update-service-account-token
dci update-service-account-token [body] [flags]
Moves the token between active and disabled by setting state. Disabling takes effect
immediately: the token stops authenticating until it is re-enabled. Setting the state a
token already has succeeds and changes nothing.
The two directions are not symmetric. Disabling a token whose expiry has passed succeeds,
but re-enabling an expired token returns 422 — expiry is final, and a new token has to be
created instead. deleted and expired are not accepted values: a token is deleted through
the delete operation, and expires on its own.
With dryRun=true nothing is written and the response body is the token as it would look
after the change, so a 422 here means a real request would also be refused. Requires the
serviceAccountManager permission.
Pass the request body as name: value arguments or pipe JSON on stdin — see Command structure.
Request
Content-Type: application/json
| Field | Type | Required | Description |
|---|---|---|---|
state | string | yes | active to enable the token, disabled to stop it authenticating. Any other value, deleted and expired included, returns 400. Re-enabling a token whose expiry has passed returns 422. One of: "active", "disabled". |
Example body (JSON)
{
"state": "disabled"
}
Raw JSON schema
{
"type": "object",
"description": "The state to move an API token to.",
"required": [
"state"
],
"properties": {
"state": {
"type": "string",
"enum": [
"active",
"disabled"
],
"description": "`active` to enable the token, `disabled` to stop it authenticating. Any other value, `deleted` and `expired` included, returns `400`. Re-enabling a token whose expiry has passed returns `422`.",
"example": "disabled"
}
}
}
Flags
| Flag | Type | Default | Example | Description |
|---|---|---|---|---|
--dry-run | boolean | false | If true, validates the request and returns the would-be result without applying it. The response then carries the X-Dry-Run header. |
Every command also accepts the CLI-wide flags for output shaping — see Output formats and Table output options.
Output
OK - API token state changed, or previewed when dryRun=true.
By default dci renders the result as a table. Use --output json to get the full structure described below — see Output formats.
| Field | Type | Description |
|---|---|---|
id | string | API token ID. null only on a dry-run create. |
serviceAccountId | string | ID of the service account that owns the token. |
customerId | string | ID of the customer whose service account the token belongs to. |
name | string | Name, unique among the service account's tokens. |
state | string | The token's stored state: active while it is enabled, disabled once it has been turned off. This is not a liveness signal — a token whose expiresTime has passed stops authenticating but keeps the state it was stored with, so active here does not by itself mean the token still works; compare expiresTime. Only these two values can be set. One of: "active", "disabled". |
createTime | string (date-time) | When the token was created. null only on a dry-run create. |
expiresTime | string (date-time) | When the token stops authenticating. null when it does not expire. |
lastUsedTime | string (date-time) | When the token last authenticated a request. null until it is first used. |
Example response (--output json)
{
"id": "Mr0sN7pQ4tU2vW5xY8zC",
"serviceAccountId": "Lq3nO9rM5wS2tU0xY4zA",
"customerId": "Kp2mN8qL4vR0sT1wX3yZ",
"name": "ci-pipeline-prod",
"state": "disabled",
"createTime": "2026-09-01T08:00:00Z",
"expiresTime": "2027-09-01T08:00:00Z",
"lastUsedTime": "2026-09-20T14:31:00Z"
}
Raw JSON schema
{
"type": "object",
"description": "An API token of a service account. It authenticates with the service account's permissions, and carries no secret material after the create response.",
"required": [
"id",
"serviceAccountId",
"customerId",
"name",
"state",
"createTime",
"expiresTime",
"lastUsedTime"
],
"properties": {
"id": {
"type": "string",
"nullable": true,
"readOnly": true,
"description": "API token ID. `null` only on a dry-run create.",
"example": "Mr0sN7pQ4tU2vW5xY8zC"
},
"serviceAccountId": {
"type": "string",
"readOnly": true,
"description": "ID of the service account that owns the token.",
"example": "Lq3nO9rM5wS2tU0xY4zA"
},
"customerId": {
"type": "string",
"readOnly": true,
"description": "ID of the customer whose service account the token belongs to.",
"example": "Kp2mN8qL4vR0sT1wX3yZ"
},
"name": {
"type": "string",
"description": "Name, unique among the service account's tokens.",
"example": "ci-pipeline-prod"
},
"state": {
"type": "string",
"enum": [
"active",
"disabled"
],
"description": "The token's stored state: `active` while it is enabled, `disabled` once it has been turned off. This is not a liveness signal — a token whose `expiresTime` has passed stops authenticating but keeps the state it was stored with, so `active` here does not by itself mean the token still works; compare `expiresTime`. Only these two values can be set.",
"example": "active"
},
"createTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"readOnly": true,
"description": "When the token was created. `null` only on a dry-run create.",
"example": "2026-09-01T08:00:00Z"
},
"expiresTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"description": "When the token stops authenticating. `null` when it does not expire.",
"example": "2027-09-01T08:00:00Z"
},
"lastUsedTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"readOnly": true,
"description": "When the token last authenticated a request. `null` until it is first used.",
"example": "2026-09-20T14:31:00Z"
}
}
}
Errors
On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.
HTTP status to exit code mapping
| HTTP status | Exit code | Error code | Meaning |
|---|---|---|---|
| 400, 422 | 30 | VALIDATION_ERROR | The arguments or request body were rejected. Review the command's flags and payload. |
| 401 | 10 | AUTHENTICATION_FAILED | Not signed in, or the API token is invalid. Run dci login or check DCI_API_KEY. |
| 403 | 11 | PERMISSION_DENIED | The DoiT user or the active customer context does not have access. |
| 404 | 20 | RESOURCE_NOT_FOUND | The requested resource does not exist. Check the identifier argument. |
| 500 | 40 | API_SERVER_ERROR | The API failed to process the request. Retryable; contact DoiT support if it persists. |
Related
- create-service-account — Create a service account
- create-service-account-token — Create an API token for a service account
- delete-service-account — Delete a service account
- delete-service-account-token — Delete an API token
- get-service-account — Get a service account
- get-service-account-token — Get an API token
- list-service-account-tokens — List API tokens for a service account
- list-service-accounts — List service accounts
- update-service-account — Update a service account
- API reference: PATCH /iam/v1/service-accounts/{serviceAccountId}/api-tokens/{id}
Aliases: updateserviceaccounttoken