Bridgit ServiceAccounts API

The ServiceAccounts API from Bridgit — 3 operation(s) for serviceaccounts.

OpenAPI Specification

bridgit-serviceaccounts-api-openapi.yml Raw ↑
openapi: 3.0.4
info:
  title: Bench AccountActivities ServiceAccounts API
  description: "<h2>Versioning</h2>\n<p>\n    The API is currently at version <code>1.0</code>. All API endpoints (other than\n    authentication) require you to specify the API version as part of the path.\n</p>\n\n<h2>URL Paths</h2>\n<p>\n    Authentication requests should be made to <code>/auth/signin</code>,\n    as documented below. All other API requests should be made to\n    sub-paths of <code>/rp/api/1.0/...</code>.\n</p>\n\n<h2>Authentication</h2>\n<p>\n    API requests are authenticated using an OAuth Bearer token.\n    You can get a token by authenticating your user by sending a\n    POST request to <code>/auth/signin</code>, with \"username and \"password\"\n    parameters form-encoded in the body of the request.\n\n    POST /auth/signin HTTP/1.1\n    Content-Type: application/x-www-form-urlencoded\n\n    username=user@example.com&password=some-secret-password\n</p>\n<p>\n    The response will be a JSON object including both\n    <b>\"access_token\"</b> and <b>\"refresh_token\"</b> property.\n    All other requests against the Bench API should include an\n    authorization header: <code>Authorization: Bearer xxxYYYzzz</code>,\n    where <b>xxxYYYzzz</b> is the value of <b>\"access_token\"</b> in the response.\n    <br><br>\n    For example:\n\n    $ curl https://bench.gobridgit.com/auth/signin -H 'Content-Type: application/x-www-form-urlencoded' --data-urlencode 'username=someone@example.com' --data-urlencode 'password=[...snip...]'\n    {\n        \"access_token\": \"...snip...\",\n        \"token_type\": \"Bearer\",\n        \"refresh_token\": \"...snip...\"\n        \"expiry\": \"2020-01-01T00:00:00.413440849Z\"\n    }\n\n</p>\n\n<p>\n    The refresh token can be used to generate new session by request with <code>/auth/token</code> endpoint:\n\n    POST /auth/token HTTP/1.1\n    Content-Type: application/x-www-form-urlencoded\n\n    grant_type=refresh_token&refresh_token=tGzv3JOkF0XG5Qx2TlKWIA\n</p>\n<p>\n    Note that once the refresh token is used, the previous access and refresh token is no longer valid.\n    <br><br>\n    For example:\n\n    $ curl https://bench.gobridgit.com/auth/token -H 'Content-Type: application/x-www-form-urlencoded' --data-urlencode 'grant_type=refresh_token' --data-urlencode 'refresh_token=[...snip...]'\n    {\n        \"access_token\": \"...snip...\",\n        \"token_type\": \"Bearer\",\n        \"refresh_token\": \"...snip...\"\n        \"expiry\": \"2020-01-01T00:00:00.413440849Z\"\n    }\n</p>\n\n<h2>Pagination</h2>\n<p>\n    Several of the API endpoints are paginated. These are denoted by\n    including the <code>offset</code> (zero-based offset) and <code>limit</code> query\n    parameters. For example, to request the <code>10</code> items,\n    set the <code>offset=0</code> to <code>limit=10</code>.\n    <br>\n    NOTE: the result set contains items with index of 0-9\n    <br>\n    To request the next 10 items (starting at index 10),\n    set the <code>offset=10</code> to <code>limit=10</code>\n</p>\n<p>\n    Responses to paginated API endpoints return a JSON array of objects.\n    If there are results beyond the page you have requested, the server\n    will set a <code>query-has-more: true</code> header in the response.\n</p>\n\n<h2>Request Encoding</h2>\n<p>\n    <code>GET</code> and <code>DELETE</code> requests should have parameters encoded as URL query\n    parameters. Boolean values should be encoded as <code>true</code> and\n    <code>false</code>, not as <code>1</code> and <code>0</code>.\n</p>\n\n<h2>Errors</h2>\n<p>\n    Errors are returned for some response codes such as <code>400 Bad Request</code> in the\n    following format:\n\n    {\n      \"errors\": [\n        {\n          \"errorType\": \"ValidationError\",\n          \"description\": \"The value of Name must be a string with a minimum length of 1 and a maximum length of 8 and not whitespace.\",\n          \"field\": \"Name\",\n          \"values\": [\n            null\n          ]\n        }\n      ],\n      \"title\": \"One or more validation errors occurred.\",\n      \"status\": 400,\n      \"instance\": \"api/v1/accounts/0/persons\",\n      \"requestUid\": \"123e4567-e89b-12d3-a456-426614174000\"\n    }\n</p>\n"
  version: '1.0'
servers:
- url: https://bench.gobridgit.com
  description: Bridgit Bench production
security:
- {}
tags:
- name: ServiceAccounts
paths:
  /rp/api/v1/accounts/{accountId}/service-accounts:
    get:
      tags:
      - ServiceAccounts
      summary: Gets service accounts in the given account
      description: '<br/><strong>Permissions</strong><br/>Account: Read'
      operationId: ServiceAccounts_GetServiceAccounts
      parameters:
      - name: accountId
        in: path
        description: The Account ID
        required: true
        schema:
          type: integer
          format: int32
      - name: ids
        in: query
        description: (Optional) Filters the result to contain accounts that match the ids passed in.
        schema:
          type: array
          items:
            type: integer
            format: int32
      responses:
        '200':
          description: 'Success: Service Account model'
          content:
            text/plain:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/ServiceAccountResponse'
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/ServiceAccountResponse'
            text/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/ServiceAccountResponse'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
    post:
      tags:
      - ServiceAccounts
      summary: Creates a service account in the given account
      description: 'This endpoint will generate a unique login and password in the response.


        There is no way to retrieve the password again after the account is created.


        This is a limit of 10 service accounts on a single account.<br/><strong>Permissions</strong><br/>Account: Write'
      operationId: ServiceAccounts_CreateServiceAccount
      parameters:
      - name: accountId
        in: path
        description: The Account ID
        required: true
        schema:
          type: integer
          format: int32
      requestBody:
        description: Object containing the name and group the service account will be created with
        content:
          application/json-patch+json:
            schema:
              $ref: '#/components/schemas/ServiceAccountRequest'
          application/json:
            schema:
              $ref: '#/components/schemas/ServiceAccountRequest'
          text/json:
            schema:
              $ref: '#/components/schemas/ServiceAccountRequest'
          application/*+json:
            schema:
              $ref: '#/components/schemas/ServiceAccountRequest'
        required: true
      responses:
        '201':
          description: 'Success: Service Account model with password'
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ServiceAccountDetailResponse'
              example:
                password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
                id: 3245
                name: Allocation Integration
                login: b1c657b0a0864e9597cbdbacc67c79de
                group: Administrator
                allowedIPNetworks: null
                createdOn: '2026-05-25T04:42:55.1879247Z'
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceAccountDetailResponse'
              example:
                password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
                id: 3245
                name: Allocation Integration
                login: b1c657b0a0864e9597cbdbacc67c79de
                group: Administrator
                allowedIPNetworks: null
                createdOn: '2026-05-25T04:42:55.1879247Z'
            text/json:
              schema:
                $ref: '#/components/schemas/ServiceAccountDetailResponse'
              example:
                password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
                id: 3245
                name: Allocation Integration
                login: b1c657b0a0864e9597cbdbacc67c79de
                group: Administrator
                allowedIPNetworks: null
                createdOn: '2026-05-25T04:42:55.1879247Z'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
  /rp/api/v1/accounts/{accountId}/service-accounts/{id}:
    put:
      tags:
      - ServiceAccounts
      summary: Updates a service account in the given account
      description: 'You must specify both "name" and "group" for this endpoint.<br/><strong>Permissions</strong><br/>Account: Write'
      operationId: ServiceAccounts_UpdateServiceAccount
      parameters:
      - name: accountId
        in: path
        description: The Account ID
        required: true
        schema:
          type: integer
          format: int32
      - name: id
        in: path
        description: The Service Account ID
        required: true
        schema:
          type: integer
          format: int32
      requestBody:
        description: Object containing the name and group the service account will be updated with
        content:
          application/json-patch+json:
            schema:
              $ref: '#/components/schemas/ServiceAccountRequest'
          application/json:
            schema:
              $ref: '#/components/schemas/ServiceAccountRequest'
          text/json:
            schema:
              $ref: '#/components/schemas/ServiceAccountRequest'
          application/*+json:
            schema:
              $ref: '#/components/schemas/ServiceAccountRequest'
        required: true
      responses:
        '204':
          description: Success
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
    delete:
      tags:
      - ServiceAccounts
      summary: Deactivates a service account in the given account
      description: 'Deactivates the account preventing it from being able to log in and make API calls.<br/><strong>Permissions</strong><br/>Account: Write'
      operationId: ServiceAccounts_DeactivateServiceAccount
      parameters:
      - name: accountId
        in: path
        description: The Account ID
        required: true
        schema:
          type: integer
          format: int32
      - name: id
        in: path
        description: The Service Account ID
        required: true
        schema:
          type: integer
          format: int32
      responses:
        '204':
          description: Success
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
  /rp/api/v1/accounts/{accountId}/service-accounts/{id}/reset-password:
    post:
      tags:
      - ServiceAccounts
      summary: Generates a new password for a service account in the given account
      description: 'This endpoint will generate a new password in the response.


        There is no way to retrieve the password again. A new password will need to be generated if you lose it.<br/><strong>Permissions</strong><br/>Account: Write'
      operationId: ServiceAccounts_ResetPassword
      parameters:
      - name: accountId
        in: path
        description: The Account ID
        required: true
        schema:
          type: integer
          format: int32
      - name: id
        in: path
        description: The Service Account ID
        required: true
        schema:
          type: integer
          format: int32
      responses:
        '200':
          description: 'Success: Service Account model with password'
          content:
            text/plain:
              schema:
                $ref: '#/components/schemas/ServiceAccountDetailResponse'
              example:
                password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
                id: 3245
                name: Allocation Integration
                login: b1c657b0a0864e9597cbdbacc67c79de
                group: Administrator
                allowedIPNetworks: null
                createdOn: '2026-05-25T04:42:55.1888354Z'
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceAccountDetailResponse'
              example:
                password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
                id: 3245
                name: Allocation Integration
                login: b1c657b0a0864e9597cbdbacc67c79de
                group: Administrator
                allowedIPNetworks: null
                createdOn: '2026-05-25T04:42:55.1888354Z'
            text/json:
              schema:
                $ref: '#/components/schemas/ServiceAccountDetailResponse'
              example:
                password: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
                id: 3245
                name: Allocation Integration
                login: b1c657b0a0864e9597cbdbacc67c79de
                group: Administrator
                allowedIPNetworks: null
                createdOn: '2026-05-25T04:42:55.1888354Z'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '422':
          description: Unprocessable Entitiy - Something went wrong trying to reset the password
components:
  schemas:
    ServiceAccountResponse:
      type: object
      properties:
        id:
          type: integer
          format: int32
          example: 3245
        name:
          type: string
          nullable: true
          example: Allocation Integration
        login:
          type: string
          nullable: true
          example: b1c657b0a0864e9597cbdbacc67c79de
        group:
          type: string
          nullable: true
          example: Administrator
        allowedIPNetworks:
          type: array
          items:
            type: string
          nullable: true
        createdOn:
          type: string
          format: date-time
          example: '2020-01-01'
      additionalProperties: false
    ServiceAccountRequest:
      type: object
      properties:
        name:
          type: string
          nullable: true
          example: Allocation Integration
        group:
          type: string
          nullable: true
          example: Administrator
        allowedIPNetworks:
          maxItems: 50
          type: array
          items:
            type: string
          description: The list of allowed IP networks for the service account.
          nullable: true
          example:
          - 192.168.1.0/24
          - 10.0.0.0/8
      additionalProperties: false
    ServiceAccountDetailResponse:
      type: object
      properties:
        password:
          type: string
          nullable: true
          example: uI|O..KsE>TPBmq$#j#(*?-jd*Zm@i@0
        id:
          type: integer
          format: int32
          example: 3245
        name:
          type: string
          nullable: true
          example: Allocation Integration
        login:
          type: string
          nullable: true
          example: b1c657b0a0864e9597cbdbacc67c79de
        group:
          type: string
          nullable: true
          example: Administrator
        allowedIPNetworks:
          type: array
          items:
            type: string
          nullable: true
        createdOn:
          type: string
          format: date-time
          example: '2020-01-01'
      additionalProperties: false
  securitySchemes:
    Bearer:
      type: http
      description: Standard Authorization header using the Bearer scheme
      scheme: bearer
      bearerFormat: JWT