Delete and undelete service accounts
Stay organized with collections
Save and categorize content based on your preferences.
This page explains how to delete and undelete service accounts using the
Identity and Access Management (IAM) API, the Google Cloud console, and the gcloud command-
line tool.
Before you begin
Enable the IAM API, if it is not already enabled.
Roles required to enable APIs
To enable APIs, you need the serviceusage.services.enable permission. If you
created the project, then you likely already have this permission through the
Owner role (roles/owner). Otherwise, you can get this permission through the
Service Usage Admin role (roles/serviceusage.serviceUsageAdmin).
Learn how to grant roles.
At the bottom of the Google Cloud console, a
Cloud Shell
session starts and displays a command-line prompt. Cloud Shell is a shell environment
with the Google Cloud CLI
already installed and with values already set for
your current project. It can take a few seconds for the session to initialize.
C#
To use the .NET samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the C++ samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the Go samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the Java samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the Python samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To get the permissions that
you need to delete and undelete service accounts,
ask your administrator to grant you the
following IAM roles on the project:
IAM basic roles also contain permissions to manage service
accounts.
You should not grant basic roles in a production environment, but you can grant them in a
development or test environment.
Delete a service account
When you delete a service account, applications will no longer have access to
Google Cloud resources through that service account. If you delete the
default App Engine and Compute Engine service accounts, then the
App Engine apps and Compute Engine VM instances that use those
service accounts will no longer have access to resources in the project.
Delete service accounts with caution. Make sure your critical applications are
no longer using a service account before deleting it. If you're not sure whether
a service account is being used, Google recommends
disabling the service account
instead of deleting it. Disabled service accounts can be re-enabled if they are
still needed. For more information, see Disable unused service
accounts before deleting them.
If you want to restore a deleted service account, you can
undelete it, if it's been 30 days or less
since you deleted the service account. After 30 days,
IAM permanently removes the service account. Google Cloud
cannot recover the service account after it is permanently removed, even if you
file a support request.
To further reduce the risk of deleting a necessary service account, you can
also enable change risk recommendations. Change
risk recommendations generate warnings when you try to delete service accounts
that Google Cloud has identified as important.
If you delete a service account, then create a new service account with the same
name, the new service account is treated as a separate identity; it does not
inherit the roles granted to the deleted service account. In contrast, when you
delete a service account, then undelete it, the service account's identity does
not change, and the service account retains its roles.
When a service account is deleted, its role bindings are not immediately
removed; they are automatically purged from the system after a maximum of
60 days. Until that time, the service account appears in
role bindings with a deleted: prefix and a
?uid=NUMERIC_ID suffix, where
NUMERIC_ID is a unique numeric ID for the service
account.
At the bottom of the Google Cloud console, a
Cloud Shell
session starts and displays a command-line prompt. Cloud Shell is a shell environment
with the Google Cloud CLI
already installed and with values already set for
your current project. It can take a few seconds for the session to initialize.
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
usingSystem;usingGoogle.Apis.Auth.OAuth2;usingGoogle.Apis.Iam.v1;publicpartialclassServiceAccounts{publicstaticvoidDeleteServiceAccount(stringemail){varcredential=GoogleCredential.GetApplicationDefault().CreateScoped(IamService.Scope.CloudPlatform);varservice=newIamService(newIamService.Initializer{HttpClientInitializer=credential});stringresource="projects/-/serviceAccounts/"+email;service.Projects.ServiceAccounts.Delete(resource).Execute();Console.WriteLine("Deleted service account: "+email);}}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
import("context""fmt""io"iam"google.golang.org/api/iam/v1")// deleteServiceAccount deletes a service account.funcdeleteServiceAccount(wio.Writer,emailstring)error{ctx:=context.Background()service,err:=iam.NewService(ctx)iferr!=nil{returnfmt.Errorf("iam.NewService: %w",err)}_,err=service.Projects.ServiceAccounts.Delete("projects/-/serviceAccounts/"+email).Do()iferr!=nil{returnfmt.Errorf("Projects.ServiceAccounts.Delete: %w",err)}fmt.Fprintf(w,"Deleted service account: %v",email)returnnil}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
importcom.google.cloud.iam.admin.v1.IAMClient;importcom.google.iam.admin.v1.DeleteServiceAccountRequest;importcom.google.iam.admin.v1.ServiceAccountName;importjava.io.IOException;publicclassDeleteServiceAccount{publicstaticvoidmain(String[]args)throwsIOException{// TODO(developer): Replace the variables before running the sample.StringprojectId="your-project-id";StringserviceAccountName="my-service-account-name";deleteServiceAccount(projectId,serviceAccountName);}// Deletes a service account.publicstaticvoiddeleteServiceAccount(StringprojectId,StringserviceAccountName)throwsIOException{// Initialize client that will be used to send requests.// This client only needs to be created once, and can be reused for multiple requests.try(IAMClientclient=IAMClient.create()){StringaccountName=ServiceAccountName.of(projectId,serviceAccountName).toString();StringaccountEmail=String.format("%s@%s.iam.gserviceaccount.com",accountName,projectId);DeleteServiceAccountRequestrequest=DeleteServiceAccountRequest.newBuilder().setName(accountEmail).build();client.deleteServiceAccount(request);System.out.println("Deleted service account: "+serviceAccountName);}}}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
fromgoogle.cloudimportiam_admin_v1fromgoogle.cloud.iam_admin_v1importtypesdefdelete_service_account(project_id:str,account:str)-> None:"""Deletes a service account. project_id: ID or number of the Google Cloud project you want to use. account: ID or email which is unique identifier of the service account. """iam_admin_client=iam_admin_v1.IAMClient()request=types.DeleteServiceAccountRequest()request.name=f"projects/{project_id}/serviceAccounts/{account}"iam_admin_client.delete_service_account(request=request)print(f"Deleted a service account: {account}")
Before using any of the request data,
make the following replacements:
PROJECT_ID: Your Google Cloud project
ID. Project IDs are alphanumeric strings, like my-project.
SA_ID: The ID of your service account.
This can either be the service account's email address in the form
SA_NAME@PROJECT_ID.iam.gserviceaccount.com, or the service
account's unique numeric ID.
Open the
method reference page.
The APIs Explorer panel opens on the right side of the page.
You can interact with this tool to send requests.
Complete any required fields and click Execute.
If successful, the response body will be empty.
Undelete a service account
In some cases, you can use the undelete command to undelete a deleted service
account. You can usually undelete a deleted service account if it meets these
criteria:
The service account was deleted less than 30 days
ago.
After 30 days, IAM permanently removes
the service account. Google Cloud cannot recover the service account
after it is permanently removed, even if you file a support request.
There is no existing service account with the same name as the deleted service
account.
For example, suppose that you accidentally delete the service account
my-service-account@project-id.iam.gserviceaccount.com. You still need a
service account with that name, so you create a new service account with the
same name, my-service-account@project-id.iam.gserviceaccount.com.
The new service account does not inherit the permissions of the deleted
service account. In effect, it is completely separate from the deleted
service account. However, you cannot undelete the original service account,
because the new service account has the same name.
To address this issue, delete the new service account, then try to undelete
the original service account.
If you are not able to undelete the service account, you can create a new
service account with the same name; revoke all of the roles from the deleted
service account; and grant the same roles to the new service account. For
details, see Policies with deleted principals.
Find a deleted service account's numeric ID
When you undelete a service account, you must provide its numeric ID. The
numeric ID is a 21-digit number, such as 123456789012345678901, that uniquely
identifies the service account. For example, if you delete a service account,
then create a new service account with the same name, the original service
account and the new service account will have different numeric IDs.
If you know that a binding in an allow policy includes the deleted service
account, you can get the allow policy, then find the numeric ID
in the allow policy. The numeric ID is appended to the name of the deleted
service account. For example, in this allow policy, the numeric ID for the
deleted service account is 123456789012345678901:
In the query editor, enter the following query, replacing
SERVICE_ACCOUNT_EMAIL with the email address of your
service account (for example,
my-service-account@project-id.iam.gserviceaccount.com):
If the service account was deleted more than an hour ago, click
scheduleLast 1 hour,
select a longer period of time from the drop-down list, then click
Apply.
Click Run query. The Logs Explorer displays the DeleteServiceAccount
operations that affected service accounts with the name you specified.
Find and note the numeric ID of the deleted service account by doing one of
the following:
If the search results include only one DeleteServiceAccount operation,
find the numeric ID in the Unique ID field of the Log fields pane.
If the search results show more than one log, do the following:
Find the correct log entry. To find the correct log entry, click the
keyboard_arrow_right expander arrow
next to a log entry. Review the details of the log entry and determine
whether the log entry shows the operation that you want to undo. Repeat
this process until you find the correct log entry.
In the correct log entry, locate the service account's numeric ID. To
locate the numeric ID, expand the log entry's protoPayload field,
then find the resourceName field.
The numeric ID is everything after serviceAccounts in the resourceName
field.
Undelete the service account by numeric ID
After you find the numeric ID for the deleted service account, you can try to
undelete the service account.
gcloud
In the Google Cloud console, activate Cloud Shell.
At the bottom of the Google Cloud console, a
Cloud Shell
session starts and displays a command-line prompt. Cloud Shell is a shell environment
with the Google Cloud CLI
already installed and with values already set for
your current project. It can take a few seconds for the session to initialize.
Open the
method reference page.
The APIs Explorer panel opens on the right side of the page.
You can interact with this tool to send requests.
Complete any required fields and click Execute.
If the account can be undeleted, you receive a 200 OK response
code with details about the restored service account, like the following:
{
"restoredAccount": {
"name": "projects/my-project/serviceAccounts/my-service-account@my-project.iam.gserviceaccount.com",
"projectId": "my-project",
"uniqueId": "123456789012345678901",
"email": "my-service-account@my-project.iam.gserviceaccount.com",
"displayName": "My service account",
"etag": "BwUp3rVlzes=",
"description": "A service account for running jobs in my project",
"oauth2ClientId": "987654321098765432109"
}
}
If you're new to Google Cloud, create an account to evaluate how our
products perform in real-world scenarios. New customers also get $300 in
free credits to run, test, and deploy workloads.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-09-30 UTC."],[],[]]