---
title: "Get service account tokens"
method: GET
path: "/serviceaccounts/{serviceAccountId}/tokens"
tags: ["service_accounts"]
---

# Get service account tokens

`GET /serviceaccounts/{serviceAccountId}/tokens`

Required permissions (See note in the [introduction](https://grafana.com/docs/grafana/latest/developers/http_api/serviceaccount/#service-account-api) for an explanation):
action: `serviceaccounts:read` scope: `global:serviceaccounts:id:1` (single service account)

Requires basic authentication and that the authenticated user is a Grafana Admin.

## Path parameters

- `serviceAccountId` integer, required

## Response `200`

(empty)

- TokenDTO[]
  - `created` string, date-time
  - `expiration` string, date-time
  - `hasExpired` boolean
  - `id` integer
  - `isRevoked` boolean
  - `lastUsedAt` string, date-time
  - `name` string
  - `secondsUntilExpiration` number, double

## Other responses

- `400` — BadRequestError is returned when the request is invalid and it cannot be processed.
- `401` — UnauthorizedError is returned when the request is not authenticated.
- `403` — ForbiddenError is returned if the user/token has insufficient permissions to access the requested resource.
- `500` — InternalServerError is a general error indicating something went wrong internally.

---

[API](https://skmtc.net/grafana/apis/http-api.md) · [All operations](https://skmtc.net/grafana/apis/http-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/grafana/http-api/versions/df55ba1718ba/schema)
