> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ListServiceAccounts



## OpenAPI

````yaml openapi/api_v1_config_openapi3_DOCUMENTATION_ONLY.json GET /api/v1/config/service-accounts
openapi: 3.0.3
info:
  description: >

    The Config API provides standard HTTP/JSON REST endpoints for creating,
    reading,

    updating, deleting, and listing configurable Chronosphere resources.


    Use this link to download the raw Swagger specification:

    <a href="/api/v1/config/swagger.json">/api/v1/config/swagger.json</a>
  title: Config V1 API
  version: v1
servers:
  - url: https://{tenant}.chronosphere.io
    variables:
      tenant:
        default: tenant
        description: tenant ID assigned by the service provider
security:
  - ApiKeyAuth: []
tags:
  - name: ConfigV1
paths:
  /api/v1/config/service-accounts:
    get:
      tags:
        - ServiceAccount
      operationId: ListServiceAccounts
      parameters:
        - description: >-
            Sets the preferred number of items to return per page. If set to
            `0`, the

            server will use its default value. Regardless of the value
            specified, clients

            must never assume how many items will be returned.
          in: query
          name: page.max_size
          schema:
            format: int64
            type: integer
        - description: >-
            An opaque page token that identifies which page the client should
            request.

            An empty value indicates the first page.
          in: query
          name: page.token
          schema:
            type: string
        - description: >-
            Filters results by slug, where any ServiceAccount with a matching
            slug in the given list (and matches all other filters) will be
            returned.
          in: query
          name: slugs
          schema:
            items:
              type: string
            type: array
        - description: >-
            Filters results by name, where any ServiceAccount with a matching
            name in the given list (and matches all other filters) will be
            returned.
          in: query
          name: names
          schema:
            items:
              type: string
            type: array
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/configv1ListServiceAccountsResponse'
          description: A successful response.
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/apiError'
          description: An unexpected error response.
        default:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/genericError'
          description: An undefined error response.
components:
  schemas:
    configv1ListServiceAccountsResponse:
      properties:
        page:
          $ref: '#/components/schemas/configv1PageResult'
        service_accounts:
          items:
            $ref: '#/components/schemas/configv1ServiceAccount'
          type: array
      type: object
    apiError:
      properties:
        message:
          description: An error message describing what went wrong.
          type: string
      type: object
    genericError:
      additionalProperties: true
      type: object
    configv1PageResult:
      properties:
        next_token:
          description: |-
            An opaque page token that identifies the next page of items that the
            client should request. An empty value indicates that there are no
            more items to return.
          type: string
      type: object
    configv1ServiceAccount:
      properties:
        created_at:
          description: >-
            Timestamp of when the ServiceAccount was created. Cannot be set by
            clients.
          format: date-time
          readOnly: true
          type: string
        email:
          description: >-
            The unique email user for this service account. Cannot be set by
            clients.
          readOnly: true
          type: string
        metrics_restriction:
          allOf:
            - $ref: '#/components/schemas/ServiceAccountMetricsRestriction'
          description: |-
            If set, restricts access of the service account to only metric data.

            Only one of `unrestricted` or `metrics_restriction` must be set.
        name:
          description: >-
            The name of the ServiceAccount. You can modify this value after the
            ServiceAccount is created.
          type: string
        slug:
          description: >-
            The unique identifier of the ServiceAccount. If a `slug` isn't
            provided, one is generated based on the `name` field. You can't
            modify this field after the ServiceAccount is created.
          type: string
        token:
          description: >-
            Generated API token of the service account. Cannot be set by
            clients.


            The token is set only once by the server in the
            `CreateServiceAccount` response.

            The `ReadServiceAccount` response always returns an empty token.
            Therefore, when

            creating a service account, ensure you securely store the response
            token.

            If you lose the token, you must delete and recreate the service
            account to

            generate a new token.
          readOnly: true
          type: string
        unrestricted:
          description: >-
            If set, grants the service account access to all Palo Alto Networks
            APIs, including

            resource configuration and metric data within the access controls
            defined by the

            service account's team membership.


            Only one of `unrestricted` or `metrics_restriction` must be set.
          type: boolean
        updated_at:
          description: >-
            Timestamp of when the ServiceAccount was last updated. Cannot be set
            by clients.
          format: date-time
          readOnly: true
          type: string
      required:
        - name
      type: object
    ServiceAccountMetricsRestriction:
      properties:
        labels:
          additionalProperties:
            type: string
          description: >-
            Optional. Specifies labels that further restrict the service account
            to only

            read or write metrics with the given label names and values.
          type: object
        permission:
          allOf:
            - $ref: '#/components/schemas/MetricsRestrictionPermission'
          description: >-
            Permission that defines the access level of the service account to
            only metric data:

            - `READ` grants read-only access.

            - `WRITE` grants write-only access.

            - `READ_WRITE` grants read and write access.
      required:
        - permission
      type: object
    MetricsRestrictionPermission:
      enum:
        - READ
        - WRITE
        - READ_WRITE
      type: string
  securitySchemes:
    ApiKeyAuth:
      description: Chronosphere API token
      in: header
      name: API-Token
      type: apiKey

````

## Related topics

- [Service accounts](/administer/accounts-teams/service-accounts.md)
- [Accounts and teams](/administer/accounts-teams.md)
- [User accounts](/administer/accounts-teams/user-accounts.md)
- [Teams](/administer/accounts-teams/teams.md)
- [CreateServiceAccount](/tooling/api-info/definition/operations/CreateServiceAccount.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.