2 min lesson
Move one nightly SDK job off a personal key
Replace a personal SDK key with a service account key, then prove the usage event carries the service account identity.
Step 1 of 2
Two credentials appear in this test. CURSOR_API_KEY starts the SDK run as Nightly CI Agent. A Team Admin API key reads the team's usage events and cannot run the SDK. The SDK tag identifies the product path, while serviceAccountId and serviceAccountName identify the caller. Keep both secrets out of logs. Rotation passes only when the old value fails and the replacement produces another attributed event.
Learn more
Optional practice
Test yourself on Move one nightly SDK job off a personal key
QWhat proves the nightly SDK job no longer depends on a developer's key?