openapi: 3.2.0 info: title: Bench Service Accounts API description: 'Versioning The API is currently at version 1.0.' version: '1.0' servers: - url: https://bench.gobridgit.com description: Bridgit Bench production security: - {} tags: - name: Service Accounts paths: /rp/api/v1/accounts/{accountId}/service-accounts: get: tags: - Service Accounts summary: Gets service accounts in the given account description: 'Permissions Account: Read' operationId: ServiceAccounts_GetServiceAccounts parameters: - name: accountId in: path description: The Account ID required: true schema: type: integer format: int32 - name: ids in: query description: (Optional) Filters the result to contain accounts that match the ids passed in. schema: type: array items: type: integer format: int32 responses: '200': description: 'Success: Service Account model' content: text/plain: schema: type: array items: $ref: '#/components/schemas/ServiceAccountResponse' application/json: schema: type: array items: $ref: '#/components/schemas/ServiceAccountResponse' text/json: schema: type: array items: $ref: '#/components/schemas/ServiceAccountResponse' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden post: tags: - Service Accounts summary: Creates a service account in the given account description: 'This endpoint will generate a unique login and password in the response. There is no way to retrieve the password again after the account is created. This is a limit of 10 service accounts on a single account. Permissions Account: Write' operationId: ServiceAccounts_CreateServiceAccount parameters: - name: accountId in: path description: The Account ID required: true schema: type: integer format: int32 requestBody: description: Object containing the name and group the service account will be created with content: application/json-patch+json: schema: $ref: '#/components/schemas/ServiceAccountRequest' application/json: schema: $ref: '#/components/schemas/ServiceAccountRequest' text/json: schema: $ref: '#/components/schemas/ServiceAccountRequest' application/*+json: schema: $ref: '#/components/schemas/ServiceAccountRequest' required: true responses: '201': description: 'Success: Service Account model with password' content: text/plain: schema: $ref: '#/components/schemas/ServiceAccountDetailResponse' example: password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: 3245 name: Allocation Integration login: b1c657b0a0864e9597cbdbacc67c79de group: Administrator allowedIPNetworks: null createdOn: '2026-05-25T04:42:55.1879247Z' application/json: schema: $ref: '#/components/schemas/ServiceAccountDetailResponse' example: password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: 3245 name: Allocation Integration login: b1c657b0a0864e9597cbdbacc67c79de group: Administrator allowedIPNetworks: null createdOn: '2026-05-25T04:42:55.1879247Z' text/json: schema: $ref: '#/components/schemas/ServiceAccountDetailResponse' example: password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: 3245 name: Allocation Integration login: b1c657b0a0864e9597cbdbacc67c79de group: Administrator allowedIPNetworks: null createdOn: '2026-05-25T04:42:55.1879247Z' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden /rp/api/v1/accounts/{accountId}/service-accounts/{id}: put: tags: - Service Accounts summary: Updates a service account in the given account description: 'You must specify both "name" and "group" for this endpoint. Permissions Account: Write' operationId: ServiceAccounts_UpdateServiceAccount parameters: - name: accountId in: path description: The Account ID required: true schema: type: integer format: int32 - name: id in: path description: The Service Account ID required: true schema: type: integer format: int32 requestBody: description: Object containing the name and group the service account will be updated with content: application/json-patch+json: schema: $ref: '#/components/schemas/ServiceAccountRequest' application/json: schema: $ref: '#/components/schemas/ServiceAccountRequest' text/json: schema: $ref: '#/components/schemas/ServiceAccountRequest' application/*+json: schema: $ref: '#/components/schemas/ServiceAccountRequest' required: true responses: '204': description: Success '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden delete: tags: - Service Accounts summary: Deactivates a service account in the given account description: 'Deactivates the account preventing it from being able to log in and make API calls. Permissions Account: Write' operationId: ServiceAccounts_DeactivateServiceAccount parameters: - name: accountId in: path description: The Account ID required: true schema: type: integer format: int32 - name: id in: path description: The Service Account ID required: true schema: type: integer format: int32 responses: '204': description: Success '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden /rp/api/v1/accounts/{accountId}/service-accounts/{id}/reset-password: post: tags: - Service Accounts summary: Generates a new password for a service account in the given account description: 'This endpoint will generate a new password in the response. There is no way to retrieve the password again. A new password will need to be generated if you lose it. Permissions Account: Write' operationId: ServiceAccounts_ResetPassword parameters: - name: accountId in: path description: The Account ID required: true schema: type: integer format: int32 - name: id in: path description: The Service Account ID required: true schema: type: integer format: int32 responses: '200': description: 'Success: Service Account model with password' content: text/plain: schema: $ref: '#/components/schemas/ServiceAccountDetailResponse' example: password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: 3245 name: Allocation Integration login: b1c657b0a0864e9597cbdbacc67c79de group: Administrator allowedIPNetworks: null createdOn: '2026-05-25T04:42:55.1888354Z' application/json: schema: $ref: '#/components/schemas/ServiceAccountDetailResponse' example: password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: 3245 name: Allocation Integration login: b1c657b0a0864e9597cbdbacc67c79de group: Administrator allowedIPNetworks: null createdOn: '2026-05-25T04:42:55.1888354Z' text/json: schema: $ref: '#/components/schemas/ServiceAccountDetailResponse' example: password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: 3245 name: Allocation Integration login: b1c657b0a0864e9597cbdbacc67c79de group: Administrator allowedIPNetworks: null createdOn: '2026-05-25T04:42:55.1888354Z' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '422': description: Unprocessable Entitiy - Something went wrong trying to reset the password components: schemas: ServiceAccountRequest: type: object properties: name: type: - string - 'null' example: Allocation Integration group: type: - string - 'null' example: Administrator allowedIPNetworks: maxItems: 50 type: - array - 'null' items: type: string description: The list of allowed IP networks for the service account. example: - 192.168.1.0/24 - 10.0.0.0/8 additionalProperties: false ServiceAccountDetailResponse: type: object properties: password: type: - string - 'null' example: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: type: integer format: int32 example: 3245 name: type: - string - 'null' example: Allocation Integration login: type: - string - 'null' example: b1c657b0a0864e9597cbdbacc67c79de group: type: - string - 'null' example: Administrator allowedIPNetworks: type: - array - 'null' items: type: string createdOn: type: string format: date-time example: '2020-01-01' additionalProperties: false ServiceAccountResponse: type: object properties: id: type: integer format: int32 example: 3245 name: type: - string - 'null' example: Allocation Integration login: type: - string - 'null' example: b1c657b0a0864e9597cbdbacc67c79de group: type: - string - 'null' example: Administrator allowedIPNetworks: type: - array - 'null' items: type: string createdOn: type: string format: date-time example: '2020-01-01' additionalProperties: false securitySchemes: Bearer: type: http description: Standard Authorization header using the Bearer scheme scheme: bearer bearerFormat: JWT