Skip to article
NEXUSDocs
Documentation/Administration
Configuration guide

Service Accounts

Create and manage service accounts for programmatic access

Before you begin

Availability depends on your school's enabled tools, provider setup, and account permissions. These settings are managed in the web workspace. A class policy may restrict a feature described here.

A service account is a non-human user that exists only to call the Nexus API. Creating one gives you an API key, which lets you build custom applications, integrate with external systems, and automate workflows.

This page applies to Nexus v4.7 and later. For older versions, see Service Accounts before v4.7.

A service account is a distinct user in Nexus, so you can trace its activity, keep its chat sessions private, and scope resources to it.

How a Service Account Gets Its Access#

A service account has no permissions of its own. Its access is the combination of the permissions of every group you assign it, exactly like a person's access.

Groups assignedWhat the key can do
NoneChat only. It can create sessions and send messages, but it cannot search and cannot reach any admin endpoint.
BasicChat, search, projects, and its own agents.
AdminEverything, including every admin/ endpoint.
A custom groupWhatever that group grants. A group with Manage Connectors & Document Sets, for example, lets the key manage connectors.

Assigning several groups adds their permissions together.

If a key can chat but search returns nothing, check whether its service account is in a group.

For how groups and permissions fit together, see Understanding Permissions.

Who Can Manage Service Accounts#

Managing service accounts requires the Manage Service Accounts permission, which an admin grants to a group. Admins always have it.

Granting Manage Service Accounts is equivalent to granting Admin. The group selector is deliberately uncapped, so anyone who can create a service account can put it in the Admin group and then use its key.

Creating a Service Account#

In the Admin Panel, go to Service Accounts under Integrations.

Create the account#

Click New Service Account, give it a name, and select the groups it should belong to. You can change both later.

Save and copy the key#

Copy or download the key before closing the dialog. Nexus shows it only once.

Service-account availability depends on the deployed edition and its license. School membership and class checks still apply to school resources.

Managing Service Accounts#

The Service Accounts page lists each account with its name, masked key, and groups. For each account you can:

ActionWhat it does
RegenerateIssues a new key and revokes the current one.
GroupsAdds the account to groups or removes it from them, which changes what its key can do.
Edit AccountRenames the account or changes its groups.
Delete AccountRemoves the account and its key.

Regenerating or deleting a key breaks any application still using the old one.

Personal Access Tokens#

Service accounts are for applications. When you want a token that acts as a person, use a Personal Access Token instead. Any user with the Create User Access Token permission can create one from Settings > Accounts & Access.

See Overview & Auth for token scopes and usage.

NEXUS

Nexus helps students think, practice, and learn, with teachers guiding AI use.

[ Support ]

[ NARB TECHNOLOGY INC. ]

Nexus is a school AI platform by narb Technology Inc. · 16192 Coastal Hwy, Lewes, DE 19958

© 2026 narb Technology Inc.

Nexus

Nexus helps schools make room for questions, practice, and reflection — with teacher guidance in view.

[ Contact us through e-mail ]

© 2026 narb Technology Inc.

NEXUS

Nexus helps students think, practice, and learn, with teachers guiding AI use.

[ Support ]

[ NARB TECHNOLOGY INC. ]

Nexus is a school AI platform by narb Technology Inc.

© 2026 narb Technology Inc.