List and edit service accounts
Stay organized with collections
Save and categorize content based on your preferences.
This page explains how to list and edit service accounts using the
Identity and Access Management (IAM) API, the Google Cloud console, and the gcloud command-
line tool.
Before you begin
Enable the IAM API, if it is not already enabled.
Roles required to enable APIs
To enable APIs, you need the serviceusage.services.enable permission. If you
created the project, then you likely already have this permission through the
Owner role (roles/owner). Otherwise, you can get this permission through the
Service Usage Admin role (roles/serviceusage.serviceUsageAdmin).
Learn how to grant roles.
At the bottom of the Google Cloud console, a
Cloud Shell
session starts and displays a command-line prompt. Cloud Shell is a shell environment
with the Google Cloud CLI
already installed and with values already set for
your current project. It can take a few seconds for the session to initialize.
C#
To use the .NET samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the C++ samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the Go samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the Java samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the Python samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
IAM basic roles also contain permissions to manage service
accounts.
You should not grant basic roles in a production environment, but you can grant them in a
development or test environment.
Listing service accounts
You can list the user-managed service accounts in a project
to help you audit service accounts and keys, or as part of a custom tool for
managing service accounts.
You can't list the service agents that might appear in your
project's allow policy and audit logs. Service agents aren't located in your
project, and you can't access them directly.
Console
In the Google Cloud console, go to the Service accounts page.
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
import("context""fmt""io"iam"google.golang.org/api/iam/v1")// listServiceAccounts lists a project's service accounts.funclistServiceAccounts(wio.Writer,projectIDstring)([]*iam.ServiceAccount,error){ctx:=context.Background()service,err:=iam.NewService(ctx)iferr!=nil{returnnil,fmt.Errorf("iam.NewService: %w",err)}response,err:=service.Projects.ServiceAccounts.List("projects/"+projectID).Do()iferr!=nil{returnnil,fmt.Errorf("Projects.ServiceAccounts.List: %w",err)}for_,account:=rangeresponse.Accounts{fmt.Fprintf(w,"Listing service account: %v\n",account.Name)}returnresponse.Accounts,nil}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
importcom.google.cloud.iam.admin.v1.IAMClient;importcom.google.iam.admin.v1.ServiceAccount;importjava.io.IOException;publicclassListServiceAccounts{publicstaticvoidmain(String[]args)throwsIOException{// TODO(Developer): Replace the below variables before running.StringprojectId="your-project-id";listServiceAccounts(projectId);}// Lists all service accounts for the current project.publicstaticIAMClient.ListServiceAccountsPagedResponselistServiceAccounts(StringprojectId)throwsIOException{// Initialize client that will be used to send requests.// This client only needs to be created once, and can be reused for multiple requests.try(IAMClientiamClient=IAMClient.create()){IAMClient.ListServiceAccountsPagedResponseresponse=iamClient.listServiceAccounts(String.format("projects/%s",projectId));for(ServiceAccountaccount:response.iterateAll()){System.out.println("Name: "+account.getName());System.out.println("Display name: "+account.getDisplayName());System.out.println("Email: "+account.getEmail()+"\n");}returnresponse;}}}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
fromtypingimportListfromgoogle.cloudimportiam_admin_v1fromgoogle.cloud.iam_admin_v1importtypesdeflist_service_accounts(project_id:str)-> List[iam_admin_v1.ServiceAccount]:"""Get list of project service accounts. project_id: ID or number of the Google Cloud project you want to use. returns a list of iam_admin_v1.ServiceAccount """iam_admin_client=iam_admin_v1.IAMClient()request=types.ListServiceAccountsRequest()request.name=f"projects/{project_id}"accounts=iam_admin_client.list_service_accounts(request=request)returnaccounts.accounts
REST
The
serviceAccounts.list
method lists every user-managed service account in the specified project.
Before using any of the request data,
make the following replacements:
PROJECT_ID: Your Google Cloud project
ID. Project IDs are alphanumeric strings, like my-project.
HTTP method and URL:
GET https://iam.googleapis.com/v1/projects/PROJECT_ID/serviceAccounts
To send your request, expand one of these options:
Open the
method reference page.
The APIs Explorer panel opens on the right side of the page.
You can interact with this tool to send requests.
Complete any required fields and click Execute.
You should receive a JSON response similar to the following:
{
"accounts": [
{
"name": "projects/my-project/serviceAccounts/sa-1@my-project.iam.gserviceaccount.com",
"projectId": "my-project",
"uniqueId": "123456789012345678901",
"email": "sa-1@my-project.iam.gserviceaccount.com",
"description": "My first service account",
"displayName": "Service account 1",
"etag": "BwUpTsLVUkQ=",
"oauth2ClientId": "987654321098765432109"
},
{
"name": "projects/my-project/serviceAccounts/sa-2@my-project.iam.gserviceaccount.com",
"projectId": "my-project",
"uniqueId": "234567890123456789012",
"email": "sa-2@my-project.iam.gserviceaccount.com",
"description": "My second service account",
"displayName": "Service account 2",
"etag": "UkQpTwBVUsL=",
"oauth2ClientId": "876543210987654321098"
}
]
}
Edit a service account
The display name (friendly name) and description of a service account are
commonly used to capture additional information about the service account, such
as the purpose of the service account or a contact person for the account.
Console
In the Google Cloud console, go to the Service accounts page.
Before using any of the command data below,
make the following replacements:
SA_NAME: The alphanumeric ID of your
service account. This name must be between 6 and 30 characters, and can contain lowercase
alphanumeric characters and dashes.
PROJECT_ID: Your Google Cloud project
ID. Project IDs are alphanumeric strings, like my-project.
Replace at least one of the following:
UPDATED_DISPLAY_NAME: A new display name for your service
account.
UPDATED_DESCRIPTION: A new description for your service
account.
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
usingSystem;usingGoogle.Apis.Auth.OAuth2;usingGoogle.Apis.Iam.v1;usingGoogle.Apis.Iam.v1.Data;publicpartialclassServiceAccounts{publicstaticServiceAccountRenameServiceAccount(stringemail,stringnewDisplayName){varcredential=GoogleCredential.GetApplicationDefault().CreateScoped(IamService.Scope.CloudPlatform);varservice=newIamService(newIamService.Initializer{HttpClientInitializer=credential});// First, get a ServiceAccount using List() or Get().stringresource="projects/-/serviceAccounts/"+email;varserviceAccount=service.Projects.ServiceAccounts.Get(resource).Execute();// Then you can update the display name.serviceAccount.DisplayName=newDisplayName;serviceAccount=service.Projects.ServiceAccounts.Update(serviceAccount,resource).Execute();Console.WriteLine($"Updated display name for {serviceAccount.Email} "+"to: "+serviceAccount.DisplayName);returnserviceAccount;}}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
import("context""fmt""io"iam"google.golang.org/api/iam/v1")// renameServiceAccount renames a service account.funcrenameServiceAccount(wio.Writer,email,newDisplayNamestring)(*iam.ServiceAccount,error){ctx:=context.Background()service,err:=iam.NewService(ctx)iferr!=nil{returnnil,fmt.Errorf("iam.NewService: %w",err)}// First, get a ServiceAccount using List() or Get().resource:="projects/-/serviceAccounts/"+emailserviceAccount,err:=service.Projects.ServiceAccounts.Get(resource).Do()iferr!=nil{returnnil,fmt.Errorf("Projects.ServiceAccounts.Get: %w",err)}// Then you can update the display name.serviceAccount.DisplayName=newDisplayNameserviceAccount,err=service.Projects.ServiceAccounts.Update(resource,serviceAccount).Do()iferr!=nil{returnnil,fmt.Errorf("Projects.ServiceAccounts.Update: %w",err)}fmt.Fprintf(w,"Updated service account: %v",serviceAccount.Email)returnserviceAccount,nil}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
importcom.google.cloud.iam.admin.v1.IAMClient;importcom.google.iam.admin.v1.GetServiceAccountRequest;importcom.google.iam.admin.v1.PatchServiceAccountRequest;importcom.google.iam.admin.v1.ServiceAccount;importcom.google.iam.admin.v1.ServiceAccountName;importcom.google.protobuf.FieldMask;importjava.io.IOException;publicclassRenameServiceAccount{publicstaticvoidmain(String[]args)throwsIOException{// TODO(developer): Replace the variables before running the sample.StringprojectId="your-project-id";StringserviceAccountName="my-service-account-name";StringdisplayName="your-new-display-name";renameServiceAccount(projectId,serviceAccountName,displayName);}// Changes a service account's display name.publicstaticServiceAccountrenameServiceAccount(StringprojectId,StringserviceAccountName,StringdisplayName)throwsIOException{// Construct the service account email.// You can modify the ".iam.gserviceaccount.com" to match the service account name in which// you want to delete the key.// See, https://cloud.google.com/iam/docs/creating-managing-service-account-keys?hl=en#deletingStringserviceAccountEmail=serviceAccountName+"@"+projectId+".iam.gserviceaccount.com";// Initialize client that will be used to send requests.// This client only needs to be created once, and can be reused for multiple requests.try(IAMClientiamClient=IAMClient.create()){// First, get a service account using getServiceAccount or listServiceAccountsGetServiceAccountRequestserviceAccountRequest=GetServiceAccountRequest.newBuilder().setName(ServiceAccountName.of(projectId,serviceAccountEmail).toString()).build();ServiceAccountserviceAccount=iamClient.getServiceAccount(serviceAccountRequest);// You can patch only the `display_name` and `description` fields. You must use// the `update_mask` field to specify which of these fields you want to patch.serviceAccount=serviceAccount.toBuilder().setDisplayName(displayName).build();PatchServiceAccountRequestpatchServiceAccountRequest=PatchServiceAccountRequest.newBuilder().setServiceAccount(serviceAccount).setUpdateMask(FieldMask.newBuilder().addPaths("display_name").build()).build();serviceAccount=iamClient.patchServiceAccount(patchServiceAccountRequest);System.out.println("Updated display name for "+serviceAccount.getName()+" to: "+serviceAccount.getDisplayName());returnserviceAccount;}}}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
fromgoogle.cloudimportiam_admin_v1fromgoogle.cloud.iam_admin_v1importtypesdefrename_service_account(project_id:str,account:str,new_name:str)-> types.ServiceAccount:"""Renames service account display name. project_id: ID or number of the Google Cloud project you want to use. account: ID or email which is unique identifier of the service account. new_name: New display name of the service account. """iam_admin_client=iam_admin_v1.IAMClient()get_request=types.GetServiceAccountRequest()get_request.name=f"projects/{project_id}/serviceAccounts/{account}"service_account=iam_admin_client.get_service_account(request=get_request)service_account.display_name=new_namerequest=types.PatchServiceAccountRequest()request.service_account=service_account# You can patch only the `display_name` and `description` fields.# You must use the `update_mask` field to specify which of these fields# you want to patch.# To successfully set update mask you need to transform# snake_case field to camelCase.# e.g. `display_name` will become `displayName`request.update_mask="displayName"updated_account=iam_admin_client.patch_service_account(request=request)returnupdated_account
Before using any of the request data,
make the following replacements:
PROJECT_ID: Your Google Cloud project
ID. Project IDs are alphanumeric strings, like my-project.
SA_ID: The ID of your service account.
This can either be the service account's email address in the form
SA_NAME@PROJECT_ID.iam.gserviceaccount.com, or the service
account's unique numeric ID.
SA_NAME: The alphanumeric ID of your
service account. This name must be between 6 and 30 characters, and can contain lowercase
alphanumeric characters and dashes.
Replace at least one of the following:
UPDATED_DISPLAY_NAME: A new display name for your service
account.
UPDATED_DESCRIPTION: A new description for your service
account.
Copy the request body and open the
method reference page.
The APIs Explorer panel opens on the right side of the page.
You can interact with this tool to send requests.
Paste the request body in this tool, complete any other required fields, and click Execute.
You should receive a JSON response similar to the following:
{
"name": "projects/my-project/serviceAccounts/my-service-account@my-project.iam.gserviceaccount.com",
"displayName": "My updated service account",
"description": "An updated description of my service account"
}
If you're new to Google Cloud, create an account to evaluate how our
products perform in real-world scenarios. New customers also get $300 in
free credits to run, test, and deploy workloads.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-09-30 UTC."],[],[]]