Service Accounts
Create non-human identities that authenticate with the Virbe API for automations, integrations, and server-to-server calls.
A Service Account is a non-human identity used by automated systems, scripts, or integrations to authenticate with the Virbe API. Instead of using a personal user's credentials for API calls, you create a dedicated Service Account with its own API key – so integrations continue working even when team members change.
When to use a Service Account
Use a Service Account for any automated or server-side process that calls the Virbe API:
- A backend service that creates or updates Knowledge Base content programmatically
- A CI/CD pipeline that imports conversation logic as part of a deployment process
- A webhook handler that posts data to Virbe on external events
- Any integration where a human user's credentials would be inappropriate or fragile
Creating a Service Account
- Go to Settings → Users & Roles → Service Accounts
- Click + Create service account
- Enter a descriptive name (e.g.
content-sync-bot,crm-integration) - Click Assign roles – the Service Account will only have the permissions of its assigned role
- Click API keys to generate API key, give it a name first
- Copy the generated API key immediately – it is only shown once
The API key is shown only at creation time. If you lose it, you must generate a new key – the old key cannot be recovered. Store it securely (e.g. in your team's secrets manager or environment variables).
Managing Service Accounts
From the Service Accounts list:
- Edit name – edit name of the Service Account
- Assign roles – assign permissions to the Service Account
- Regenerate key – issue a new API key and invalidate the old one. Use this if a key is compromised.
- Delete – permanently remove the account and invalidate its key.
API key security
- Never commit API keys to source code repositories
- Store keys in environment variables or a secrets management service
- Use the minimum permission role needed – a Service Account that only reads Knowledge Base content should not have write or publish permissions
- Rotate keys periodically, especially after team changes