returns only the groups and limiter types that have a workspace-level override. With include_inherited=true, returns every group with organization-level limits the workspace can see, listing for each the values it inherits from the organization as well as its own overrides. Each value's source says which it is.
When limit is omitted, every matching entry is returned in a single page; when limit truncates the result, follow next_page to fetch the remaining entries.
Path parameters
workspace_id: string
The ID of the workspace.
Query parameters
group_type: optional "batch" or "files" or "model_group" or 3 more
Filter by group type.
"batch"
"files"
"model_group"
"tracks"
"token_count"
"web_search"
include_inherited: optional boolean
Also list the limiter values the workspace inherits from the organization, including groups with no workspace-level override.
default: false
limit: optional number
Maximum number of items to return per page. Ranges from 1 to 1000.
When omitted, every remaining entry is returned in a single page and next_page is null.
minimum: 1, maximum: 1000
page: optional string
Opaque cursor from a previous response's next_page.
Returns
data: array of BetaWorkspaceRateLimit
Rate-limit entries for the workspace: one per group with at least one override, or, with include_inherited set to true, one per group the workspace can see that has organization-level limits.
type: "workspace_rate_limit"
Object type. Always workspace_rate_limit for workspace rate-limit entries.
default: workspace_rate_limit
group: BetaOrganizationRateLimitModelGroup or BetaOrganizationRateLimitBatchGroup or BetaOrganizationRateLimitTokenCountGroup or 3 more
The rate-limit group this entry's limits apply to. Its type equals group_type.
BetaOrganizationRateLimitModelGroup object
type: "model_group"
Always model_group: a family of models.
default: model_group
id: string
Opaque identifier of the rate-limit group (for example, rlg_01VPTCmyiu5ZLsWkcxYG2pY8). It is the same in every organization and never changes, unlike the entry's own identifier, which differs per organization.
display_name: string
Human-readable name of the model group (for example, Haijun Sonnet 4.x). For display only; it may change.
BetaOrganizationRateLimitBatchGroup object
type: "batch"
Always batch: the Message Batches API.
default: batch
id: string
Opaque identifier of the rate-limit group (for example, rlg_01VPTCmyiu5ZLsWkcxYG2pY8). It is the same in every organization and never changes, unlike the entry's own identifier, which differs per organization.
BetaOrganizationRateLimitTokenCountGroup object
type: "token_count"
Always token_count: the Token Count API.
default: token_count
id: string
Opaque identifier of the rate-limit group (for example, rlg_01VPTCmyiu5ZLsWkcxYG2pY8). It is the same in every organization and never changes, unlike the entry's own identifier, which differs per organization.
BetaOrganizationRateLimitFilesGroup object
type: "files"
Always files: the Files API.
default: files
id: string
Opaque identifier of the rate-limit group (for example, rlg_01VPTCmyiu5ZLsWkcxYG2pY8). It is the same in every organization and never changes, unlike the entry's own identifier, which differs per organization.
BetaOrganizationRateLimitSkillsGroup object
type: "tracks"
Always tracks: the Tracks API.
default: tracks
id: string
Opaque identifier of the rate-limit group (for example, rlg_01VPTCmyiu5ZLsWkcxYG2pY8). It is the same in every organization and never changes, unlike the entry's own identifier, which differs per organization.
BetaOrganizationRateLimitWebSearchGroup object
type: "web_search"
Always web_search: the Messages API web search tool.
default: web_search
id: string
Opaque identifier of the rate-limit group (for example, rlg_01VPTCmyiu5ZLsWkcxYG2pY8). It is the same in every organization and never changes, unlike the entry's own identifier, which differs per organization.
limits: array of BetaWorkspaceRateLimitValue
The workspace's limiter values for this group. By default only the limiter types with a workspace-level override are listed. With include_inherited set to true, the limiter types the workspace inherits from the organization are listed too, each marked by source.
type: string
The limiter type (for example, requests_per_minute or input_tokens_per_minute).
org_limit: number or null
The organization-level value for the same limiter type, for reference. null when the organization has no limit configured for this limiter type.
source: BetaWorkspaceRateLimitWorkspaceSource or BetaWorkspaceRateLimitOrganizationSource
Where value comes from. organization values are listed only when include_inherited is true, and then value equals org_limit.
BetaWorkspaceRateLimitWorkspaceSource object
type: "workspace"
Always workspace: a workspace-level override is stored.
default: workspace
BetaWorkspaceRateLimitOrganizationSource object
type: "organization"
Always organization: no workspace-level override is stored, so the organization's value applies.
default: organization
value: number
The workspace's value for this limiter type: the workspace-level override when source.type is workspace, otherwise the organization's value.
models: array of string or null
Model names this entry's limits apply to, including aliases. null when group_type is not "model_group".
rate_limit_id: string
The id of the organization's RateLimit entry this entry applies to.
workspace_id: string
ID of the Workspace this entry applies to.
group_type: "batch" or "files" or "model_group" or 3 more
Deprecated: Use group.type instead. group_type is still returned and always equals group.type.
Deprecated: use group.type instead. The kind of rate-limit group this entry represents. model_group entries apply to a family of models (listed in models); other values apply to an API-surface category and have models set to null. Always equal to group.type.
"batch"
"files"
"model_group"
"tracks"
"token_count"
"web_search"
next_page: string or null
Opaque cursor for the next page of results, or null when no entries remain beyond this response.
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/rate_limits \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"data": [
{
"group": {
"id": "id",
"display_name": "display_name",
"type": "model_group"
},
"group_type": "batch",
"limits": [
{
"org_limit": 0,
"source": {
"type": "workspace"
},
"type": "type",
"value": 0
}
],
"models": [
"string"
],
"rate_limit_id": "rate_limit_id",
"type": "workspace_rate_limit",
"workspace_id": "workspace_id"
}
],
"next_page": "next_page"
}Workspaces › Members
List Workspace Members
GET /v1/organizations/workspaces/{workspace_id}/members
List Workspace Members
Path parameters
workspace_id: string
ID of the Workspace.
Query parameters
after_id: optional string
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately after this object.
before_id: optional string
ID of the object to use as a cursor for pagination. When provided, returns the page of results immediately before this object.
limit: optional number
Number of items to return per page.
Defaults to 20. Ranges from 1 to 1000.
default: 20, minimum: 1, maximum: 1000
Returns
data: array of BetaWorkspaceMember
type: "workspace_member"
Object type.
For Workspace Members, this is always "workspace_member".
default: workspace_member
user_id: string
ID of the User.
workspace_id: string
ID of the Workspace.
workspace_role: BetaWorkspaceRole
Role of the Workspace Member.
"workspace_admin"
"workspace_billing"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
first_id: string or null
First ID in the data list. Can be used as the before_id for the previous page.
has_more: boolean
Indicates if there are more results in the requested page direction.
last_id: string or null
Last ID in the data list. Can be used as the after_id for the next page.
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/members \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"data": [
{
"type": "workspace_member",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"workspace_role": "workspace_admin"
}
],
"first_id": "first_id",
"has_more": true,
"last_id": "last_id"
}Create Workspace Member
POST /v1/organizations/workspaces/{workspace_id}/members
Create Workspace Member
Path parameters
workspace_id: string
ID of the Workspace.
Body parameters
user_id: string
ID of the User.
workspace_role: BetaNoBillingWorkspaceRole
Role of the new Workspace Member. Cannot be workspace_billing.
"workspace_admin"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
Returns
BetaWorkspaceMember object
type: "workspace_member"
Object type.
For Workspace Members, this is always "workspace_member".
default: workspace_member
user_id: string
ID of the User.
workspace_id: string
ID of the Workspace.
workspace_role: BetaWorkspaceRole
Role of the Workspace Member.
"workspace_admin"
"workspace_billing"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/members \
-H 'Content-Type: application/json' \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY" \
-d '{
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_role": "workspace_admin"
}'Response (200)
{
"type": "workspace_member",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"workspace_role": "workspace_admin"
}Get Workspace Member
GET /v1/organizations/workspaces/{workspace_id}/members/{user_id}
Get Workspace Member
Path parameters
workspace_id: string
ID of the Workspace.
user_id: string
ID of the User.
Returns
BetaWorkspaceMember object
type: "workspace_member"
Object type.
For Workspace Members, this is always "workspace_member".
default: workspace_member
user_id: string
ID of the User.
workspace_id: string
ID of the Workspace.
workspace_role: BetaWorkspaceRole
Role of the Workspace Member.
"workspace_admin"
"workspace_billing"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"type": "workspace_member",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"workspace_role": "workspace_admin"
}Update Workspace Member
POST /v1/organizations/workspaces/{workspace_id}/members/{user_id}
Update Workspace Member
Path parameters
workspace_id: string
ID of the Workspace.
user_id: string
ID of the User.
Body parameters
workspace_role: BetaWorkspaceRole
New workspace role for the User.
"workspace_admin"
"workspace_billing"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
Returns
BetaWorkspaceMember object
type: "workspace_member"
Object type.
For Workspace Members, this is always "workspace_member".
default: workspace_member
user_id: string
ID of the User.
workspace_id: string
ID of the Workspace.
workspace_role: BetaWorkspaceRole
Role of the Workspace Member.
"workspace_admin"
"workspace_billing"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \
-H 'Content-Type: application/json' \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY" \
-d '{
"workspace_role": "workspace_admin"
}'Response (200)
{
"type": "workspace_member",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ",
"workspace_role": "workspace_admin"
}Delete Workspace Member
DELETE /v1/organizations/workspaces/{workspace_id}/members/{user_id}
Delete Workspace Member
Path parameters
workspace_id: string
ID of the Workspace.
user_id: string
ID of the User.
Returns
type: "workspace_member_deleted"
Deleted object type.
For Workspace Members, this is always "workspace_member_deleted".
default: workspace_member_deleted
user_id: string
ID of the User.
workspace_id: string
ID of the Workspace.
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \
-X DELETE \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"type": "workspace_member_deleted",
"user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q",
"workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"
}Workspaces › Service Accounts
List Service Account Workspace Members
GET /v1/organizations/workspaces/{workspace_id}/service_accounts
Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.
List the service accounts that are members of a workspace.
Each entry includes the service account's workspace_role. Use limit and the next_page cursor to paginate. Archived workspaces return 400; use GET /service_accounts/{id}/workspaces to audit memberships of an archived workspace. The implicit default-workspace membership is not included in this list. Memberships of archived service accounts are omitted from the results.
Path parameters
workspace_id: string
ID of the workspace.
Query parameters
limit: optional number
Number of results per page.
default: 20, minimum: 1, maximum: 100
page: optional string
Opaque cursor from a previous response's next_page.
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
Returns
data: array of BetaServiceAccountWorkspaceMember
type: "service_account_workspace_member"
default: service_account_workspace_member
created_by_actor_id: string or null
Tagged ID (user_.../svac_...) of the actor who created this membership.
implicit: boolean or null
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed.
service_account_id: string
Tagged service account ID (svac_...).
workspace_id: string
Tagged workspace ID (wrkspc_...).
workspace_role: BetaWorkspaceRole
Role of the service account in this workspace. Service accounts cannot hold the workspace_billing role.
"workspace_admin"
"workspace_billing"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
next_page: string or null
Opaque cursor for the next page, or null if no more results.
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"data": [
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}
],
"next_page": "next_page"
}Create Service Account Workspace Member
POST /v1/organizations/workspaces/{workspace_id}/service_accounts
Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.
Add a service account to a workspace with the given workspace_role.
The role determines what the service account can do in the workspace and which workspace-scoped permissions it can be granted when authenticating through federation. Every service account is already an implicit workspace_user member of the default workspace; adding it explicitly assigns a chosen role. If the service account is already an explicit member of the workspace, its workspace_role is replaced with the value supplied here. Archived workspaces return 400. Archived service accounts cannot be added and are rejected.
Path parameters
workspace_id: string
ID of the workspace.
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
Body parameters
service_account_id: string
Tagged service account ID to add.
workspace_role: BetaNoBillingWorkspaceRole
Role to assign to the service account in this workspace.
"workspace_admin"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
Returns
BetaServiceAccountWorkspaceMember object
type: "service_account_workspace_member"
default: service_account_workspace_member
created_by_actor_id: string or null
Tagged ID (user_.../svac_...) of the actor who created this membership.
implicit: boolean or null
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed.
service_account_id: string
Tagged service account ID (svac_...).
workspace_id: string
Tagged workspace ID (wrkspc_...).
workspace_role: BetaWorkspaceRole
Role of the service account in this workspace. Service accounts cannot hold the workspace_billing role.
"workspace_admin"
"workspace_billing"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \
-H 'Content-Type: application/json' \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY" \
-d '{
"service_account_id": "service_account_id",
"workspace_role": "workspace_admin"
}'Response (200)
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}Get Service Account Workspace Member
GET /v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}
Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.
Retrieve a service account's membership in a workspace.
Returns the membership record, including the service account's workspace_role in this workspace. Archived workspaces return 400. For the default workspace, returns the implicit (implicit: true) membership when no explicit membership exists; an explicitly added membership is returned with its assigned role. An archived service account returns 404.
Path parameters
workspace_id: string
ID of the workspace.
service_account_id: string
ID of the service account.
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
Returns
BetaServiceAccountWorkspaceMember object
type: "service_account_workspace_member"
default: service_account_workspace_member
created_by_actor_id: string or null
Tagged ID (user_.../svac_...) of the actor who created this membership.
implicit: boolean or null
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed.
service_account_id: string
Tagged service account ID (svac_...).
workspace_id: string
Tagged workspace ID (wrkspc_...).
workspace_role: BetaWorkspaceRole
Role of the service account in this workspace. Service accounts cannot hold the workspace_billing role.
"workspace_admin"
"workspace_billing"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}Update Service Account Workspace Member
POST /v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}
Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.
Change a service account's role in a workspace.
The new workspace_role replaces the current one. Only explicit memberships can be updated; to set a role on the implicit default-workspace membership, add the service account explicitly with POST /workspaces/{workspace_id}/service_accounts. Archived workspaces return 400. Archived service accounts cannot be updated and are rejected.
Path parameters
workspace_id: string
ID of the workspace.
service_account_id: string
ID of the service account.
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
Body parameters
workspace_role: BetaNoBillingWorkspaceRole
New role for the service account in this workspace.
"workspace_admin"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
Returns
BetaServiceAccountWorkspaceMember object
type: "service_account_workspace_member"
default: service_account_workspace_member
created_by_actor_id: string or null
Tagged ID (user_.../svac_...) of the actor who created this membership.
implicit: boolean or null
True when this is the implicit default-workspace membership every service account has when no explicit membership exists. Implicit memberships have role workspace_user and cannot be removed.
service_account_id: string
Tagged service account ID (svac_...).
workspace_id: string
Tagged workspace ID (wrkspc_...).
workspace_role: BetaWorkspaceRole
Role of the service account in this workspace. Service accounts cannot hold the workspace_billing role.
"workspace_admin"
"workspace_billing"
"workspace_developer"
"workspace_restricted_developer"
"workspace_user"
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
-H 'Content-Type: application/json' \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY" \
-d '{
"workspace_role": "workspace_admin"
}'Response (200)
{
"created_by_actor_id": "created_by_actor_id",
"implicit": true,
"service_account_id": "service_account_id",
"type": "service_account_workspace_member",
"workspace_id": "workspace_id",
"workspace_role": "workspace_admin"
}Delete Service Account Workspace Member
DELETE /v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}
Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.
Remove a service account from a workspace.
Removal is idempotent (returns 200 even if the membership was already removed). A DELETE against the implicit default-workspace membership returns 200 but is a no-op and the membership persists; deleting an explicit default-workspace row reverts to the implicit workspace_user membership. Archived workspaces return 400.
Path parameters
workspace_id: string
ID of the workspace.
service_account_id: string
ID of the service account.
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
Returns
type: "service_account_workspace_member_deleted"
default: service_account_workspace_member_deleted
service_account_id: string
Tagged service account ID (svac_...) named in the delete request. Removal is idempotent; see the endpoint description for the implicit-membership no-op.
workspace_id: string
Tagged workspace ID (wrkspc_...) named in the delete request.
Example
curl https://haijun.my.id/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \
-X DELETE \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"service_account_id": "service_account_id",
"type": "service_account_workspace_member_deleted",
"workspace_id": "workspace_id"
}