openapi: 3.0.4
info:
title: Bench AccountActivities ServiceAccounts API
description: "
Versioning
\n\n The API is currently at version 1.0. All API endpoints (other than\n authentication) require you to specify the API version as part of the path.\n
\n\nURL Paths
\n\n Authentication requests should be made to /auth/signin,\n as documented below. All other API requests should be made to\n sub-paths of /rp/api/1.0/....\n
\n\nAuthentication
\n\n API requests are authenticated using an OAuth Bearer token.\n You can get a token by authenticating your user by sending a\n POST request to /auth/signin, with \"username and \"password\"\n parameters form-encoded in the body of the request.\n\n POST /auth/signin HTTP/1.1\n Content-Type: application/x-www-form-urlencoded\n\n username=user@example.com&password=some-secret-password\n
\n\n The response will be a JSON object including both\n \"access_token\" and \"refresh_token\" property.\n All other requests against the Bench API should include an\n authorization header: Authorization: Bearer xxxYYYzzz,\n where xxxYYYzzz is the value of \"access_token\" in the response.\n
\n For example:\n\n $ curl https://bench.gobridgit.com/auth/signin -H 'Content-Type: application/x-www-form-urlencoded' --data-urlencode 'username=someone@example.com' --data-urlencode 'password=[...snip...]'\n {\n \"access_token\": \"...snip...\",\n \"token_type\": \"Bearer\",\n \"refresh_token\": \"...snip...\"\n \"expiry\": \"2020-01-01T00:00:00.413440849Z\"\n }\n\n
\n\n\n The refresh token can be used to generate new session by request with /auth/token endpoint:\n\n POST /auth/token HTTP/1.1\n Content-Type: application/x-www-form-urlencoded\n\n grant_type=refresh_token&refresh_token=tGzv3JOkF0XG5Qx2TlKWIA\n
\n\n Note that once the refresh token is used, the previous access and refresh token is no longer valid.\n
\n For example:\n\n $ curl https://bench.gobridgit.com/auth/token -H 'Content-Type: application/x-www-form-urlencoded' --data-urlencode 'grant_type=refresh_token' --data-urlencode 'refresh_token=[...snip...]'\n {\n \"access_token\": \"...snip...\",\n \"token_type\": \"Bearer\",\n \"refresh_token\": \"...snip...\"\n \"expiry\": \"2020-01-01T00:00:00.413440849Z\"\n }\n
\n\nPagination
\n\n Several of the API endpoints are paginated. These are denoted by\n including the offset (zero-based offset) and limit query\n parameters. For example, to request the 10 items,\n set the offset=0 to limit=10.\n
\n NOTE: the result set contains items with index of 0-9\n
\n To request the next 10 items (starting at index 10),\n set the offset=10 to limit=10\n
\n\n Responses to paginated API endpoints return a JSON array of objects.\n If there are results beyond the page you have requested, the server\n will set a query-has-more: true header in the response.\n
\n\nRequest Encoding
\n\n GET and DELETE requests should have parameters encoded as URL query\n parameters. Boolean values should be encoded as true and\n false, not as 1 and 0.\n
\n\nErrors
\n\n Errors are returned for some response codes such as 400 Bad Request in the\n following format:\n\n {\n \"errors\": [\n {\n \"errorType\": \"ValidationError\",\n \"description\": \"The value of Name must be a string with a minimum length of 1 and a maximum length of 8 and not whitespace.\",\n \"field\": \"Name\",\n \"values\": [\n null\n ]\n }\n ],\n \"title\": \"One or more validation errors occurred.\",\n \"status\": 400,\n \"instance\": \"api/v1/accounts/0/persons\",\n \"requestUid\": \"123e4567-e89b-12d3-a456-426614174000\"\n }\n
\n"
version: '1.0'
servers:
- url: https://bench.gobridgit.com
description: Bridgit Bench production
security:
- {}
tags:
- name: ServiceAccounts
paths:
/rp/api/v1/accounts/{accountId}/service-accounts:
get:
tags:
- ServiceAccounts
summary: Gets service accounts in the given account
description: '
Permissions
Account: Read'
operationId: ServiceAccounts_GetServiceAccounts
parameters:
- name: accountId
in: path
description: The Account ID
required: true
schema:
type: integer
format: int32
- name: ids
in: query
description: (Optional) Filters the result to contain accounts that match the ids passed in.
schema:
type: array
items:
type: integer
format: int32
responses:
'200':
description: 'Success: Service Account model'
content:
text/plain:
schema:
type: array
items:
$ref: '#/components/schemas/ServiceAccountResponse'
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/ServiceAccountResponse'
text/json:
schema:
type: array
items:
$ref: '#/components/schemas/ServiceAccountResponse'
'400':
description: Bad Request
'401':
description: Unauthorized
'403':
description: Forbidden
post:
tags:
- ServiceAccounts
summary: Creates a service account in the given account
description: 'This endpoint will generate a unique login and password in the response.
There is no way to retrieve the password again after the account is created.
This is a limit of 10 service accounts on a single account.
Permissions
Account: Write'
operationId: ServiceAccounts_CreateServiceAccount
parameters:
- name: accountId
in: path
description: The Account ID
required: true
schema:
type: integer
format: int32
requestBody:
description: Object containing the name and group the service account will be created with
content:
application/json-patch+json:
schema:
$ref: '#/components/schemas/ServiceAccountRequest'
application/json:
schema:
$ref: '#/components/schemas/ServiceAccountRequest'
text/json:
schema:
$ref: '#/components/schemas/ServiceAccountRequest'
application/*+json:
schema:
$ref: '#/components/schemas/ServiceAccountRequest'
required: true
responses:
'201':
description: 'Success: Service Account model with password'
content:
text/plain:
schema:
$ref: '#/components/schemas/ServiceAccountDetailResponse'
example:
password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
id: 3245
name: Allocation Integration
login: b1c657b0a0864e9597cbdbacc67c79de
group: Administrator
allowedIPNetworks: null
createdOn: '2026-05-25T04:42:55.1879247Z'
application/json:
schema:
$ref: '#/components/schemas/ServiceAccountDetailResponse'
example:
password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
id: 3245
name: Allocation Integration
login: b1c657b0a0864e9597cbdbacc67c79de
group: Administrator
allowedIPNetworks: null
createdOn: '2026-05-25T04:42:55.1879247Z'
text/json:
schema:
$ref: '#/components/schemas/ServiceAccountDetailResponse'
example:
password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
id: 3245
name: Allocation Integration
login: b1c657b0a0864e9597cbdbacc67c79de
group: Administrator
allowedIPNetworks: null
createdOn: '2026-05-25T04:42:55.1879247Z'
'400':
description: Bad Request
'401':
description: Unauthorized
'403':
description: Forbidden
/rp/api/v1/accounts/{accountId}/service-accounts/{id}:
put:
tags:
- ServiceAccounts
summary: Updates a service account in the given account
description: 'You must specify both "name" and "group" for this endpoint.
Permissions
Account: Write'
operationId: ServiceAccounts_UpdateServiceAccount
parameters:
- name: accountId
in: path
description: The Account ID
required: true
schema:
type: integer
format: int32
- name: id
in: path
description: The Service Account ID
required: true
schema:
type: integer
format: int32
requestBody:
description: Object containing the name and group the service account will be updated with
content:
application/json-patch+json:
schema:
$ref: '#/components/schemas/ServiceAccountRequest'
application/json:
schema:
$ref: '#/components/schemas/ServiceAccountRequest'
text/json:
schema:
$ref: '#/components/schemas/ServiceAccountRequest'
application/*+json:
schema:
$ref: '#/components/schemas/ServiceAccountRequest'
required: true
responses:
'204':
description: Success
'400':
description: Bad Request
'401':
description: Unauthorized
'403':
description: Forbidden
delete:
tags:
- ServiceAccounts
summary: Deactivates a service account in the given account
description: 'Deactivates the account preventing it from being able to log in and make API calls.
Permissions
Account: Write'
operationId: ServiceAccounts_DeactivateServiceAccount
parameters:
- name: accountId
in: path
description: The Account ID
required: true
schema:
type: integer
format: int32
- name: id
in: path
description: The Service Account ID
required: true
schema:
type: integer
format: int32
responses:
'204':
description: Success
'400':
description: Bad Request
'401':
description: Unauthorized
'403':
description: Forbidden
/rp/api/v1/accounts/{accountId}/service-accounts/{id}/reset-password:
post:
tags:
- ServiceAccounts
summary: Generates a new password for a service account in the given account
description: 'This endpoint will generate a new password in the response.
There is no way to retrieve the password again. A new password will need to be generated if you lose it.
Permissions
Account: Write'
operationId: ServiceAccounts_ResetPassword
parameters:
- name: accountId
in: path
description: The Account ID
required: true
schema:
type: integer
format: int32
- name: id
in: path
description: The Service Account ID
required: true
schema:
type: integer
format: int32
responses:
'200':
description: 'Success: Service Account model with password'
content:
text/plain:
schema:
$ref: '#/components/schemas/ServiceAccountDetailResponse'
example:
password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
id: 3245
name: Allocation Integration
login: b1c657b0a0864e9597cbdbacc67c79de
group: Administrator
allowedIPNetworks: null
createdOn: '2026-05-25T04:42:55.1888354Z'
application/json:
schema:
$ref: '#/components/schemas/ServiceAccountDetailResponse'
example:
password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
id: 3245
name: Allocation Integration
login: b1c657b0a0864e9597cbdbacc67c79de
group: Administrator
allowedIPNetworks: null
createdOn: '2026-05-25T04:42:55.1888354Z'
text/json:
schema:
$ref: '#/components/schemas/ServiceAccountDetailResponse'
example:
password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
id: 3245
name: Allocation Integration
login: b1c657b0a0864e9597cbdbacc67c79de
group: Administrator
allowedIPNetworks: null
createdOn: '2026-05-25T04:42:55.1888354Z'
'400':
description: Bad Request
'401':
description: Unauthorized
'403':
description: Forbidden
'422':
description: Unprocessable Entitiy - Something went wrong trying to reset the password
components:
schemas:
ServiceAccountResponse:
type: object
properties:
id:
type: integer
format: int32
example: 3245
name:
type: string
nullable: true
example: Allocation Integration
login:
type: string
nullable: true
example: b1c657b0a0864e9597cbdbacc67c79de
group:
type: string
nullable: true
example: Administrator
allowedIPNetworks:
type: array
items:
type: string
nullable: true
createdOn:
type: string
format: date-time
example: '2020-01-01'
additionalProperties: false
ServiceAccountRequest:
type: object
properties:
name:
type: string
nullable: true
example: Allocation Integration
group:
type: string
nullable: true
example: Administrator
allowedIPNetworks:
maxItems: 50
type: array
items:
type: string
description: The list of allowed IP networks for the service account.
nullable: true
example:
- 192.168.1.0/24
- 10.0.0.0/8
additionalProperties: false
ServiceAccountDetailResponse:
type: object
properties:
password:
type: string
nullable: true
example: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
id:
type: integer
format: int32
example: 3245
name:
type: string
nullable: true
example: Allocation Integration
login:
type: string
nullable: true
example: b1c657b0a0864e9597cbdbacc67c79de
group:
type: string
nullable: true
example: Administrator
allowedIPNetworks:
type: array
items:
type: string
nullable: true
createdOn:
type: string
format: date-time
example: '2020-01-01'
additionalProperties: false
securitySchemes:
Bearer:
type: http
description: Standard Authorization header using the Bearer scheme
scheme: bearer
bearerFormat: JWT