メインコンテンツへスキップ

list-service-account-tokens

dci list-service-account-tokens

Returns the service account's non-deleted API tokens in a single unpaginated items array, at most 10. Secret material is never returned here — accessToken is shown only once, by the create operation. Requires the serviceAccountViewer permission.

Output​

OK - API tokens returned.

By default dci renders the result as a table. Use --output json to get the full structure described below — see Output formats.

FieldTypeDescription
itemsarray of objectThe service account's non-deleted API tokens.
items[].idstringAPI token ID. null only on a dry-run create.
items[].serviceAccountIdstringID of the service account that owns the token.
items[].customerIdstringID of the customer whose service account the token belongs to.
items[].namestringName, unique among the service account's tokens.
items[].statestringThe token's stored state: active while it is enabled, disabled once it has been turned off. This is not a liveness signal — a token whose expiresTime has passed stops authenticating but keeps the state it was stored with, so active here does not by itself mean the token still works; compare expiresTime. Only these two values can be set. One of: "active", "disabled".
items[].createTimestring (date-time)When the token was created. null only on a dry-run create.
items[].expiresTimestring (date-time)When the token stops authenticating. null when it does not expire.
items[].lastUsedTimestring (date-time)When the token last authenticated a request. null until it is first used.

Example response (--output json)​

{
"items": [
{
"id": "Mr0sN7pQ4tU2vW5xY8zC",
"serviceAccountId": "Lq3nO9rM5wS2tU0xY4zA",
"customerId": "Kp2mN8qL4vR0sT1wX3yZ",
"name": "ci-pipeline-prod",
"state": "active",
"createTime": "2026-09-01T08:00:00Z",
"expiresTime": "2027-09-01T08:00:00Z",
"lastUsedTime": "2026-09-20T14:31:00Z"
}
]
}
Raw JSON schema
{
"type": "object",
"description": "API tokens of a service account, at most 10.",
"required": [
"items"
],
"properties": {
"items": {
"type": "array",
"maxItems": 10,
"description": "The service account's non-deleted API tokens.",
"items": {
"type": "object",
"description": "An API token of a service account. It authenticates with the service account's permissions, and carries no secret material after the create response.",
"required": [
"id",
"serviceAccountId",
"customerId",
"name",
"state",
"createTime",
"expiresTime",
"lastUsedTime"
],
"properties": {
"id": {
"type": "string",
"nullable": true,
"readOnly": true,
"description": "API token ID. `null` only on a dry-run create.",
"example": "Mr0sN7pQ4tU2vW5xY8zC"
},
"serviceAccountId": {
"type": "string",
"readOnly": true,
"description": "ID of the service account that owns the token.",
"example": "Lq3nO9rM5wS2tU0xY4zA"
},
"customerId": {
"type": "string",
"readOnly": true,
"description": "ID of the customer whose service account the token belongs to.",
"example": "Kp2mN8qL4vR0sT1wX3yZ"
},
"name": {
"type": "string",
"description": "Name, unique among the service account's tokens.",
"example": "ci-pipeline-prod"
},
"state": {
"type": "string",
"enum": [
"active",
"disabled"
],
"description": "The token's stored state: `active` while it is enabled, `disabled` once it has been turned off. This is not a liveness signal — a token whose `expiresTime` has passed stops authenticating but keeps the state it was stored with, so `active` here does not by itself mean the token still works; compare `expiresTime`. Only these two values can be set.",
"example": "active"
},
"createTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"readOnly": true,
"description": "When the token was created. `null` only on a dry-run create.",
"example": "2026-09-01T08:00:00Z"
},
"expiresTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"description": "When the token stops authenticating. `null` when it does not expire.",
"example": "2027-09-01T08:00:00Z"
},
"lastUsedTime": {
"type": "string",
"format": "date-time",
"nullable": true,
"readOnly": true,
"description": "When the token last authenticated a request. `null` until it is first used.",
"example": "2026-09-20T14:31:00Z"
}
}
},
"example": [
{
"id": "Mr0sN7pQ4tU2vW5xY8zC",
"serviceAccountId": "Lq3nO9rM5wS2tU0xY4zA",
"customerId": "Kp2mN8qL4vR0sT1wX3yZ",
"name": "ci-pipeline-prod",
"state": "active",
"createTime": "2026-09-01T08:00:00Z",
"expiresTime": "2027-09-01T08:00:00Z",
"lastUsedTime": "2026-09-20T14:31:00Z"
}
]
}
}
}

Errors​

On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.

HTTP status to exit code mapping
HTTP statusExit codeError codeMeaning
40110AUTHENTICATION_FAILEDNot signed in, or the API token is invalid. Run dci login or check DCI_API_KEY.
40311PERMISSION_DENIEDThe DoiT user or the active customer context does not have access.
40420RESOURCE_NOT_FOUNDThe requested resource does not exist. Check the identifier argument.
50040API_SERVER_ERRORThe API failed to process the request. Retryable; contact DoiT support if it persists.

Aliases: listserviceaccounttokens