The same identity rules apply to API, SDK, CLI and MCP. A custom role can reduce access further, but
it cannot turn a human-only operation into a Service Account operation.
Exact Service Account API operations
These are the only public API operations that accept an active Service Account credential:
In Service Account mode, MCP registers only tools supported by those 10 API operations plus three
local helpers:
airctrl_status, list_secret_types and generate_secret. The CLI rejects human-only
commands before making an API request.
Dashboard-only security and governance
These actions require deliberate human interaction in the dashboard:- Create, pause, reactivate or delete a Service Account.
- Provision, migrate, rotate, revoke or repair a Service Account credential.
- Rotate a Service Account cryptographic identity.
- Assign roles or projects to a Service Account.
- Create or revoke human Personal Access Tokens.
- Add members, manage invitations, groups and roles, or transfer account ownership.
- Manage billing, sessions, profile, preferences and recovery.