service-accounts

Admin-only CRUD for the organization's Google Calendar service account.

Manages only the org-level service account (calendar_fk IS NULL) — the one used for rooms sync. Per-calendar service accounts are auto-assigned by the calendar auth flow and are intentionally not exposed here.

Secrets (private_key, private_key_id) are write-only and never echoed; all responses use ServiceAccountReadSerializer. There is at most one org-level account per organization: create refuses a duplicate (rotate via PUT/PATCH or DELETE first). Cross-org ids resolve to 404 via the org-scoped queryset; non-admins get 403; anonymous requests 401.

get/service-accounts/{id}{format}

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Path parameters

format'.json' required
idstring required

Headers

X-Organization-Idstring

Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.

Response

idinteger required
emailstring email required
admin_emailstring email required

Google Workspace super-admin email used as the DWD impersonation subject. The service account must have domain-wide delegation granted for the Admin SDK and Calendar API scopes in the Google Admin Console.

configuredboolean required

A persisted row is, by definition, configured.

createdstring date-time required
modifiedstring date-time required

Changes

    • ○

      added the new optional header request parameter X-Organization-Id

    • ▲

      removed the required property from the response with the status

    • ○

      added the required property to the response with the status