List Service Accounts

Service account setup

Use a supported AgentOS-level database, as in the catalog server. See service account authorization for the authentication and scope configuration.

The account's sa:<name> principal identifies calls made by its token. It is distinct from created_by and the account's owner user_id. List responses contain metadata and token prefixes, not reusable plaintext credentials.

include_revoked defaults to true. Results are paginated as data and meta. Scoped visibility can include workspace-level accounts; visibility alone does not authorize revoking them.

GET/service-accounts

List service accounts. Returns metadata and display prefixes only - never hashes or plaintext.

Authorization

HTTPBearer
AuthorizationBearer <token>

In: header

Query Parameters

include_revoked?Include Revoked
Defaulttrue
limit?Limit
Range1 <= value <= 100
Default20
page?Page
Range1 <= value
Default1
sort_by?Sort By
Default"created_at"
sort_order?Sort Order
Default"desc"

Response Body

application/json

application/json

curl --request GET 'https://example.com/service-accounts'
{  "data": [    {      "id": "string",      "name": "string",      "principal": "string",      "user_id": "string",      "token_prefix": "string",      "scopes": [        {          "id": "string",          "raw": "string",          "namespace": "string",          "sub_namespace": "string",          "permission": "string",          "value": "allow"        }      ],      "created_at": 0,      "expires_at": 0,      "last_used_at": 0,      "revoked_at": 0,      "created_by": "string"    }  ],  "meta": {    "page": 0,    "limit": 20,    "total_pages": 0,    "total_count": 0,    "search_time_ms": 0  }}