Skip to lesson
Exit
Service accounts for unattended workflows1 / 2

2 min lesson

Move one nightly SDK job off a personal key

Replace a personal SDK key with a service account key, then prove the usage event carries the service account identity.

Step 1 of 2

Two credentials appear in this test. CURSOR_API_KEY starts the SDK run as Nightly CI Agent. A Team Admin API key reads the team's usage events and cannot run the SDK. The SDK tag identifies the product path, while serviceAccountId and serviceAccountName identify the caller. Keep both secrets out of logs. Rotation passes only when the old value fails and the replacement produces another attributed event.

Learn more

Optional practice

Test yourself on Move one nightly SDK job off a personal key

QWhat proves the nightly SDK job no longer depends on a developer's key?