GetServiceAccount
/api/v1/serviceaccounts/{service_account}Fetch a service account by name. The API key itself is only ever returned when it is created.
Example request
curl \ -H "Authorization: Bearer ${OBLIQUE_API_KEY}" \ "https://us.oblique.security/api/v1/serviceaccounts/{service_account}"Set OBLIQUE_API_KEY to your API key.
curl \ -H "Authorization: Bearer ${OBLIQUE_API_KEY}" \ "https://eu.oblique.security/api/v1/serviceaccounts/{service_account}"Set OBLIQUE_API_KEY to your API key.
Path parameters
namestringrequiredThe name of the service account to get.
Response
200ServiceAccountService accounts are dynamically created users that can authenticate to the API. They can be associated with API keys, and in the future will be able to authenticate automation using workload identities.
Administrators can create service accounts with associated API keys.
namestringAssigned by Oblique. The name of the service account resource. This is an arbitrary string and does not have to match the user’s name.
displayNamestringrequiredThe display name of the service account.
apiKeystringread-onlyThe API key of the service account. This is only returned once during the CreateServiceAccount call, and is not available after that. API keys use the format
obl-svc-[0-9a-fA-F_\-]+.To use a service account, provide it as a bearer token in the Authorization header:
Authorization: Bearer <api_key>.apiKeyOpaquestringread-onlyA safe version of the API key that is always returned and can be displayed to users. This replaces a significant portion of the API key with asterisks, and can be used to identify the service account without using the key itself.
createTimestring (date-time)read-onlyThe time the service account was created.
updateTimestring (date-time)read-onlyThe time the service account was last updated.
deleteTimestring (date-time)read-onlyThe time the service account was deleted, effectively revoking it.
lastUsedTimestring (date-time)read-onlyThe time the service account was successfully used. This does not include requests that are blocked by the service account’s permissions.
creatorKindstringread-onlyThe kind of the creator of the service account.
creatorstringread-onlyThe creator of the service account. Will only be present if creator_kind is USER.
Format:
users/{user}permissionsstringrequired
Errors
| Status | Meaning |
|---|---|
400 | Malformed request |
401 | Missing or invalid API key |
403 | Not allowed for this API key |
404 | Not found |
429 | Too many requests |
500 | Internal server error |