Skip to main content

update-service-account-token

dci update-service-account-token [body] [flags]

Moves the token between active and disabled by setting state. Disabling takes effect immediately: the token stops authenticating until it is re-enabled. Setting the state a token already has succeeds and changes nothing.

The two directions are not symmetric. Disabling a token whose expiry has passed succeeds, but re-enabling an expired token returns 422 — expiry is final, and a new token has to be created instead. deleted and expired are not accepted values: a token is deleted through the delete operation, and expires on its own.

With dryRun=true nothing is written and the response body is the token as it would look after the change, so a 422 here means a real request would also be refused. Requires the serviceAccountManager permission.

Pass the request body as name: value arguments or pipe JSON on stdin — see Command structure.

Request​

Content-Type: application/json

FieldTypeRequiredDescription
statestringyesactive to enable the token, disabled to stop it authenticating. Any other value, deleted and expired included, returns 400. Re-enabling a token whose expiry has passed returns 422. One of: "active", "disabled".

Example body (JSON)​

{
"state": "disabled"
}
Raw JSON schema
{
"type": "object",
"description": "The state to move an API token to.",
"required": [
"state"
],
"properties": {
"state": {
"type": "string",
"enum": [
"active",
"disabled"
],
"description": "`active` to enable the token, `disabled` to stop it authenticating. Any other value, `deleted` and `expired` included, returns `400`. Re-enabling a token whose expiry has passed returns `422`.",
"example": "disabled"
}
}
}

Flags​

FlagTypeDefaultExampleDescription
--dry-runbooleanfalseIf true, validates the request and returns the would-be result without applying it. The response then carries the X-Dry-Run header.

Every command also accepts the CLI-wide flags for output shaping — see Output formats and Table output options.

Output​

OK - API token state changed, or previewed when dryRun=true.

By default dci renders the result as a table. Use --output json to get the full structure described below — see Output formats.

FieldTypeDescription
idstringAPI token ID. null only on a dry-run create.
serviceAccountIdstringID of the service account that owns the token.
customerIdstringID of the customer whose service account the token belongs to.
namestringName, unique among the service account's tokens.
statestringThe token's stored state: active while it is enabled, disabled once it has been turned off. This is not a liveness signal — a token whose expiresTime has passed stops authenticating but keeps the state it was stored with, so active here does not by itself mean the token still works; compare expiresTime. Only these two values can be set. One of: "active", "disabled".
createTimestring (date-time)When the token was created. null only on a dry-run create.
expiresTimestring (date-time)When the token stops authenticating. null when it does not expire.
lastUsedTimestring (date-time)When the token last authenticated a request. null until it is first used.

Example response (--output json)​

{
"id": "Mr0sN7pQ4tU2vW5xY8zC",
"serviceAccountId": "Lq3nO9rM5wS2tU0xY4zA",
"customerId": "Kp2mN8qL4vR0sT1wX3yZ",
"name": "ci-pipeline-prod",
"state": "disabled",
"createTime": "2026-09-01T08:00:00Z",
"expiresTime": "2027-09-01T08:00:00Z",
"lastUsedTime": "2026-09-20T14:31:00Z"
}
Raw JSON schema
{
"type": "object",
"description": "An API token of a service account. It authenticates with the service account's permissions, and carries no secret material after the create response.",
"required": [
"id",
"serviceAccountId",
"customerId",
"name",
"state",
"createTime",
"expiresTime",
"lastUsedTime"
],
"properties": {
"id": {
"type": "string",
"nullable": true,
"readOnly": true,
"description": "API token ID. `null` only on a dry-run create.",
"example": "Mr0sN7pQ4tU2vW5xY8zC"
},
"serviceAccountId": {
"type": "string",
"readOnly": true,
"description": "ID of the service account that owns the token.",
"example": "Lq3nO9rM5wS2tU0xY4zA"
},
"customerId": {
"type": "string",
"readOnly": true,
"description": "ID of the customer whose service account the token belongs to.",
"example": "Kp2mN8qL4vR0sT1wX3yZ"
},
"name": {
"type": "string",
"description": "Name, unique among the service account's tokens.",
"example": "ci-pipeline-prod"
},
"state": {
"type": "string",
"enum": [
"active",
"disabled"
],
"description": "The token's stored state: `active` while it is enabled, `disabled` once it has been turned off. This is not a liveness signal — a token whose `expiresTime` has passed stops authenticating but keeps the state it was stored with, so `active` here does not by itself mean the token still works; compare `expiresTime`. Only these two values can be set.",
"example": "active"
},
"createTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"readOnly": true,
"description": "When the token was created. `null` only on a dry-run create.",
"example": "2026-09-01T08:00:00Z"
},
"expiresTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"description": "When the token stops authenticating. `null` when it does not expire.",
"example": "2027-09-01T08:00:00Z"
},
"lastUsedTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"readOnly": true,
"description": "When the token last authenticated a request. `null` until it is first used.",
"example": "2026-09-20T14:31:00Z"
}
}
}

Errors​

On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.

HTTP status to exit code mapping
HTTP statusExit codeError codeMeaning
400, 42230VALIDATION_ERRORThe arguments or request body were rejected. Review the command's flags and payload.
40110AUTHENTICATION_FAILEDNot signed in, or the API token is invalid. Run dci login or check DCI_API_KEY.
40311PERMISSION_DENIEDThe DoiT user or the active customer context does not have access.
40420RESOURCE_NOT_FOUNDThe requested resource does not exist. Check the identifier argument.
50040API_SERVER_ERRORThe API failed to process the request. Retryable; contact DoiT support if it persists.

Aliases: updateserviceaccounttoken