get-service-account-token
dci get-service-account-token
Returns one API token of the service account; an ID that belongs to another customer returns 404. accessToken is not included — it is shown only once, by the create operation. Requires the serviceAccountViewer permission.
Output
OK - API token returned.
By default dci renders the result as a table. Use --output json to get the full structure described below — see Output formats.
| Field | Type | Description |
|---|---|---|
id | string | API token ID. null only on a dry-run create. |
serviceAccountId | string | ID of the service account that owns the token. |
customerId | string | ID of the customer whose service account the token belongs to. |
name | string | Name, unique among the service account's tokens. |
state | string | The token's stored state: active while it is enabled, disabled once it has been turned off. This is not a liveness signal — a token whose expiresTime has passed stops authenticating but keeps the state it was stored with, so active here does not by itself mean the token still works; compare expiresTime. Only these two values can be set. One of: "active", "disabled". |
createTime | string (date-time) | When the token was created. null only on a dry-run create. |
expiresTime | string (date-time) | When the token stops authenticating. null when it does not expire. |
lastUsedTime | string (date-time) | When the token last authenticated a request. null until it is first used. |
Example response (--output json)
{
"id": "Mr0sN7pQ4tU2vW5xY8zC",
"serviceAccountId": "Lq3nO9rM5wS2tU0xY4zA",
"customerId": "Kp2mN8qL4vR0sT1wX3yZ",
"name": "ci-pipeline-prod",
"state": "active",
"createTime": "2026-09-01T08:00:00Z",
"expiresTime": "2027-09-01T08:00:00Z",
"lastUsedTime": "2026-09-20T14:31:00Z"
}
Raw JSON schema
{
"type": "object",
"description": "An API token of a service account. It authenticates with the service account's permissions, and carries no secret material after the create response.",
"required": [
"id",
"serviceAccountId",
"customerId",
"name",
"state",
"createTime",
"expiresTime",
"lastUsedTime"
],
"properties": {
"id": {
"type": "string",
"nullable": true,
"readOnly": true,
"description": "API token ID. `null` only on a dry-run create.",
"example": "Mr0sN7pQ4tU2vW5xY8zC"
},
"serviceAccountId": {
"type": "string",
"readOnly": true,
"description": "ID of the service account that owns the token.",
"example": "Lq3nO9rM5wS2tU0xY4zA"
},
"customerId": {
"type": "string",
"readOnly": true,
"description": "ID of the customer whose service account the token belongs to.",
"example": "Kp2mN8qL4vR0sT1wX3yZ"
},
"name": {
"type": "string",
"description": "Name, unique among the service account's tokens.",
"example": "ci-pipeline-prod"
},
"state": {
"type": "string",
"enum": [
"active",
"disabled"
],
"description": "The token's stored state: `active` while it is enabled, `disabled` once it has been turned off. This is not a liveness signal — a token whose `expiresTime` has passed stops authenticating but keeps the state it was stored with, so `active` here does not by itself mean the token still works; compare `expiresTime`. Only these two values can be set.",
"example": "active"
},
"createTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"readOnly": true,
"description": "When the token was created. `null` only on a dry-run create.",
"example": "2026-09-01T08:00:00Z"
},
"expiresTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"description": "When the token stops authenticating. `null` when it does not expire.",
"example": "2027-09-01T08:00:00Z"
},
"lastUsedTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"readOnly": true,
"description": "When the token last authenticated a request. `null` until it is first used.",
"example": "2026-09-20T14:31:00Z"
}
}
}
Errors
On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.
HTTP status to exit code mapping
| HTTP status | Exit code | Error code | Meaning |
|---|---|---|---|
| 401 | 10 | AUTHENTICATION_FAILED | Not signed in, or the API token is invalid. Run dci login or check DCI_API_KEY. |
| 403 | 11 | PERMISSION_DENIED | The DoiT user or the active customer context does not have access. |
| 404 | 20 | RESOURCE_NOT_FOUND | The requested resource does not exist. Check the identifier argument. |
| 500 | 40 | API_SERVER_ERROR | The API failed to process the request. Retryable; contact DoiT support if it persists. |
Related
- create-service-account — Create a service account
- create-service-account-token — Create an API token for a service account
- delete-service-account — Delete a service account
- delete-service-account-token — Delete an API token
- get-service-account — Get a service account
- list-service-account-tokens — List API tokens for a service account
- list-service-accounts — List service accounts
- update-service-account — Update a service account
- update-service-account-token — Enable or disable an API token
- API reference: GET /iam/v1/service-accounts/{serviceAccountId}/api-tokens/{id}
Aliases: getserviceaccounttoken