Revoke Service Account

Service account setup

Use a supported AgentOS-level database, as in the catalog server. See service account authorization for the authentication and scope configuration.

The account's sa:<name> principal identifies calls made by its token. It is distinct from created_by and the account's owner user_id. List responses contain metadata and token prefixes, not reusable plaintext credentials.

An absent account returns 404; revoking an existing account again returns 204. A scoped caller cannot revoke a workspace-level account (403).

The local verification cache is evicted immediately. Other workers can retain a successful verification for the configured cache TTL, 30 seconds by default. Set service_account_cache_ttl_seconds=0 in AgentOS settings to verify against the database on every request.

DELETE/service-accounts/{service_account_id}

Revoke a service account. Idempotent.

Takes effect immediately on this worker (the local verification cache entry is evicted) and within the cache TTL on other workers.

Authorization

HTTPBearer
AuthorizationBearer <token>

In: header

Path Parameters

service_account_id*Service Account Id

Response Body

application/json

curl --request DELETE 'https://example.com/service-accounts/string'
Empty