> ## Documentation Index
> Fetch the complete documentation index at: https://docs-platform.crewai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Revoke a service account granted role

> Revokes an active role granted to a service account in the organization associated
with the authenticated service account. The granted role stays in the platform for
audit purposes, so this does not delete it. Later requests for it return not found.
A revoked service account can still have its roles revoked.

The authenticated service account must hold the
`organizations:manage_identity_and_access` permission. Without it the request
is forbidden, whether or not the requested granted role exists.

A service account may revoke its own granted roles, including the last one
that gives it `organizations:manage_identity_and_access`. Doing so takes
effect immediately and its later requests to this endpoint are forbidden.
To restore the permission, an organization administrator adds the service
account to the Administrators team in Settings.




## OpenAPI

````yaml /openapi/platform-v1.yaml delete /api/v1/service-accounts/{service_account_id}/granted-roles/{id}
openapi: 3.0.1
info:
  title: CrewAI Platform API
  version: v1
  description: Supported public API for CrewAI Platform.
servers:
  - url: https://app.crewai.com
    description: Current CrewAI Platform host
security:
  - bearerAuth: []
tags:
  - name: Users
    description: Users in the organization.
  - name: Status
    description: Platform health and API availability.
  - name: Automations
    description: Automations and their source artifacts.
  - name: Teams
    description: Teams in the organization.
  - name: Group Mappings
    description: Identity-provider group mappings to Teams.
  - name: Service Accounts
    description: Service accounts in the organization.
  - name: Webhook Endpoints
    description: Endpoints that receive signed event deliveries.
paths:
  /api/v1/service-accounts/{service_account_id}/granted-roles/{id}:
    parameters:
      - name: service_account_id
        in: path
        required: true
        schema:
          type: string
          format: uuid
          example: 4f6d0d9a-7b78-4c6a-b64f-2e2e3d2c8f9a
      - name: id
        in: path
        required: true
        schema:
          type: string
          format: uuid
          example: 4f6d0d9a-7b78-4c6a-b64f-2e2e3d2c8f9a
    delete:
      tags:
        - Service Accounts
      summary: Revoke a service account granted role
      description: >
        Revokes an active role granted to a service account in the organization
        associated

        with the authenticated service account. The granted role stays in the
        platform for

        audit purposes, so this does not delete it. Later requests for it return
        not found.

        A revoked service account can still have its roles revoked.


        The authenticated service account must hold the

        `organizations:manage_identity_and_access` permission. Without it the
        request

        is forbidden, whether or not the requested granted role exists.


        A service account may revoke its own granted roles, including the last
        one

        that gives it `organizations:manage_identity_and_access`. Doing so takes

        effect immediately and its later requests to this endpoint are
        forbidden.

        To restore the permission, an organization administrator adds the
        service

        account to the Administrators team in Settings.
      operationId: revokeServiceAccountGrantedRole
      responses:
        '204':
          description: No Content
        '401':
          description: Unauthorized
          content:
            application/json:
              examples:
                unauthorized:
                  value:
                    errors:
                      - type: >-
                          https://docs-platform.crewai.com/api/problems/unauthorized
                        code: unauthorized
                        title: Unauthorized
                        status: 401
                        detail: Missing or invalid bearer token.
                  summary: Missing or invalid bearer token
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '403':
          description: Forbidden
          content:
            application/json:
              examples:
                rbac_v2_disabled:
                  value:
                    errors:
                      - type: >-
                          https://docs-platform.crewai.com/api/problems/forbidden
                        code: forbidden
                        title: Forbidden
                        status: 403
                        detail: Role grants are not available for your organization.
                  summary: Role grants unavailable without RBAC v2
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '404':
          description: Not Found
          content:
            application/json:
              examples:
                not_found:
                  value:
                    errors:
                      - type: >-
                          https://docs-platform.crewai.com/api/problems/not_found
                        code: not_found
                        title: Not found
                        status: 404
                        detail: The requested resource could not be found.
                  summary: >-
                    Service account or granted role is unknown, or the granted
                    role is already revoked or held by another principal
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
components:
  schemas:
    ErrorEnvelope:
      type: object
      required:
        - errors
      additionalProperties: false
      properties:
        errors:
          type: array
          minItems: 1
          items:
            $ref: '#/components/schemas/Error'
    Error:
      type: object
      description: Public API error object.
      required:
        - type
        - code
        - title
        - status
        - detail
      additionalProperties: false
      properties:
        type:
          type: string
          format: uri
          enum:
            - https://docs-platform.crewai.com/api/problems/bad_request
            - https://docs-platform.crewai.com/api/problems/clipper_disabled
            - https://docs-platform.crewai.com/api/problems/clipper_disallowed
            - >-
              https://docs-platform.crewai.com/api/problems/clipper_feature_disabled
            - https://docs-platform.crewai.com/api/problems/clipper_not_found
            - https://docs-platform.crewai.com/api/problems/conflict
            - https://docs-platform.crewai.com/api/problems/forbidden
            - https://docs-platform.crewai.com/api/problems/internal_error
            - https://docs-platform.crewai.com/api/problems/not_found
            - https://docs-platform.crewai.com/api/problems/service_unavailable
            - >-
              https://docs-platform.crewai.com/api/problems/tool_execution_failed
            - https://docs-platform.crewai.com/api/problems/unauthorized
            - https://docs-platform.crewai.com/api/problems/validation_error
          example: https://docs-platform.crewai.com/api/problems/bad_request
        code:
          type: string
          enum:
            - bad_request
            - clipper_disabled
            - clipper_disallowed
            - clipper_feature_disabled
            - clipper_not_found
            - conflict
            - forbidden
            - internal_error
            - not_found
            - service_unavailable
            - tool_execution_failed
            - unauthorized
            - validation_error
          example: bad_request
        title:
          type: string
          x-crewai-enum-format: freeform
          enum:
            - Bad request
            - Clipper resource disabled
            - Clipper resource disallowed
            - Clipper feature disabled
            - Clipper resource not found
            - Conflict
            - Forbidden
            - Internal error
            - Not found
            - Service unavailable
            - Tool execution failed
            - Unauthorized
            - Validation error
          example: Bad request
        status:
          type: integer
          enum:
            - 400
            - 401
            - 403
            - 404
            - 409
            - 422
            - 500
            - 503
          example: 400
        detail:
          type: string
          example: The request is invalid.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: opaque

````