service-accounts

Admin-only CRUD for the organization's Google Calendar service account.

Manages only the org-level service account (calendar_fk IS NULL) — the one used for rooms sync. Per-calendar service accounts are auto-assigned by the calendar auth flow and are intentionally not exposed here.

Secrets (private_key, private_key_id) are write-only and never echoed; all responses use ServiceAccountReadSerializer. There is at most one org-level account per organization: create refuses a duplicate (rotate via PUT/PATCH or DELETE first). Cross-org ids resolve to 404 via the org-scoped queryset; non-admins get 403; anonymous requests 401.

patch/service-accounts/{id}{format}

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Path parameters

format'.json' required
idstring required

Headers

X-Organization-Idstring

Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.

Request body

emailstring email
admin_emailstring email

Google Workspace super-admin email used as the DWD impersonation subject. The service account must have domain-wide delegation granted for the Admin SDK and Calendar API scopes in the Google Admin Console.

private_key_idstring
private_keystring

Response

emailstring email required
admin_emailstring email

Google Workspace super-admin email used as the DWD impersonation subject. The service account must have domain-wide delegation granted for the Admin SDK and Calendar API scopes in the Google Admin Console.

private_key_idstring required
private_keystring required

Changes

    • ○

      added the new optional header request parameter X-Organization-Id

    • ▲

      removed the required property from the response with the status

    • ●

      removed the request property (media type: application/json)

    • ●

      removed the request property (media type: application/x-www-form-urlencoded)

    • ●

      removed the request property (media type: multipart/form-data)