Skip to main content
Generated from the same public contract that feeds the Monaco editor. Declaration-marked deprecated compatibility methods are intentionally excluded. Do not edit this page manually.
This page contains 16 methods. Search the docs for an exact method name, or use this index:

serviceAccount.get()

Reads a service account admitted by IAM and its management ACL. Example: const account = await serviceAccount.get({ name: ‘erp-sync’ });

Signature

serviceAccount.list()

Lists visible service accounts; authorization is applied before pagination. Example: const accounts = await serviceAccount.list({ take: 20, count: true });

Signature

serviceAccount.create()

Atomic account + ACL + memberships creation; default ACL contains creator and self.

Signature

Example

serviceAccount.update()

Omitted fields preserve values; [] clears memberships/ACL entries. Requires version.

Signature

Example

serviceAccount.delete()

Deletes the account and its credentials through the existing account lifecycle. Example: await serviceAccount.delete(‘erp-sync’);

Signature

serviceAccount.activate()

Activates the account within the caller’s current delegation ceiling. Example: await serviceAccount.activate(‘erp-sync’);

Signature

serviceAccount.disable()

Disables the account while preserving its API key records. Example: await serviceAccount.disable(‘erp-sync’);

Signature

serviceAccount.restore()

Restores a deleted account as inactive; deleted credentials are not restored. Example: await serviceAccount.restore(‘erp-sync’);

Signature

serviceAccount.enablePlatformAccess()

Enables platform access within the current delegation ceiling. Example: await serviceAccount.enablePlatformAccess(‘erp-sync’);

Signature

serviceAccount.disablePlatformAccess()

Disables platform access using the same IAM, ACL and target-rank policy. Example: await serviceAccount.disablePlatformAccess(‘erp-sync’);

Signature

serviceAccount.getKeys()

Lists safe key metadata without usable credentials. Example: const keys = await serviceAccount.getKeys(‘erp-sync’, { take: 20 });

Signature

serviceAccount.getKey()

Reads a key by its UUID; the credential value is never returned. Example: const key = await serviceAccount.getKey(‘erp-sync’, input.userKeyId);

Signature

serviceAccount.createKey()

Return secret once; store it immediately and never log it.

Signature

Example

serviceAccount.updateKey()

expireAt is immutable here; use rotateKey to change the successor expiry.

Signature

Example

serviceAccount.rotateKey()

Creates a new credential; gracePeriodMs defaults to 0, max 365 days. Omit expireAt to inherit it, pass null for no expiration, or a date at least four hours ahead.

Signature

Example

serviceAccount.revokeKey()

Revokes a key without requiring a delegation ceiling; role, ACL and target rank still apply. Example: await serviceAccount.revokeKey(‘erp-sync’, input.userKeyId);

Signature

Last modified on October 5, 2026