openapi: 3.2.0 info: title: Service Accounts Account API description: Manage service accounts and their permissions. contact: name: '' version: 2021-03 servers: - url: https://api.eu.cloud.talend.com description: URL for the AWS Europe region x-talend: isPublished: true - url: https://api.ap.cloud.talend.com description: URL for the AWS Asia Pacific region x-talend: isPublished: true - url: https://api.us.cloud.talend.com description: URL for the AWS United States East region x-talend: isPublished: true - url: https://api.au.cloud.talend.com description: URL for the AWS Australia region x-talend: isPublished: true - url: https://api.us-west.cloud.talend.com description: URL for the Azure United States West region x-talend: isPublished: true security: - Public: [] tags: - name: Account paths: /account/service-accounts/{id}: parameters: - name: id in: path required: true schema: type: string get: summary: Get a service account description: Get the service account of a given ID. parameters: - $ref: '#/components/parameters/talendVersion' - $ref: '#/components/parameters/talend-version' responses: '200': description: Service account is successfully retrieved. content: application/json: schema: $ref: '#/components/schemas/ServiceAccount' '401': description: Bearer token is invalid or missing. content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Permissions to read service account information are missing. '404': description: Service account is not found. content: application/json: schema: $ref: '#/components/schemas/Error' '500': description: Status 500 content: application/json: schema: $ref: '#/components/schemas/Error' tags: - Account operationId: getAccountServiceAccountsById x-operation-id-source: derived put: summary: Update a service account description: Update the service account of a given account ID. In this update, only the name and the permissions of a service account can be changed. parameters: - $ref: '#/components/parameters/talendVersion' - $ref: '#/components/parameters/talend-version' requestBody: description: The service account with updates is displayed content: application/json: schema: $ref: '#/components/schemas/ServiceAccount' responses: '200': description: Service account is successfully updated. content: application/json: schema: $ref: '#/components/schemas/ServiceAccount' '400': description: Invalid request body. The message varies depending on the cause of the bad request. For example, the cause could be a malformed body or invalid permissions passed in the body. content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Bearer token is invalid or missing. content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Permissions to update the service account are missing. content: application/json: schema: $ref: '#/components/schemas/Error' '404': description: Service account is not found. content: application/json: schema: $ref: '#/components/schemas/Error' '409': description: The service account name is already used content: application/json: schema: type: object properties: detail: type: string description: Error detail example: "{\n \"detail\": \"The service account name is already used\"\n}" '500': description: Status 500 content: application/json: schema: $ref: '#/components/schemas/Error' tags: - Account operationId: putAccountServiceAccountsById x-operation-id-source: derived delete: summary: Delete a service account description: Delete the service account of a given ID. parameters: - $ref: '#/components/parameters/talendVersion' - $ref: '#/components/parameters/talend-version' responses: '204': description: Service account is successfully deleted. '401': description: Bearer token is invalid or missing. content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Permissions to delete the service account is missing. '404': description: Service account is not found. content: application/json: schema: $ref: '#/components/schemas/Error' '500': description: Status 500 content: application/json: schema: $ref: '#/components/schemas/Error' tags: - Account operationId: deleteAccountServiceAccountsById x-operation-id-source: derived /account/service-accounts: get: summary: List service accounts description: List the service accounts in the current tenant. parameters: - $ref: '#/components/parameters/talendVersion' - $ref: '#/components/parameters/talend-version' responses: '200': description: Service accounts of the current tenant are retrieved successfully. content: application/json: schema: type: array description: service accounts for tenant are listed. items: $ref: '#/components/schemas/ServiceAccount' '401': description: Bearer token is invalid or missing. content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Permissions to read service accounts are missing. content: application/json: schema: $ref: '#/components/schemas/Error' '500': description: Status 500 content: application/json: schema: $ref: '#/components/schemas/Error' tags: - Account operationId: getAccountServiceAccounts x-operation-id-source: derived post: summary: Create a service account description: Create a service account in the Talend tenant of the currently authenticated user or entity. The returned service account object contains an OAuth client ID and a secret. This client ID and secret must be stored in a secure way without exposing them to unauthorized parties, because these credentials are required for this service account to get the authentication tokens to access Talend services. parameters: - $ref: '#/components/parameters/talendVersion' - $ref: '#/components/parameters/talend-version' requestBody: description: The new service account is displayed. content: application/json: schema: $ref: '#/components/schemas/ServiceAccount' responses: '201': description: Service account is successfully created. headers: Location: description: URL location where new resource can be found. required: true schema: type: string description: URL location where new resource can be found. content: application/json: schema: $ref: '#/components/schemas/ServiceAccount' '400': description: Invalid request body. The message vares depending on the cause of the bad request. The cause can be a malformed body or invalid permissions passed in the body. content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Invalid bearer token. content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Permissions to create a service account are missing or the Talend account license does not allow the service account creation. content: application/json: schema: $ref: '#/components/schemas/Error' '409': description: The service account name is already used content: application/json: schema: type: object properties: detail: type: string description: Error detail example: "{\n \"detail\": \"The service account name is already used\"\n}" '500': description: Status 500 content: application/json: schema: $ref: '#/components/schemas/Error' tags: - Account operationId: postAccountServiceAccounts x-operation-id-source: derived /account/service-accounts/permissions: get: summary: Get the available permissions description: Get the available permissions for Service Accounts feature responses: '200': description: List of available permissions retrieved successfully content: application/json: schema: type: array items: type: string example: "[\n \"AUDIT_LOGS_VIEW\",\n \"TMC_CLUSTER_MANAGEMENT\",\n \"TMC_ENVIRONMENT_MANAGEMENT\",\n \"TMC_PIPELINE_MANAGEMENT\",\n \"TMC_PROMOTION_EXECUTION\",\n \"TMC_ENGINE_USE\",\n \"TMC_RUN_PROFILE_MANAGEMENT\",\n \"TMC_OPERATOR\",\n \"TMC_GROUP_MANAGEMENT\",\n \"TMC_ROLE_MANAGEMENT\",\n \"TMC_USER_MANAGEMENT\",\n \"TMC_SERVICE_ACCOUNT_MANAGEMENT\"\n]" '401': description: Bearer token is invalid or missing. tags: - Account operationId: getAccountServiceAccountsPermissions x-operation-id-source: derived /account/service-accounts/count: get: summary: Get a number of service accounts description: 'Permissions: * TMC_SERVICE_ACCOUNT_MANAGEMENT * TMC_SUBSCRIPTION_MANAGEMENT' parameters: - $ref: '#/components/parameters/talendVersion' - $ref: '#/components/parameters/talend-version' responses: '200': description: Number of existing Service Accounts for tenant content: application/json: schema: $ref: '#/components/schemas/ServiceAccountCount' example: "{\n \"count\": 2,\n \"tenantId\": \"9133741e-d49d-4cd8-a09e-9791fead2583\"\n}" '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '500': $ref: '#/components/responses/InternalServerError' tags: - Account operationId: getAccountServiceAccountsCount x-operation-id-source: derived components: schemas: ServiceAccount: type: object required: - createdDate - id - lastModifiedDate - name - permissions description: A service account represents a non-human user entity which could be a service, a job, a third-party system or alike. This account uses access tokens to authenticate and must have been assigned appropriate permissions to access the Talend services to be used. properties: id: type: string description: OAuth 2 client ID that is internally generated readOnly: true example: 657d47e3-c3b4-4999-93c8-05a1670f6d92 secret: type: string description: OAuth 2 client secret (internally generated and available only upon creation) readOnly: true name: type: string description: Meaningful name example: mock service account permissions: type: array description: Assigned permissions items: type: string example: TMC_USER_MANAGEMENT createdDate: type: string format: date-time description: Creation date readOnly: true lastModifiedDate: type: string format: date-time description: Last modification date readOnly: true lastUsedDate: type: string format: date-time description: Last date & time when a token issued for the service account was used to call an API. lastUsedApi: type: string description: Last Talend API that was called with a service account access token issued for this service account. Error: type: object required: - detail - status description: Object returned in case the operation of a service account fails. properties: status: type: integer description: HTTP status code example: 400 detail: type: string description: Human readable error description. ServiceAccountCount: type: object required: - count - tenantId description: Number of existing Service Accounts for tenant properties: tenantId: type: string description: Talend Cloud ID of the tenant count: type: integer description: Number of existing Service Accounts for tenant responses: InternalServerError: description: Internal Server Error content: application/json: schema: $ref: '#/components/schemas/Error' Forbidden: description: Permissions required to perform operation are missing Unauthorized: description: Bearer token is invalid or missing. content: application/json: schema: $ref: '#/components/schemas/Error' parameters: talend-version: name: talend-version in: header required: false description: API version schema: type: string description: API version talendVersion: name: talendVersion in: query required: false description: API version schema: type: string description: API version securitySchemes: Public: type: http scheme: bearer bearerFormat: Bearer