Skip to main content

get-service-account-token

dci get-service-account-token

Returns one API token of the service account; an ID that belongs to another customer returns 404. accessToken is not included — it is shown only once, by the create operation. Requires the serviceAccountViewer permission.

Output​

OK - API token returned.

By default dci renders the result as a table. Use --output json to get the full structure described below — see Output formats.

FieldTypeDescription
idstringAPI token ID. null only on a dry-run create.
serviceAccountIdstringID of the service account that owns the token.
customerIdstringID of the customer whose service account the token belongs to.
namestringName, unique among the service account's tokens.
statestringThe token's stored state: active while it is enabled, disabled once it has been turned off. This is not a liveness signal — a token whose expiresTime has passed stops authenticating but keeps the state it was stored with, so active here does not by itself mean the token still works; compare expiresTime. Only these two values can be set. One of: "active", "disabled".
createTimestring (date-time)When the token was created. null only on a dry-run create.
expiresTimestring (date-time)When the token stops authenticating. null when it does not expire.
lastUsedTimestring (date-time)When the token last authenticated a request. null until it is first used.

Example response (--output json)​

{
"id": "Mr0sN7pQ4tU2vW5xY8zC",
"serviceAccountId": "Lq3nO9rM5wS2tU0xY4zA",
"customerId": "Kp2mN8qL4vR0sT1wX3yZ",
"name": "ci-pipeline-prod",
"state": "active",
"createTime": "2026-09-01T08:00:00Z",
"expiresTime": "2027-09-01T08:00:00Z",
"lastUsedTime": "2026-09-20T14:31:00Z"
}
Raw JSON schema
{
"type": "object",
"description": "An API token of a service account. It authenticates with the service account's permissions, and carries no secret material after the create response.",
"required": [
"id",
"serviceAccountId",
"customerId",
"name",
"state",
"createTime",
"expiresTime",
"lastUsedTime"
],
"properties": {
"id": {
"type": "string",
"nullable": true,
"readOnly": true,
"description": "API token ID. `null` only on a dry-run create.",
"example": "Mr0sN7pQ4tU2vW5xY8zC"
},
"serviceAccountId": {
"type": "string",
"readOnly": true,
"description": "ID of the service account that owns the token.",
"example": "Lq3nO9rM5wS2tU0xY4zA"
},
"customerId": {
"type": "string",
"readOnly": true,
"description": "ID of the customer whose service account the token belongs to.",
"example": "Kp2mN8qL4vR0sT1wX3yZ"
},
"name": {
"type": "string",
"description": "Name, unique among the service account's tokens.",
"example": "ci-pipeline-prod"
},
"state": {
"type": "string",
"enum": [
"active",
"disabled"
],
"description": "The token's stored state: `active` while it is enabled, `disabled` once it has been turned off. This is not a liveness signal — a token whose `expiresTime` has passed stops authenticating but keeps the state it was stored with, so `active` here does not by itself mean the token still works; compare `expiresTime`. Only these two values can be set.",
"example": "active"
},
"createTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"readOnly": true,
"description": "When the token was created. `null` only on a dry-run create.",
"example": "2026-09-01T08:00:00Z"
},
"expiresTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"description": "When the token stops authenticating. `null` when it does not expire.",
"example": "2027-09-01T08:00:00Z"
},
"lastUsedTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"readOnly": true,
"description": "When the token last authenticated a request. `null` until it is first used.",
"example": "2026-09-20T14:31:00Z"
}
}
}

Errors​

On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.

HTTP status to exit code mapping
HTTP statusExit codeError codeMeaning
40110AUTHENTICATION_FAILEDNot signed in, or the API token is invalid. Run dci login or check DCI_API_KEY.
40311PERMISSION_DENIEDThe DoiT user or the active customer context does not have access.
40420RESOURCE_NOT_FOUNDThe requested resource does not exist. Check the identifier argument.
50040API_SERVER_ERRORThe API failed to process the request. Retryable; contact DoiT support if it persists.

Aliases: getserviceaccounttoken