> ## Documentation Index
> Fetch the complete documentation index at: https://docs.revoengine.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Service Account reference

> Service Account lifecycle, management ACLs, execution memberships, and immutable API-key rotation.

<Note>
  Generated from the same public contract that feeds the Monaco editor. Declaration-marked deprecated compatibility methods are intentionally excluded. Do not edit this page manually.
</Note>

This page contains **16 methods**. Search the docs for an exact method name, or use this index:

* [`serviceAccount.get()`](#serviceAccount-get)
* [`serviceAccount.list()`](#serviceAccount-list)
* [`serviceAccount.create()`](#serviceAccount-create)
* [`serviceAccount.update()`](#serviceAccount-update)
* [`serviceAccount.delete()`](#serviceAccount-delete)
* [`serviceAccount.activate()`](#serviceAccount-activate)
* [`serviceAccount.disable()`](#serviceAccount-disable)
* [`serviceAccount.restore()`](#serviceAccount-restore)
* [`serviceAccount.enablePlatformAccess()`](#serviceAccount-enablePlatformAccess)
* [`serviceAccount.disablePlatformAccess()`](#serviceAccount-disablePlatformAccess)
* [`serviceAccount.getKeys()`](#serviceAccount-getKeys)
* [`serviceAccount.getKey()`](#serviceAccount-getKey)
* [`serviceAccount.createKey()`](#serviceAccount-createKey)
* [`serviceAccount.updateKey()`](#serviceAccount-updateKey)
* [`serviceAccount.rotateKey()`](#serviceAccount-rotateKey)
* [`serviceAccount.revokeKey()`](#serviceAccount-revokeKey)

<span id="serviceAccount-get" aria-hidden="true" />

## `serviceAccount.get()`

Reads a service account admitted by IAM and its management ACL.
Example: const account = await serviceAccount.get(\{ name: 'erp-sync' });

### Signature

```ts theme={null}
static get(ref: ServiceAccountRef): Promise<ServiceAccountRecord>;
```

<span id="serviceAccount-list" aria-hidden="true" />

## `serviceAccount.list()`

Lists visible service accounts; authorization is applied before pagination.
Example: const accounts = await serviceAccount.list(\{ take: 20, count: true });

### Signature

```ts theme={null}
static list(query?: ServiceAccountQuery): Promise<CollectionResult<ServiceAccountRecord>>;
```

<span id="serviceAccount-create" aria-hidden="true" />

## `serviceAccount.create()`

Atomic account + ACL + memberships creation; default ACL contains creator and self.

### Signature

```ts theme={null}
static create(input: ServiceAccountCreateInput): Promise<ServiceAccountRecord>;
```

### Example

```ts theme={null}
const account = await serviceAccount.create({ name: 'erp-sync', memberships: { roleGroups: ['Integration runtime'] } });
```

<span id="serviceAccount-update" aria-hidden="true" />

## `serviceAccount.update()`

Omitted fields preserve values; \[] clears memberships/ACL entries. Requires version.

### Signature

```ts theme={null}
static update(ref: ServiceAccountRef, input: ServiceAccountUpdateInput): Promise<ServiceAccountRecord>;
```

### Example

```ts theme={null}
const account = await serviceAccount.get('erp-sync');
await serviceAccount.update('erp-sync', { version: account.version, memberships: { roleGroups: [] } });
```

<span id="serviceAccount-delete" aria-hidden="true" />

## `serviceAccount.delete()`

Deletes the account and its credentials through the existing account lifecycle.
Example: await serviceAccount.delete('erp-sync');

### Signature

```ts theme={null}
static delete(ref: ServiceAccountRef): Promise<ServiceAccountRecord>;
```

<span id="serviceAccount-activate" aria-hidden="true" />

## `serviceAccount.activate()`

Activates the account within the caller's current delegation ceiling.
Example: await serviceAccount.activate('erp-sync');

### Signature

```ts theme={null}
static activate(ref: ServiceAccountRef): Promise<ServiceAccountRecord>;
```

<span id="serviceAccount-disable" aria-hidden="true" />

## `serviceAccount.disable()`

Disables the account while preserving its API key records.
Example: await serviceAccount.disable('erp-sync');

### Signature

```ts theme={null}
static disable(ref: ServiceAccountRef): Promise<ServiceAccountRecord>;
```

<span id="serviceAccount-restore" aria-hidden="true" />

## `serviceAccount.restore()`

Restores a deleted account as inactive; deleted credentials are not restored.
Example: await serviceAccount.restore('erp-sync');

### Signature

```ts theme={null}
static restore(ref: ServiceAccountRef): Promise<ServiceAccountRecord>;
```

<span id="serviceAccount-enablePlatformAccess" aria-hidden="true" />

## `serviceAccount.enablePlatformAccess()`

Enables platform access within the current delegation ceiling.
Example: await serviceAccount.enablePlatformAccess('erp-sync');

### Signature

```ts theme={null}
static enablePlatformAccess(ref: ServiceAccountRef): Promise<ServiceAccountRecord>;
```

<span id="serviceAccount-disablePlatformAccess" aria-hidden="true" />

## `serviceAccount.disablePlatformAccess()`

Disables platform access using the same IAM, ACL and target-rank policy.
Example: await serviceAccount.disablePlatformAccess('erp-sync');

### Signature

```ts theme={null}
static disablePlatformAccess(ref: ServiceAccountRef): Promise<ServiceAccountRecord>;
```

<span id="serviceAccount-getKeys" aria-hidden="true" />

## `serviceAccount.getKeys()`

Lists safe key metadata without usable credentials.
Example: const keys = await serviceAccount.getKeys('erp-sync', \{ take: 20 });

### Signature

```ts theme={null}
static getKeys(ref: ServiceAccountRef, query?: ServiceAccountQuery): Promise<CollectionResult<ServiceAccountKey>>;
```

<span id="serviceAccount-getKey" aria-hidden="true" />

## `serviceAccount.getKey()`

Reads a key by its UUID; the credential value is never returned.
Example: const key = await serviceAccount.getKey('erp-sync', input.userKeyId);

### Signature

```ts theme={null}
static getKey(ref: ServiceAccountRef, userKeyId: string): Promise<ServiceAccountKey>;
```

<span id="serviceAccount-createKey" aria-hidden="true" />

## `serviceAccount.createKey()`

Return secret once; store it immediately and never log it.

### Signature

```ts theme={null}
static createKey(ref: ServiceAccountRef, input: ServiceAccountKeyCreateInput): Promise<ServiceAccountKeyCreated>;
```

### Example

```ts theme={null}
const key = await serviceAccount.createKey('erp-sync', { name: 'primary', restricted: false });
await vault.create('ERP_API_KEY', { value: key.secret });
```

<span id="serviceAccount-updateKey" aria-hidden="true" />

## `serviceAccount.updateKey()`

expireAt is immutable here; use rotateKey to change the successor expiry.

### Signature

```ts theme={null}
static updateKey(ref: ServiceAccountRef, userKeyId: string, input: ServiceAccountKeyUpdateInput): Promise<ServiceAccountKey>;
```

### Example

```ts theme={null}
const key = await serviceAccount.getKey('erp-sync', input.userKeyId);
await serviceAccount.updateKey('erp-sync', key.userKeyId, { version: key.version, name: 'primary' });
```

<span id="serviceAccount-rotateKey" aria-hidden="true" />

## `serviceAccount.rotateKey()`

Creates a new credential; gracePeriodMs defaults to 0, max 365 days.
Omit expireAt to inherit it, pass null for no expiration, or a date at least four hours ahead.

### Signature

```ts theme={null}
static rotateKey(ref: ServiceAccountRef, userKeyId: string, input: ServiceAccountKeyRotateInput): Promise<ServiceAccountKeyRotated>;
```

### Example

```ts theme={null}
const key = await serviceAccount.getKey('erp-sync', input.userKeyId);
const { newKey } = await serviceAccount.rotateKey('erp-sync', key.userKeyId, { version: key.version, gracePeriodMs: 60000 });
await vault.rotate('ERP_API_KEY', { value: newKey.secret });
```

<span id="serviceAccount-revokeKey" aria-hidden="true" />

## `serviceAccount.revokeKey()`

Revokes a key without requiring a delegation ceiling; role, ACL and target rank still apply.
Example: await serviceAccount.revokeKey('erp-sync', input.userKeyId);

### Signature

```ts theme={null}
static revokeKey(ref: ServiceAccountRef, userKeyId: string): Promise<ServiceAccountKey>;
```


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.