Grafana Service Accounts API

If you are running Grafana Enterprise, for some endpoints you'll need to have specific permissions. Refer to [Role-based access control permissions](https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/custom-role-actions-scopes/) for more information.

Operations 8

POST /serviceaccounts Create service account #
GET /serviceaccounts/search Search service accounts with paging #
GET /serviceaccounts/{serviceAccountId} Get single serviceaccount by Id #
DELETE /serviceaccounts/{serviceAccountId} Delete service account #
PATCH /serviceaccounts/{serviceAccountId} Update service account #
GET /serviceaccounts/{serviceAccountId}/tokens Get service account tokens #
POST /serviceaccounts/{serviceAccountId}/tokens CreateNewToken adds a token to a service account #
DELETE /serviceaccounts/{serviceAccountId}/tokens/{tokenId} DeleteToken deletes service account tokens #

Documentation

📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/
📖
Authentication
https://grafana.com/docs/grafana/latest/developers/http_api/authentication/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/dashboard/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/dashboard_versions/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/dashboard_permissions/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/dashboard_public/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/folder/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/folder_dashboard_search/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/folder_permissions/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/data_source/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/datasource_permissions/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/datasource_lbac_rules/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/alerting_provisioning/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/annotations/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/org/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/user/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/team/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/team_sync/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/preferences/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/access_control/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/serviceaccount/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/sso-settings/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/admin/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/licensing/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/reporting/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/query_and_resource_caching/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/library_element/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/correlations/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/snapshot/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/short_url/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/query_history/

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/grafana-com-service-accounts-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

grafana-com-service-accounts-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: 'The Grafana backend exposes an HTTP API, the same API is used by the frontend to do

    everything from saving dashboards, creating users and updating data sources.'
  title: Grafana HTTP API. Service Accounts API
  contact:
    name: Grafana Labs
    url: https://grafana.com
    email: hello@grafana.com
  version: 0.0.1
servers:
- url: /api
security:
- basic: []
- api_key: []
tags:
- description: If you are running Grafana Enterprise, for some endpoints you'll need to have specific permissions. Refer to Role-based access control permissions for more information.
  name: service_accounts
paths:
  /serviceaccounts:
    post:
      description: 'Required permissions (See note in the introduction for an explanation):

        action: `serviceaccounts:write` scope: `serviceaccounts:*`


        Requires basic authentication and that the authenticated user is a Grafana Admin.'
      tags:
      - service_accounts
      summary: Create service account
      operationId: createServiceAccount
      responses:
        '201':
          $ref: '#/components/responses/createServiceAccountResponse'
        '400':
          $ref: '#/components/responses/badRequestError'
        '401':
          $ref: '#/components/responses/unauthorisedError'
        '403':
          $ref: '#/components/responses/forbiddenError'
        '500':
          $ref: '#/components/responses/internalServerError'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateServiceAccountForm'
  /serviceaccounts/search:
    get:
      description: 'Required permissions (See note in the introduction for an explanation):

        action: `serviceaccounts:read` scope: `serviceaccounts:*`'
      tags:
      - service_accounts
      summary: Search service accounts with paging
      operationId: searchOrgServiceAccountsWithPaging
      parameters:
      - name: Disabled
        in: query
        schema:
          type: boolean
      - name: expiredTokens
        in: query
        schema:
          type: boolean
      - description: 'It will return results where the query value is contained in one of the name.

          Query values with spaces need to be URL encoded.'
        name: query
        in: query
        schema:
          type: string
      - description: The default value is 1000.
        name: perpage
        in: query
        schema:
          type: integer
          format: int64
      - description: The default value is 1.
        name: page
        in: query
        schema:
          type: integer
          format: int64
      responses:
        '200':
          $ref: '#/components/responses/searchOrgServiceAccountsWithPagingResponse'
        '401':
          $ref: '#/components/responses/unauthorisedError'
        '403':
          $ref: '#/components/responses/forbiddenError'
        '500':
          $ref: '#/components/responses/internalServerError'
  /serviceaccounts/{serviceAccountId}:
    get:
      description: 'Required permissions (See note in the introduction for an explanation):

        action: `serviceaccounts:read` scope: `serviceaccounts:id:1` (single service account)'
      tags:
      - service_accounts
      summary: Get single serviceaccount by Id
      operationId: retrieveServiceAccount
      parameters:
      - name: serviceAccountId
        in: path
        required: true
        schema:
          type: integer
          format: int64
      responses:
        '200':
          $ref: '#/components/responses/retrieveServiceAccountResponse'
        '400':
          $ref: '#/components/responses/badRequestError'
        '401':
          $ref: '#/components/responses/unauthorisedError'
        '403':
          $ref: '#/components/responses/forbiddenError'
        '404':
          $ref: '#/components/responses/notFoundError'
        '500':
          $ref: '#/components/responses/internalServerError'
    delete:
      description: 'Required permissions (See note in the introduction for an explanation):

        action: `serviceaccounts:delete` scope: `serviceaccounts:id:1` (single service account)'
      tags:
      - service_accounts
      summary: Delete service account
      operationId: deleteServiceAccount
      parameters:
      - name: serviceAccountId
        in: path
        required: true
        schema:
          type: integer
          format: int64
      responses:
        '200':
          $ref: '#/components/responses/okResponse'
        '400':
          $ref: '#/components/responses/badRequestError'
        '401':
          $ref: '#/components/responses/unauthorisedError'
        '403':
          $ref: '#/components/responses/forbiddenError'
        '404':
          $ref: '#/components/responses/notFoundError'
        '500':
          $ref: '#/components/responses/internalServerError'
    patch:
      description: 'Required permissions (See note in the introduction for an explanation):

        action: `serviceaccounts:write` scope: `serviceaccounts:id:1` (single service account)'
      tags:
      - service_accounts
      summary: Update service account
      operationId: updateServiceAccount
      parameters:
      - name: serviceAccountId
        in: path
        required: true
        schema:
          type: integer
          format: int64
      responses:
        '200':
          $ref: '#/components/responses/updateServiceAccountResponse'
        '400':
          $ref: '#/components/responses/badRequestError'
        '401':
          $ref: '#/components/responses/unauthorisedError'
        '403':
          $ref: '#/components/responses/forbiddenError'
        '404':
          $ref: '#/components/responses/notFoundError'
        '500':
          $ref: '#/components/responses/internalServerError'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateServiceAccountForm'
  /serviceaccounts/{serviceAccountId}/tokens:
    get:
      description: 'Required permissions (See note in the introduction for an explanation):

        action: `serviceaccounts:read` scope: `global:serviceaccounts:id:1` (single service account)


        Requires basic authentication and that the authenticated user is a Grafana Admin.'
      tags:
      - service_accounts
      summary: Get service account tokens
      operationId: listTokens
      parameters:
      - name: serviceAccountId
        in: path
        required: true
        schema:
          type: integer
          format: int64
      responses:
        '200':
          $ref: '#/components/responses/listTokensResponse'
        '400':
          $ref: '#/components/responses/badRequestError'
        '401':
          $ref: '#/components/responses/unauthorisedError'
        '403':
          $ref: '#/components/responses/forbiddenError'
        '500':
          $ref: '#/components/responses/internalServerError'
    post:
      description: 'Required permissions (See note in the introduction for an explanation):

        action: `serviceaccounts:write` scope: `serviceaccounts:id:1` (single service account)'
      tags:
      - service_accounts
      summary: CreateNewToken adds a token to a service account
      operationId: createToken
      parameters:
      - name: serviceAccountId
        in: path
        required: true
        schema:
          type: integer
          format: int64
      responses:
        '200':
          $ref: '#/components/responses/createTokenResponse'
        '400':
          $ref: '#/components/responses/badRequestError'
        '401':
          $ref: '#/components/responses/unauthorisedError'
        '403':
          $ref: '#/components/responses/forbiddenError'
        '404':
          $ref: '#/components/responses/notFoundError'
        '409':
          $ref: '#/components/responses/conflictError'
        '500':
          $ref: '#/components/responses/internalServerError'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AddServiceAccountTokenCommand'
  /serviceaccounts/{serviceAccountId}/tokens/{tokenId}:
    delete:
      description: 'Required permissions (See note in the introduction for an explanation):

        action: `serviceaccounts:write` scope: `serviceaccounts:id:1` (single service account)


        Requires basic authentication and that the authenticated user is a Grafana Admin.'
      tags:
      - service_accounts
      summary: DeleteToken deletes service account tokens
      operationId: deleteToken
      parameters:
      - name: tokenId
        in: path
        required: true
        schema:
          type: integer
          format: int64
      - name: serviceAccountId
        in: path
        required: true
        schema:
          type: integer
          format: int64
      responses:
        '200':
          $ref: '#/components/responses/okResponse'
        '400':
          $ref: '#/components/responses/badRequestError'
        '401':
          $ref: '#/components/responses/unauthorisedError'
        '403':
          $ref: '#/components/responses/forbiddenError'
        '404':
          $ref: '#/components/responses/notFoundError'
        '500':
          $ref: '#/components/responses/internalServerError'
components:
  responses:
    unauthorisedError:
      description: UnauthorizedError is returned when the request is not authenticated.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponseBody'
    createTokenResponse:
      description: (empty)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/NewApiKeyResult'
    searchOrgServiceAccountsWithPagingResponse:
      description: (empty)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/SearchOrgServiceAccountsResult'
    listTokensResponse:
      description: (empty)
      content:
        application/json:
          schema:
            type: array
            items:
              $ref: '#/components/schemas/TokenDTO'
    internalServerError:
      description: InternalServerError is a general error indicating something went wrong internally.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponseBody'
    conflictError:
      description: ConflictError
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponseBody'
    badRequestError:
      description: BadRequestError is returned when the request is invalid and it cannot be processed.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponseBody'
    okResponse:
      description: An OKResponse is returned if the request was successful.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/SuccessResponseBody'
    forbiddenError:
      description: ForbiddenError is returned if the user/token has insufficient permissions to access the requested resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponseBody'
    createServiceAccountResponse:
      description: (empty)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ServiceAccountDTO'
    retrieveServiceAccountResponse:
      description: (empty)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ServiceAccountDTO'
    updateServiceAccountResponse:
      description: (empty)
      content:
        application/json:
          schema:
            type: object
            properties:
              id:
                type: integer
                format: int64
              message:
                type: string
              name:
                type: string
              serviceaccount:
                $ref: '#/components/schemas/ServiceAccountProfileDTO'
    notFoundError:
      description: NotFoundError is returned when the requested resource was not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponseBody'
  schemas:
    UpdateServiceAccountForm:
      type: object
      properties:
        isDisabled:
          type: boolean
        name:
          type: string
        role:
          type: string
          enum:
          - None
          - Viewer
          - Editor
          - Admin
        serviceAccountId:
          type: integer
          format: int64
    ErrorResponseBody:
      type: object
      required:
      - message
      properties:
        error:
          description: Error An optional detailed description of the actual error. Only included if running in developer mode.
          type: string
        message:
          description: a human readable version of the error
          type: string
        status:
          description: 'Status An optional status to denote the cause of the error.


            For example, a 412 Precondition Failed error may include additional information of why that error happened.'
          type: string
    TokenDTO:
      type: object
      properties:
        created:
          type: string
          format: date-time
          example: '2022-03-23T10:31:02Z'
        expiration:
          type: string
          format: date-time
          example: '2022-03-23T10:31:02Z'
        hasExpired:
          type: boolean
          example: false
        id:
          type: integer
          format: int64
          example: 1
        isRevoked:
          type: boolean
          example: false
        lastUsedAt:
          type: string
          format: date-time
          example: '2022-03-23T10:31:02Z'
        name:
          type: string
          example: grafana
        secondsUntilExpiration:
          type: number
          format: double
          example: 0
    NewApiKeyResult:
      type: object
      properties:
        id:
          type: integer
          format: int64
          example: 1
        key:
          type: string
          example: glsa_REDACTED-GRAFANA-SERVICE-ACCOUNT-TOKEN
        name:
          type: string
          example: grafana
    ServiceAccountProfileDTO:
      type: object
      properties:
        accessControl:
          type: object
          additionalProperties:
            type: boolean
        avatarUrl:
          type: string
          example: /avatar/8ea890a677d6a223c591a1beea6ea9d2
        createdAt:
          type: string
          format: date-time
          example: '2022-03-21T14:35:33Z'
        id:
          type: integer
          format: int64
          example: 2
        isDisabled:
          type: boolean
          example: false
        isExternal:
          type: boolean
          example: false
        login:
          type: string
          example: sa-grafana
        name:
          type: string
          example: test
        orgId:
          type: integer
          format: int64
          example: 1
        requiredBy:
          type: string
          example: grafana-app
        role:
          type: string
          example: Editor
        teams:
          type: array
          items:
            type: string
          example: []
        tokens:
          type: integer
          format: int64
        uid:
          type: string
          example: fe1xejlha91xce
        updatedAt:
          type: string
          format: date-time
          example: '2022-03-21T14:35:33Z'
    CreateServiceAccountForm:
      type: object
      properties:
        isDisabled:
          type: boolean
          example: false
        name:
          type: string
          example: grafana
        role:
          type: string
          enum:
          - None
          - Viewer
          - Editor
          - Admin
          example: Admin
    AddServiceAccountTokenCommand:
      type: object
      properties:
        name:
          type: string
        secondsToLive:
          type: integer
          format: int64
    SearchOrgServiceAccountsResult:
      type: object
      properties:
        page:
          type: integer
          format: int64
        perPage:
          type: integer
          format: int64
        serviceAccounts:
          type: array
          items:
            $ref: '#/components/schemas/ServiceAccountDTO'
        totalCount:
          description: 'It can be used for pagination of the user list

            E.g. if totalCount is equal to 100 users and

            the perpage parameter is set to 10 then there are 10 pages of users.'
          type: integer
          format: int64
    ServiceAccountDTO:
      type: object
      properties:
        accessControl:
          type: object
          additionalProperties:
            type: boolean
          example:
            serviceaccounts:delete: true
            serviceaccounts:read: true
            serviceaccounts:write: true
        avatarUrl:
          type: string
          example: /avatar/85ec38023d90823d3e5b43ef35646af9
        id:
          type: integer
          format: int64
        isDisabled:
          type: boolean
          example: false
        isExternal:
          type: boolean
          example: false
        login:
          type: string
          example: sa-grafana
        name:
          type: string
          example: grafana
        orgId:
          type: integer
          format: int64
          example: 1
        role:
          type: string
          example: Viewer
        tokens:
          type: integer
          format: int64
          example: 0
        uid:
          type: string
          example: fe1xejlha91xce
    SuccessResponseBody:
      type: object
      properties:
        message:
          type: string
  securitySchemes:
    api_key:
      type: apiKey
      name: Authorization
      in: header
    basic:
      type: http
      scheme: basic