openapi: 3.0.4 info: title: Bench AccountActivities ServiceAccounts API description: "

Versioning

\n

\n The API is currently at version 1.0. All API endpoints (other than\n authentication) require you to specify the API version as part of the path.\n

\n\n

URL Paths

\n

\n Authentication requests should be made to /auth/signin,\n as documented below. All other API requests should be made to\n sub-paths of /rp/api/1.0/....\n

\n\n

Authentication

\n

\n API requests are authenticated using an OAuth Bearer token.\n You can get a token by authenticating your user by sending a\n POST request to /auth/signin, with \"username and \"password\"\n parameters form-encoded in the body of the request.\n\n POST /auth/signin HTTP/1.1\n Content-Type: application/x-www-form-urlencoded\n\n username=user@example.com&password=some-secret-password\n

\n

\n The response will be a JSON object including both\n \"access_token\" and \"refresh_token\" property.\n All other requests against the Bench API should include an\n authorization header: Authorization: Bearer xxxYYYzzz,\n where xxxYYYzzz is the value of \"access_token\" in the response.\n

\n For example:\n\n $ curl https://bench.gobridgit.com/auth/signin -H 'Content-Type: application/x-www-form-urlencoded' --data-urlencode 'username=someone@example.com' --data-urlencode 'password=[...snip...]'\n {\n \"access_token\": \"...snip...\",\n \"token_type\": \"Bearer\",\n \"refresh_token\": \"...snip...\"\n \"expiry\": \"2020-01-01T00:00:00.413440849Z\"\n }\n\n

\n\n

\n The refresh token can be used to generate new session by request with /auth/token endpoint:\n\n POST /auth/token HTTP/1.1\n Content-Type: application/x-www-form-urlencoded\n\n grant_type=refresh_token&refresh_token=tGzv3JOkF0XG5Qx2TlKWIA\n

\n

\n Note that once the refresh token is used, the previous access and refresh token is no longer valid.\n

\n For example:\n\n $ curl https://bench.gobridgit.com/auth/token -H 'Content-Type: application/x-www-form-urlencoded' --data-urlencode 'grant_type=refresh_token' --data-urlencode 'refresh_token=[...snip...]'\n {\n \"access_token\": \"...snip...\",\n \"token_type\": \"Bearer\",\n \"refresh_token\": \"...snip...\"\n \"expiry\": \"2020-01-01T00:00:00.413440849Z\"\n }\n

\n\n

Pagination

\n

\n Several of the API endpoints are paginated. These are denoted by\n including the offset (zero-based offset) and limit query\n parameters. For example, to request the 10 items,\n set the offset=0 to limit=10.\n
\n NOTE: the result set contains items with index of 0-9\n
\n To request the next 10 items (starting at index 10),\n set the offset=10 to limit=10\n

\n

\n Responses to paginated API endpoints return a JSON array of objects.\n If there are results beyond the page you have requested, the server\n will set a query-has-more: true header in the response.\n

\n\n

Request Encoding

\n

\n GET and DELETE requests should have parameters encoded as URL query\n parameters. Boolean values should be encoded as true and\n false, not as 1 and 0.\n

\n\n

Errors

\n

\n Errors are returned for some response codes such as 400 Bad Request in the\n following format:\n\n {\n \"errors\": [\n {\n \"errorType\": \"ValidationError\",\n \"description\": \"The value of Name must be a string with a minimum length of 1 and a maximum length of 8 and not whitespace.\",\n \"field\": \"Name\",\n \"values\": [\n null\n ]\n }\n ],\n \"title\": \"One or more validation errors occurred.\",\n \"status\": 400,\n \"instance\": \"api/v1/accounts/0/persons\",\n \"requestUid\": \"123e4567-e89b-12d3-a456-426614174000\"\n }\n

\n" version: '1.0' servers: - url: https://bench.gobridgit.com description: Bridgit Bench production security: - {} tags: - name: ServiceAccounts paths: /rp/api/v1/accounts/{accountId}/service-accounts: get: tags: - ServiceAccounts summary: Gets service accounts in the given account description: '
Permissions
Account: Read' operationId: ServiceAccounts_GetServiceAccounts parameters: - name: accountId in: path description: The Account ID required: true schema: type: integer format: int32 - name: ids in: query description: (Optional) Filters the result to contain accounts that match the ids passed in. schema: type: array items: type: integer format: int32 responses: '200': description: 'Success: Service Account model' content: text/plain: schema: type: array items: $ref: '#/components/schemas/ServiceAccountResponse' application/json: schema: type: array items: $ref: '#/components/schemas/ServiceAccountResponse' text/json: schema: type: array items: $ref: '#/components/schemas/ServiceAccountResponse' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden post: tags: - ServiceAccounts summary: Creates a service account in the given account description: 'This endpoint will generate a unique login and password in the response. There is no way to retrieve the password again after the account is created. This is a limit of 10 service accounts on a single account.
Permissions
Account: Write' operationId: ServiceAccounts_CreateServiceAccount parameters: - name: accountId in: path description: The Account ID required: true schema: type: integer format: int32 requestBody: description: Object containing the name and group the service account will be created with content: application/json-patch+json: schema: $ref: '#/components/schemas/ServiceAccountRequest' application/json: schema: $ref: '#/components/schemas/ServiceAccountRequest' text/json: schema: $ref: '#/components/schemas/ServiceAccountRequest' application/*+json: schema: $ref: '#/components/schemas/ServiceAccountRequest' required: true responses: '201': description: 'Success: Service Account model with password' content: text/plain: schema: $ref: '#/components/schemas/ServiceAccountDetailResponse' example: password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: 3245 name: Allocation Integration login: b1c657b0a0864e9597cbdbacc67c79de group: Administrator allowedIPNetworks: null createdOn: '2026-05-25T04:42:55.1879247Z' application/json: schema: $ref: '#/components/schemas/ServiceAccountDetailResponse' example: password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: 3245 name: Allocation Integration login: b1c657b0a0864e9597cbdbacc67c79de group: Administrator allowedIPNetworks: null createdOn: '2026-05-25T04:42:55.1879247Z' text/json: schema: $ref: '#/components/schemas/ServiceAccountDetailResponse' example: password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: 3245 name: Allocation Integration login: b1c657b0a0864e9597cbdbacc67c79de group: Administrator allowedIPNetworks: null createdOn: '2026-05-25T04:42:55.1879247Z' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden /rp/api/v1/accounts/{accountId}/service-accounts/{id}: put: tags: - ServiceAccounts summary: Updates a service account in the given account description: 'You must specify both "name" and "group" for this endpoint.
Permissions
Account: Write' operationId: ServiceAccounts_UpdateServiceAccount parameters: - name: accountId in: path description: The Account ID required: true schema: type: integer format: int32 - name: id in: path description: The Service Account ID required: true schema: type: integer format: int32 requestBody: description: Object containing the name and group the service account will be updated with content: application/json-patch+json: schema: $ref: '#/components/schemas/ServiceAccountRequest' application/json: schema: $ref: '#/components/schemas/ServiceAccountRequest' text/json: schema: $ref: '#/components/schemas/ServiceAccountRequest' application/*+json: schema: $ref: '#/components/schemas/ServiceAccountRequest' required: true responses: '204': description: Success '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden delete: tags: - ServiceAccounts summary: Deactivates a service account in the given account description: 'Deactivates the account preventing it from being able to log in and make API calls.
Permissions
Account: Write' operationId: ServiceAccounts_DeactivateServiceAccount parameters: - name: accountId in: path description: The Account ID required: true schema: type: integer format: int32 - name: id in: path description: The Service Account ID required: true schema: type: integer format: int32 responses: '204': description: Success '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden /rp/api/v1/accounts/{accountId}/service-accounts/{id}/reset-password: post: tags: - ServiceAccounts summary: Generates a new password for a service account in the given account description: 'This endpoint will generate a new password in the response. There is no way to retrieve the password again. A new password will need to be generated if you lose it.
Permissions
Account: Write' operationId: ServiceAccounts_ResetPassword parameters: - name: accountId in: path description: The Account ID required: true schema: type: integer format: int32 - name: id in: path description: The Service Account ID required: true schema: type: integer format: int32 responses: '200': description: 'Success: Service Account model with password' content: text/plain: schema: $ref: '#/components/schemas/ServiceAccountDetailResponse' example: password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: 3245 name: Allocation Integration login: b1c657b0a0864e9597cbdbacc67c79de group: Administrator allowedIPNetworks: null createdOn: '2026-05-25T04:42:55.1888354Z' application/json: schema: $ref: '#/components/schemas/ServiceAccountDetailResponse' example: password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: 3245 name: Allocation Integration login: b1c657b0a0864e9597cbdbacc67c79de group: Administrator allowedIPNetworks: null createdOn: '2026-05-25T04:42:55.1888354Z' text/json: schema: $ref: '#/components/schemas/ServiceAccountDetailResponse' example: password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: 3245 name: Allocation Integration login: b1c657b0a0864e9597cbdbacc67c79de group: Administrator allowedIPNetworks: null createdOn: '2026-05-25T04:42:55.1888354Z' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '422': description: Unprocessable Entitiy - Something went wrong trying to reset the password components: schemas: ServiceAccountResponse: type: object properties: id: type: integer format: int32 example: 3245 name: type: string nullable: true example: Allocation Integration login: type: string nullable: true example: b1c657b0a0864e9597cbdbacc67c79de group: type: string nullable: true example: Administrator allowedIPNetworks: type: array items: type: string nullable: true createdOn: type: string format: date-time example: '2020-01-01' additionalProperties: false ServiceAccountRequest: type: object properties: name: type: string nullable: true example: Allocation Integration group: type: string nullable: true example: Administrator allowedIPNetworks: maxItems: 50 type: array items: type: string description: The list of allowed IP networks for the service account. nullable: true example: - 192.168.1.0/24 - 10.0.0.0/8 additionalProperties: false ServiceAccountDetailResponse: type: object properties: password: type: string nullable: true example: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0 id: type: integer format: int32 example: 3245 name: type: string nullable: true example: Allocation Integration login: type: string nullable: true example: b1c657b0a0864e9597cbdbacc67c79de group: type: string nullable: true example: Administrator allowedIPNetworks: type: array items: type: string nullable: true createdOn: type: string format: date-time example: '2020-01-01' additionalProperties: false securitySchemes: Bearer: type: http description: Standard Authorization header using the Bearer scheme scheme: bearer bearerFormat: JWT