Dedicated service accounts for API automation
What would you like to change?
I would like to create an identity for a bot or integration without creating a personal account or using a team member's API key. An administrator could create a "CI bot" for a workspace or team, grant the permissions it needs, and issue an API key under that identity.
Comments, activity history, and other actions should clearly identify the account as a bot. Authorised administrators should be able to manage and revoke its keys without access to a person's account. The integration should keep working if its owner leaves the workspace, until an administrator disables it.
Additional context
Kaneo already supports API keys, but each key belongs to a user account. Automations therefore depend on a person's identity, and their actions are harder to identify in the audit trail. Service accounts could use the existing workspace and team permissions and API key limits while recording the actor as a bot. Instance administrators could manage them centrally, while workspace or team administrators would only manage bots in their own scope. These identities should not support interactive login, and their keys should be easy to rotate or revoke.
Originally requested by @thriz0 on 2026-09-28. Original GitHub request #1844.