CloudTruth Service Accounts API

The Service Accounts API from CloudTruth — 3 operation(s) for service accounts.

Operations 7

GET /api/v1/serviceaccounts/ Serviceaccounts list #
POST /api/v1/serviceaccounts/ Create a ServiceAccount user #
GET /api/v1/serviceaccounts/{id}/ Serviceaccounts retrieve #
PUT /api/v1/serviceaccounts/{id}/ Update a ServiceAccount user #
PATCH /api/v1/serviceaccounts/{id}/ Serviceaccounts partial update #
DELETE /api/v1/serviceaccounts/{id}/ Serviceaccounts destroy #
POST /api/v1/serviceaccounts/{id}/rekey/ Serviceaccounts rekey create #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cloudtruth:cloudtruth-service-accounts-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cloudtruth-service-accounts-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: CloudTruth Management Serviceaccounts API
  version: v1
  description: CloudTruth centralizes your configuration parameters and secrets making them easier to manage and use as a team.
  contact:
    name: CloudTruth Support
    email: support@cloudtruth.com
tags:
- name: Service Accounts
paths:
  /api/v1/serviceaccounts/:
    get:
      operationId: serviceaccounts_list
      parameters:
      - name: ordering
        required: false
        in: query
        description: Which field to use when ordering the results.
        schema:
          type: string
      - name: page
        required: false
        in: query
        description: A page number within the paginated result set.
        schema:
          type: integer
      - name: page_size
        required: false
        in: query
        description: Number of results to return per page.
        schema:
          type: integer
      tags:
      - Service Accounts
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedServiceAccountList'
          description: ''
      summary: Serviceaccounts list
      x-summary-source: derived
    post:
      operationId: serviceaccounts_create
      description: 'Creates a new ServiceAccount. A ServiceAccount is a user record intended

        for machine use (such as a build system). It does not have a username/password

        but is instead accessed using an API key.


        On creation, the API key will be returned. This key will only be shown once,

        is not stored on any CloudTruth system, and should be treated as a secret. Should

        the key be lost, you will need to delete and recreate the ServiceAccount in order

        to generate a new API key.'
      summary: Create a ServiceAccount user
      tags:
      - Service Accounts
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ServiceAccountCreateRequest'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/ServiceAccountCreateRequest'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/ServiceAccountCreateRequest'
        required: true
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceAccountCreateResponse'
          description: ''
  /api/v1/serviceaccounts/{id}/:
    get:
      operationId: serviceaccounts_retrieve
      parameters:
      - in: path
        name: id
        schema:
          type: string
        description: A unique value identifying this service account.
        required: true
      tags:
      - Service Accounts
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceAccount'
          description: ''
      summary: Serviceaccounts retrieve
      x-summary-source: derived
    put:
      operationId: serviceaccounts_update
      description: 'Updates a ServiceAccount. A ServiceAccount is a user record intended

        for machine use (such as a build system). It does not have a username/password

        but is instead accessed using an API key.'
      summary: Update a ServiceAccount user
      parameters:
      - in: path
        name: id
        schema:
          type: string
        description: A unique value identifying this service account.
        required: true
      tags:
      - Service Accounts
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ServiceAccountUpdateRequest'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/ServiceAccountUpdateRequest'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/ServiceAccountUpdateRequest'
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceAccountUpdateRequest'
          description: ''
    patch:
      operationId: serviceaccounts_partial_update
      parameters:
      - in: path
        name: id
        schema:
          type: string
        description: A unique value identifying this service account.
        required: true
      tags:
      - Service Accounts
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PatchedServiceAccount'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/PatchedServiceAccount'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/PatchedServiceAccount'
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceAccount'
          description: ''
      summary: Serviceaccounts partial update
      x-summary-source: derived
    delete:
      operationId: serviceaccounts_destroy
      parameters:
      - in: path
        name: id
        schema:
          type: string
        description: A unique value identifying this service account.
        required: true
      tags:
      - Service Accounts
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '204':
          description: No response body
      summary: Serviceaccounts destroy
      x-summary-source: derived
  /api/v1/serviceaccounts/{id}/rekey/:
    post:
      operationId: serviceaccounts_rekey_create
      parameters:
      - in: path
        name: id
        schema:
          type: string
        description: A unique value identifying this service account.
        required: true
      tags:
      - Service Accounts
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ServiceAccountRekeyRequest'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/ServiceAccountRekeyRequest'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/ServiceAccountRekeyRequest'
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceAccountRekeyRequest'
          description: ''
      summary: Serviceaccounts rekey create
      x-summary-source: derived
components:
  schemas:
    ServiceAccountRekeyRequest:
      type: object
      properties:
        expire_at:
          type:
          - string
          - 'null'
          format: date-time
          description: The date and time the previous API key will expire.
    ServiceAccountCreateResponse:
      type: object
      properties:
        url:
          type: string
          format: uri
          readOnly: true
        id:
          type: string
          readOnly: true
        owner:
          type:
          - string
          - 'null'
          format: uri
        user:
          allOf:
          - $ref: '#/components/schemas/User'
          readOnly: true
        description:
          type: string
          description: An optional description of the process or system using the service account.
        keys:
          type: array
          items:
            $ref: '#/components/schemas/ServiceAccountAPIKey'
          readOnly: true
        created_at:
          type: string
          format: date-time
          readOnly: true
        modified_at:
          type:
          - string
          - 'null'
          format: date-time
          readOnly: true
        last_used_at:
          type:
          - string
          - 'null'
          format: date-time
          readOnly: true
          description: The most recent date and time the service account was used.  It will be null if the service account has not been used.
        apikey:
          type: string
          readOnly: true
          description: The API Key to use as a Bearer token for the service account.
      required:
      - apikey
      - created_at
      - id
      - keys
      - last_used_at
      - modified_at
      - url
      - user
    ServiceAccountCreateRequest:
      type: object
      properties:
        name:
          type: string
          description: The name of the process or system using the service account.
          maxLength: 128
        description:
          type: string
          description: An optional description of the process or system using the service account.
        role:
          type: string
          writeOnly: true
          description: The role for the service acount
        owner:
          type: string
          description: The owner of the service account.
          maxLength: 128
      required:
      - name
    ServiceAccount:
      type: object
      properties:
        url:
          type: string
          format: uri
          readOnly: true
        id:
          type: string
          readOnly: true
        owner:
          type:
          - string
          - 'null'
          format: uri
        user:
          allOf:
          - $ref: '#/components/schemas/User'
          readOnly: true
        description:
          type: string
          description: An optional description of the process or system using the service account.
        keys:
          type: array
          items:
            $ref: '#/components/schemas/ServiceAccountAPIKey'
          readOnly: true
        created_at:
          type: string
          format: date-time
          readOnly: true
        modified_at:
          type:
          - string
          - 'null'
          format: date-time
          readOnly: true
        last_used_at:
          type:
          - string
          - 'null'
          format: date-time
          readOnly: true
          description: The most recent date and time the service account was used.  It will be null if the service account has not been used.
      required:
      - created_at
      - id
      - keys
      - last_used_at
      - modified_at
      - url
      - user
    PatchedServiceAccount:
      type: object
      properties:
        url:
          type: string
          format: uri
          readOnly: true
        id:
          type: string
          readOnly: true
        owner:
          type:
          - string
          - 'null'
          format: uri
        user:
          allOf:
          - $ref: '#/components/schemas/User'
          readOnly: true
        description:
          type: string
          description: An optional description of the process or system using the service account.
        keys:
          type: array
          items:
            $ref: '#/components/schemas/ServiceAccountAPIKey'
          readOnly: true
        created_at:
          type: string
          format: date-time
          readOnly: true
        modified_at:
          type:
          - string
          - 'null'
          format: date-time
          readOnly: true
        last_used_at:
          type:
          - string
          - 'null'
          format: date-time
          readOnly: true
          description: The most recent date and time the service account was used.  It will be null if the service account has not been used.
    ServiceAccountUpdateRequest:
      type: object
      properties:
        description:
          type: string
          description: An optional description of the process or system using the service account.
        role:
          type: string
          readOnly: true
          description: The role for the service acount
        owner:
          type: string
          description: The owner of the service account.
          maxLength: 128
      required:
      - role
    ServiceAccountAPIKey:
      type: object
      properties:
        name:
          type: string
          description: A free-form name for the API key. Need not be unique. 50 characters max.
          maxLength: 50
        prefix:
          type: string
          readOnly: true
        revoked:
          type: boolean
          description: If the API key is revoked, clients cannot use it anymore. (This cannot be undone.)
        has_expired:
          type: boolean
          readOnly: true
        created:
          type: string
          format: date-time
          readOnly: true
        expiry_date:
          type:
          - string
          - 'null'
          format: date-time
          title: Expires
          description: Once API key expires, clients cannot use it anymore.
      required:
      - created
      - has_expired
      - prefix
    User:
      type: object
      properties:
        url:
          type: string
          format: uri
          readOnly: true
        id:
          type: string
          description: The unique identifier of a user.
          maxLength: 256
        type:
          type: string
          description: The type of user record.
          maxLength: 12
        name:
          type:
          - string
          - 'null'
          readOnly: true
        organization_name:
          type:
          - string
          - 'null'
          readOnly: true
          description: The user's organization name.
        membership_id:
          type:
          - string
          - 'null'
          readOnly: true
          description: Membership identifier for user.
        chatgpt_threads:
          type: object
          additionalProperties: {}
          readOnly: true
          description: The threads this user is participating in with ChatGPT.
        role:
          type:
          - string
          - 'null'
          readOnly: true
          description: The user's role in the current organization (defined by the request authorization header).
        email:
          type:
          - string
          - 'null'
          readOnly: true
        picture_url:
          type:
          - string
          - 'null'
          readOnly: true
        created_at:
          type: string
          format: date-time
          readOnly: true
        modified_at:
          type:
          - string
          - 'null'
          format: date-time
          readOnly: true
      required:
      - chatgpt_threads
      - created_at
      - email
      - id
      - membership_id
      - modified_at
      - name
      - organization_name
      - picture_url
      - role
      - url
    PaginatedServiceAccountList:
      type: object
      required:
      - count
      - results
      properties:
        count:
          type: integer
          example: 123
        next:
          type:
          - string
          - 'null'
          format: uri
          example: http://api.example.org/accounts/?page=4
        previous:
          type:
          - string
          - 'null'
          format: uri
          example: http://api.example.org/accounts/?page=2
        results:
          type: array
          items:
            $ref: '#/components/schemas/ServiceAccount'
  securitySchemes:
    ApiKeyAuth:
      in: header
      name: Authorization
      type: apiKey
      description: "\nUse your CloudTruth API Key to authenticate to the API.  You can get\nan API Key by creating a Service Account.  During setup of the Service\nAccount you will generate a long-lived API key intended for use by automation\nand API clients.  Access through the service account will be audited separately\nfrom any other user.\n\nIf you are just trying to use the API in a normal workflow, this is likely the\nauthentication mechanism you want to use.\n\nTo use the API Key, place your API Key in the Authorization header as 'Api-Key APIKEY', where\nAPIKEY is your CloudTruth API Key.  For example:\n\n    Authorization: Api-Key fskur.ghlsiudhrg84so938r5u\n        "
    JWTAuth:
      in: header
      name: Authorization
      type: apiKey
      description: "\nUse your JWT to authenticate to the API.  This is how the CloudTruth\nWeb UI authenticates to the backend.  It requires a user to have already logged in\nand gotten a JWT from the login process.  This is usually done by an Auth0 authentication\nflow from one of the Auth0 javascript libraries.  Alternatively, you can pull the\nJWT from your browser if you have a logged in session with the CloudTruth UI.\n\nThis authentication mechanism is intended for deeper integrations into the CloudTruth\nsystem, where you want to handle the user logins directly in your application.  For\nnormal API use, you likely want the Api-Key authentication header and not this one.\n\nTo use the JWT, place your JWT in the Authorization header as 'Bearer JWT', where\nJWT is your JWT.  For example:\n\n    Authorization: Bearer eyJhbGciOiJIkuydfy.eyJzdWIiOiIxMjM....\n        "
    tokenAuth:
      type: http
      scheme: bearer
externalDocs:
  url: https://docs.cloudtruth.com/