openapi: 3.2.0 info: description: API Documentation title: Control-plane Service Accounts API version: '1.0' servers: - url: https://facetsdemo.console.facets.cloud description: Generated server url security: - basicAuth: [] tags: - name: Service Accounts paths: /cc-ui/v1/service-accounts: get: description: '- **Description:** Returns every service account shipped with the control plane, its role, the role''s current permissions, any shipped defaults that have been edited away, and whether its tokens can be managed here at all. - **Permissions:** Requires CI_USER_TOKEN_MANAGE permission.' operationId: list responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/ServiceAccountResponse' description: OK '400': content: application/json: schema: oneOf: - $ref: '#/components/schemas/ErrorDetails' - $ref: '#/components/schemas/GithubAppPermissionsPendingErrorDetails' description: Bad Request '403': content: application/json: schema: type: string description: Forbidden '404': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Not Found '405': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Method Not Allowed '409': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Conflict '500': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Internal Server Error summary: List the shipped service accounts tags: - Service Accounts /cc-ui/v1/service-accounts/{accountId}/tokens: get: description: '- **Description:** Lists the account''s named API tokens, newest first. Raw token values are never returned — only a mint response carries one. Tokens owned by a provisioning flow come back with `revocable: false`. - **Permissions:** Requires CI_USER_TOKEN_MANAGE permission.' operationId: listTokens parameters: - in: path name: accountId required: true schema: type: string responses: '200': content: application/json: schema: type: array items: $ref: '#/components/schemas/ServiceAccountTokenView' description: OK '400': content: application/json: schema: oneOf: - $ref: '#/components/schemas/ErrorDetails' - $ref: '#/components/schemas/GithubAppPermissionsPendingErrorDetails' description: Bad Request '403': content: application/json: schema: type: string description: Forbidden '404': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Not Found '405': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Method Not Allowed '409': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Conflict '500': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Internal Server Error summary: List a service account's tokens tags: - Service Accounts post: description: '- **Description:** Mints a named API token for the account. The raw token is returned exactly once and cannot be recovered later. Rejected for accounts whose tokens are managed by their integration. - **Permissions:** Requires CI_USER_TOKEN_MANAGE permission.' operationId: mintToken parameters: - in: path name: accountId required: true schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/CreateServiceAccountTokenRequest' required: true responses: '200': content: application/json: schema: $ref: '#/components/schemas/ServiceAccountTokenResponse' description: OK '400': content: application/json: schema: oneOf: - $ref: '#/components/schemas/ErrorDetails' - $ref: '#/components/schemas/GithubAppPermissionsPendingErrorDetails' description: Bad Request '403': content: application/json: schema: type: string description: Forbidden '404': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Not Found '405': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Method Not Allowed '409': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Conflict '500': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Internal Server Error summary: Mint a service account token tags: - Service Accounts /cc-ui/v1/service-accounts/{accountId}/tokens/{tokenId}: delete: description: '- **Description:** Revokes one of the account''s tokens and returns the token that was removed. Tokens owned by a provisioning flow (the modules-repo and Praxis integration tokens) cannot be revoked here — rotate them from their own flow instead. - **Permissions:** Requires CI_USER_TOKEN_MANAGE permission.' operationId: revokeToken parameters: - in: path name: accountId required: true schema: type: string - in: path name: tokenId required: true schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/ServiceAccountTokenView' description: OK '400': content: application/json: schema: oneOf: - $ref: '#/components/schemas/ErrorDetails' - $ref: '#/components/schemas/GithubAppPermissionsPendingErrorDetails' description: Bad Request '403': content: application/json: schema: type: string description: Forbidden '404': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Not Found '405': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Method Not Allowed '409': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Conflict '500': content: application/json: schema: $ref: '#/components/schemas/ErrorDetails' description: Internal Server Error summary: Revoke a service account token tags: - Service Accounts components: schemas: ServiceAccountTokenView: type: object properties: createdOn: type: string format: date-time description: type: string name: type: string revocable: type: boolean tokenId: type: string userName: type: string GithubAppPermissionsPendingErrorDetails: type: object properties: approvalUrl: type: string code: type: string errorCode: type: string message: type: string missingPermissions: type: array items: type: string ErrorDetails: type: object properties: code: type: string message: type: string CreateServiceAccountTokenRequest: type: object properties: description: type: string name: type: string ServiceAccountResponse: type: object properties: id: type: string missingDefaultPermissions: uniqueItems: true type: array items: type: string enum: - ACCOUNTS_WRITE - ACCOUNTS_DELETE - ALERTS_CONFIGURE - ARTIFACTORY_WRITE - ARTIFACTORY_DELETE - ARTIFACTS_DELETE - ARTIFACTS_WRITE - ARTIFACT_ROUTING_RULE_WRITE - ARTIFACT_ROUTING_RULE_DELETE - APPLICATION_ROLLING_RESTART - RUN_ACTION - RUN_CLOUD_ACTION - APPLICATION_DEPLOYMENT_PROMOTE - APPLICATION_DEPLOYMENT_ABORT - BILLING_MANAGE - CHANNEL_WRITE - CHANNEL_DELETE - ENVIRONMENT_CONFIGURE - ENVIRONMENT_DELETE - ENVIRONMENT_WRITE - ENVIRONMENT_DESTROY - ENVIRONMENT_LAUNCH - OAUTH_INTEGRATION_DELETE - OAUTH_INTEGRATION_WRITE - RESOURCE_OVERRIDE - RESOURCE_WRITE - RESOURCE_DELETE - CRITICAL_RESOURCE_WRITE - RESOURCE_GROUP_READ - RESOURCE_GROUP_WRITE - RESOURCE_GROUP_DELETE - RELEASE_APPROVAL_AUTHORITY - RELEASE_FULL - RELEASE_PLAN - RELEASE_APPLY_PLAN - RELEASE_SELECTIVE - RELEASE_CUSTOM - RELEASE_IMPORT - RELEASE_MAINTENANCE - RELEASE_TERRAFORM_EXPORT - RELEASE_SCALE_UP - RELEASE_SCALE_DOWN - RELEASE_FULL_ALLOW_DESTROY - RELEASE_SELECTIVE_ALLOW_DESTROY - RELEASE_CUSTOM_ALLOW_DESTROY - RELEASE_PAUSE - RELEASE_ABORT - STACK_CONFIGURE - STACK_WRITE - STACK_DELETE - BLUEPRINT_PR_CREATE - BLUEPRINT_PR_MERGE - BLUEPRINT_PR_CLOSE - SUBSCRIPTION_WRITE - SUBSCRIPTION_DELETE - SETTINGS_WRITE - USER_READ - USER_WRITE - USER_DELETE - CI_USER_TOKEN_MANAGE - TEMPLATE_WRITE - TEMPLATE_DELETE - TRASH_RESTORE - TRASH_DELETE - USER_GROUP_READ - USER_GROUP_WRITE - USER_GROUP_DELETE - CUSTOM_ROLE_READ - CUSTOM_ROLE_WRITE - CUSTOM_ROLE_DELETE - K8S_READER - K8S_DEBUGGER - K8S_CUSTOM - K8S_ADMIN - K8S_CREDENTIALS - CLI_ARTIFACT_PUSH - K8S_PERMISSION - PIPELINE_WRITE - ARTIFACT_CI_WRITE - ARTIFACT_CI_DELETE - PROMOTIONAL_WORKFLOW_WRITE - PROMOTIONAL_WORKFLOW_DELETE - VIEW_RESOURCE_SECRETS - COST_EXPLORER_VIEW - RELEASE_STREAM_WRITE - RELEASE_STREAM_DELETE - BLUEPRINT_TEMPLATE_WRITE - BLUEPRINT_TEMPLATE_DELETE - VPN_CONNECT - OPA_WRITE - OPA_EXECUTE - OPA_DELETE - AUDIT_LOGS_VIEW - CI_CD_CONFIGURE - VIEW_SECRETS - MAINTENANCE_WINDOW_EDIT - MODULE_READ - MODULE_WRITE - MODULE_DELETE - MODULE_REPO_MANAGE - PROJECT_TYPE_WRITE - PROJECT_TYPE_DELETE - WEB_COMPONENT_WRITE - WEB_COMPONENT_DELETE roleLabel: type: string roleName: type: string rolePermissions: uniqueItems: true type: array items: type: string enum: - ACCOUNTS_WRITE - ACCOUNTS_DELETE - ALERTS_CONFIGURE - ARTIFACTORY_WRITE - ARTIFACTORY_DELETE - ARTIFACTS_DELETE - ARTIFACTS_WRITE - ARTIFACT_ROUTING_RULE_WRITE - ARTIFACT_ROUTING_RULE_DELETE - APPLICATION_ROLLING_RESTART - RUN_ACTION - RUN_CLOUD_ACTION - APPLICATION_DEPLOYMENT_PROMOTE - APPLICATION_DEPLOYMENT_ABORT - BILLING_MANAGE - CHANNEL_WRITE - CHANNEL_DELETE - ENVIRONMENT_CONFIGURE - ENVIRONMENT_DELETE - ENVIRONMENT_WRITE - ENVIRONMENT_DESTROY - ENVIRONMENT_LAUNCH - OAUTH_INTEGRATION_DELETE - OAUTH_INTEGRATION_WRITE - RESOURCE_OVERRIDE - RESOURCE_WRITE - RESOURCE_DELETE - CRITICAL_RESOURCE_WRITE - RESOURCE_GROUP_READ - RESOURCE_GROUP_WRITE - RESOURCE_GROUP_DELETE - RELEASE_APPROVAL_AUTHORITY - RELEASE_FULL - RELEASE_PLAN - RELEASE_APPLY_PLAN - RELEASE_SELECTIVE - RELEASE_CUSTOM - RELEASE_IMPORT - RELEASE_MAINTENANCE - RELEASE_TERRAFORM_EXPORT - RELEASE_SCALE_UP - RELEASE_SCALE_DOWN - RELEASE_FULL_ALLOW_DESTROY - RELEASE_SELECTIVE_ALLOW_DESTROY - RELEASE_CUSTOM_ALLOW_DESTROY - RELEASE_PAUSE - RELEASE_ABORT - STACK_CONFIGURE - STACK_WRITE - STACK_DELETE - BLUEPRINT_PR_CREATE - BLUEPRINT_PR_MERGE - BLUEPRINT_PR_CLOSE - SUBSCRIPTION_WRITE - SUBSCRIPTION_DELETE - SETTINGS_WRITE - USER_READ - USER_WRITE - USER_DELETE - CI_USER_TOKEN_MANAGE - TEMPLATE_WRITE - TEMPLATE_DELETE - TRASH_RESTORE - TRASH_DELETE - USER_GROUP_READ - USER_GROUP_WRITE - USER_GROUP_DELETE - CUSTOM_ROLE_READ - CUSTOM_ROLE_WRITE - CUSTOM_ROLE_DELETE - K8S_READER - K8S_DEBUGGER - K8S_CUSTOM - K8S_ADMIN - K8S_CREDENTIALS - CLI_ARTIFACT_PUSH - K8S_PERMISSION - PIPELINE_WRITE - ARTIFACT_CI_WRITE - ARTIFACT_CI_DELETE - PROMOTIONAL_WORKFLOW_WRITE - PROMOTIONAL_WORKFLOW_DELETE - VIEW_RESOURCE_SECRETS - COST_EXPLORER_VIEW - RELEASE_STREAM_WRITE - RELEASE_STREAM_DELETE - BLUEPRINT_TEMPLATE_WRITE - BLUEPRINT_TEMPLATE_DELETE - VPN_CONNECT - OPA_WRITE - OPA_EXECUTE - OPA_DELETE - AUDIT_LOGS_VIEW - CI_CD_CONFIGURE - VIEW_SECRETS - MAINTENANCE_WINDOW_EDIT - MODULE_READ - MODULE_WRITE - MODULE_DELETE - MODULE_REPO_MANAGE - PROJECT_TYPE_WRITE - PROJECT_TYPE_DELETE - WEB_COMPONENT_WRITE - WEB_COMPONENT_DELETE tokensUserManaged: type: boolean userName: type: string ServiceAccountTokenResponse: type: object properties: name: type: string rawToken: type: string tokenId: type: string userName: type: string securitySchemes: basicAuth: description: Basic Authentication scheme: basic type: http