List Service Accounts
const url = 'https://example.com/iam/v1/service-accounts';const options = {method: 'GET'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/iam/v1/service-accountsReturns a paginated directory of service accounts.
Parameters
Section titled “ Parameters ”Query Parameters
Section titled “Query Parameters ”The maximum number of service accounts to return. The service may return fewer than this value. If unspecified, at most 20 service accounts will be returned. The maximum value is 100; values above 100 will be coerced to 100.
A page token from a previous ListServiceAccounts call.
AIP-160 filter expression. Filterable fields: bounded_context, create_time, id, service_email, status, update_time.
AIP-132 order_by expression. Sortable fields: bounded_context, create_time, service_email, status, update_time.
AIP-158 offset mode: number of resources to skip from the start of the filtered, sorted set. Use EITHER skip (offset paging) OR page_token (cursor paging) — never both in the same request. Supplying both is an invalid request. Default 0 (no skip).
Responses
Section titled “ Responses ”OK
ListServiceAccountsResponse
Response message for ListServiceAccounts.
object
The list of service accounts.
ServiceAccount: the machine identity a bounded context authenticates as for service-to-service calls. A CTI child of Principal, sharing the principal id.
Distinct from the Principal projection, which carries only the columns every principal kind has: a service account is addressed by its service_email and grouped by the bounded_context it represents, and neither exists on Principal.
Entirely OUTPUT_ONLY. Service accounts are provisioned by migration seed, one per bounded context, and are never created or edited through the API.
object
The unique identifier of the service account, shared with its Principal root.
The unique address of this machine identity, e.g. compute@iam.serviceaccount.cloud.qibdo.com.
The bounded context this service account acts on behalf of, e.g. “compute”.
Whether the identity may currently authenticate.
When the service account was provisioned.
When the service account was last modified.
A token to retrieve the next page; empty when there are no further pages.
Exact count of resources matching the request’s filter and scope (both pagination modes).
Example
{ "service_accounts": [ { "status": "PRINCIPAL_STATUS_UNSPECIFIED" } ]}default
Section titled “default ”Default error response
The Status type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by gRPC. Each Status message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the API Design Guide.
object
The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].
A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.
A list of messages that carry the error details. There is a common set of message types for APIs to use.
Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.
object
The type of the serialized message.
Example generated
{ "code": 1, "message": "example", "details": [ { "@type": "example" } ]}