openapi: 3.2.0 info: title: APImetrics Service Accounts API description: API for the APImetrics platform termsOfService: http://apimetrics.io/tos/ contact: name: APIContext Support url: https://apicontext.io/ email: support@apicontext.com license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html version: v2026-09-02 tags: - name: Service Accounts paths: /api/3/organizations/{org_id}/service_accounts: get: tags: - Service Accounts summary: List-Service-Accounts description: List the service accounts defined on the given organization. operationId: list-service-accounts security: - OAuth2: [] - ApiKey: [] parameters: - name: org_id in: path required: true schema: type: string pattern: ^[a-z0-9]{3,400}$ title: Organization ID - name: cursor in: query required: false schema: anyOf: - type: string - type: 'null' title: Cursor - name: limit in: query required: false schema: type: integer default: 25 title: Limit responses: '200': description: Successful Response content: application/json: schema: $ref: '#/components/schemas/ServiceAccountListResponse' '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' post: tags: - Service Accounts summary: Create-Service-Account description: Create a service account. The client_secret is returned once, here only. operationId: create-service-account security: - OAuth2: [] - ApiKey: [] parameters: - name: org_id in: path required: true schema: type: string pattern: ^[a-z0-9]{3,400}$ title: Organization ID requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateServiceAccountBody' responses: '201': description: Successful Response content: application/json: schema: $ref: '#/components/schemas/ServiceAccountCreateResponse' '409': description: A service account with this name already exists. '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' /api/3/organizations/{org_id}/service_accounts/{service_account_id}: get: tags: - Service Accounts summary: Get-Service-Account description: Get a single service account. The client_secret is never returned. operationId: get-service-account security: - OAuth2: [] - ApiKey: [] parameters: - name: service_account_id in: path required: true schema: type: string pattern: ^[A-Za-z0-9_-]+$ title: Resource ID - name: org_id in: path required: true schema: type: string pattern: ^[a-z0-9]{3,400}$ title: Organization ID responses: '200': description: Successful Response content: application/json: schema: $ref: '#/components/schemas/ServiceAccountResponse' '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' delete: tags: - Service Accounts summary: Delete-Service-Account description: Delete a service account and its Auth0 client and virtual user. operationId: delete-service-account security: - OAuth2: [] - ApiKey: [] parameters: - name: service_account_id in: path required: true schema: type: string pattern: ^[A-Za-z0-9_-]+$ title: Resource ID - name: org_id in: path required: true schema: type: string pattern: ^[a-z0-9]{3,400}$ title: Organization ID responses: '204': description: Successful Response '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' /api/3/organizations/{org_id}/service_accounts/{service_account_id}/roles: put: tags: - Service Accounts summary: Update-Service-Account-Roles description: Replace the organization roles granted to a service account. operationId: update-service-account-roles security: - OAuth2: [] - ApiKey: [] parameters: - name: service_account_id in: path required: true schema: type: string pattern: ^[A-Za-z0-9_-]+$ title: Resource ID - name: org_id in: path required: true schema: type: string pattern: ^[a-z0-9]{3,400}$ title: Organization ID requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateRolesBody' responses: '200': description: Successful Response content: application/json: schema: $ref: '#/components/schemas/ServiceAccountResponse' '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' /api/3/organizations/{org_id}/service_accounts/{service_account_id}/rotate_secret: post: tags: - Service Accounts summary: Rotate-Service-Account-Secret description: Rotate the client secret. The new secret is returned once, here only. operationId: rotate-service-account-secret security: - OAuth2: [] - ApiKey: [] parameters: - name: service_account_id in: path required: true schema: type: string pattern: ^[A-Za-z0-9_-]+$ title: Resource ID - name: org_id in: path required: true schema: type: string pattern: ^[a-z0-9]{3,400}$ title: Organization ID responses: '200': description: Successful Response content: application/json: schema: $ref: '#/components/schemas/RotateSecretResponse' '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' /api/3/organizations/{org_id}/service_accounts/{service_account_id}/projects/{project_id}: put: tags: - Service Accounts summary: Grant-Service-Account-Project-Access description: Grant a service account a project access level (VIEWER/EDITOR/etc.). operationId: grant-service-account-project-access security: - OAuth2: [] - ApiKey: [] parameters: - name: service_account_id in: path required: true schema: type: string pattern: ^[A-Za-z0-9_-]+$ title: Resource ID - name: project_id in: path required: true schema: type: string pattern: ^[A-Za-z0-9_-]+$ title: Resource ID - name: org_id in: path required: true schema: type: string pattern: ^[a-z0-9]{3,400}$ title: Organization ID requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GrantProjectAccessBody' responses: '200': description: Successful Response content: application/json: schema: $ref: '#/components/schemas/api3__service_accounts__service_accounts__ProjectAccessResponse' '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' delete: tags: - Service Accounts summary: Revoke-Service-Account-Project-Access description: Revoke a service account's access to a project. operationId: revoke-service-account-project-access security: - OAuth2: [] - ApiKey: [] parameters: - name: service_account_id in: path required: true schema: type: string pattern: ^[A-Za-z0-9_-]+$ title: Resource ID - name: project_id in: path required: true schema: type: string pattern: ^[A-Za-z0-9_-]+$ title: Resource ID - name: org_id in: path required: true schema: type: string pattern: ^[a-z0-9]{3,400}$ title: Organization ID responses: '204': description: Successful Response '422': description: Validation Error content: application/json: schema: $ref: '#/components/schemas/HTTPValidationError' components: schemas: ServiceAccountResponse: properties: id: type: string title: Id description: Unique identifier for the service account meta: $ref: '#/components/schemas/ServiceAccountMeta' service_account: $ref: '#/components/schemas/ServiceAccountSpec' type: object required: - id - meta - service_account title: ServiceAccountResponse RotateSecretResponse: properties: client_secret: type: string title: Client Secret description: The newly rotated client secret. Shown only here. type: object required: - client_secret title: RotateSecretResponse GrantProjectAccessBody: properties: access_level: type: string title: Access Level description: 'Project access level to grant. One of: [''VIEWER'', ''ANALYST'', ''MANAGER'', ''EDITOR'', ''OWNER'']' type: object required: - access_level title: GrantProjectAccessBody ServiceAccountCreateResponse: properties: id: type: string title: Id description: Unique identifier for the service account meta: $ref: '#/components/schemas/ServiceAccountMeta' service_account: $ref: '#/components/schemas/ServiceAccountSpec' client_secret: type: string title: Client Secret description: Client secret for the client_credentials flow. Returned only on creation and rotation; never stored or shown again. type: object required: - id - meta - service_account - client_secret title: ServiceAccountCreateResponse CreateServiceAccountBody: properties: name: type: string pattern: ^[a-zA-Z0-9][a-zA-Z0-9._-]{0,62}$ title: Service account name description: Unique name within the organization; forms the local part of the virtual user email, so it must be email-local safe roles: items: type: string type: array title: Roles description: Organization roles to grant the service account type: object required: - name title: CreateServiceAccountBody ServiceAccountListMeta: properties: org_id: type: string title: Org Id description: Organization the accounts belong to next_cursor: anyOf: - type: string - type: 'null' title: Next Cursor description: Cursor to retrieve the next page, or null on the last page more: type: boolean title: More description: True if there are further pages beyond this response type: object required: - org_id - next_cursor - more title: ServiceAccountListMeta ServiceAccountMeta: properties: name: type: string title: Name description: Display name of the service account org_id: type: string title: Org Id description: Organization the account belongs to owner: type: string title: Owner description: ID of the organization that owns it account_id: type: string title: Account Id description: Stable account id (the backing virtual user id) created_by: anyOf: - type: string - type: 'null' title: Created By description: Account id that created the service account created: type: string format: date-time title: Created description: When the account was created last_update: type: string format: date-time title: Last Update description: When the account was most recently modified type: object required: - name - org_id - owner - account_id - created_by - created - last_update title: ServiceAccountMeta ServiceAccountListResponse: properties: results: items: $ref: '#/components/schemas/ServiceAccountResponse' type: array title: Results meta: $ref: '#/components/schemas/ServiceAccountListMeta' type: object required: - results - meta title: ServiceAccountListResponse HTTPValidationError: properties: detail: items: $ref: '#/components/schemas/ValidationError' type: array title: Detail type: object title: HTTPValidationError api3__service_accounts__service_accounts__ProjectAccessResponse: properties: account_id: type: string title: Account Id description: The service account's account id project_id: type: string title: Project Id description: The project the grant applies to access_level: type: string title: Access Level description: The granted access level type: object required: - account_id - project_id - access_level title: ProjectAccessResponse ServiceAccountSpec: properties: auth0_client_id: type: string title: Auth0 Client Id description: Auth0 machine-to-machine client id used for client_credentials roles: items: type: string type: array title: Roles description: Organization roles granted to the service account type: object required: - auth0_client_id - roles title: ServiceAccountSpec UpdateRolesBody: properties: roles: items: type: string type: array title: Roles description: Organization roles to grant the service account, replacing any current roles type: object required: - roles title: UpdateRolesBody ValidationError: properties: loc: items: anyOf: - type: string - type: integer type: array title: Location msg: type: string title: Message type: type: string title: Error Type input: title: Input ctx: type: object title: Context type: object required: - loc - msg - type title: ValidationError securitySchemes: OAuth2: type: oauth2 flows: authorizationCode: scopes: openid: OpenID Connect identity profile: User profile email: User email address authorizationUrl: https://auth.apimetrics.io/authorize?audience=https://client.apimetrics.io tokenUrl: https://auth.apimetrics.io/oauth/token ApiKey: type: apiKey in: header name: X-Api-Key