Help Center/ Organizations/ API Reference/ APIs/ Managing Policies/ Listing Delegated Administrator Accounts
Updated on 2026-07-29 GMT+08:00

Listing Delegated Administrator Accounts

Function

This API is used to list the accounts that are designated as delegated administrators in an organization. It can be called only from the organization's management account or from a member account that is a delegated administrator for a cloud service.

Debugging

You can debug this API through automatic authentication in API Explorer or use the SDK sample code generated by API Explorer.

Authorization Information

Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.

  • If you are using role/policy-based authorization, see Permissions Policies and Supported Actions for details on the required permissions.
  • If you are using identity policy-based authorization, the following identity policy-based permissions are required.

    Action

    Access Level

    Resource Type (*: required)

    Condition Key

    Alias

    Dependencies

    organizations:delegatedAdministrators:list

    List

    -

    organizations:ServicePrincipal

    -

    -

URI

GET /v1/organizations/delegated-administrators

Table 1 Query Parameters

Parameter

Mandatory

Type

Description

service_principal

No

String

Definition

Name of a service principal.

Constraints

Mandatory

Range

None

Default Value

None

limit

No

Integer

Maximum number of results on the page. If the limit is not specified, the default value is 1,000.

marker

No

String

Definition

Pagination marker.

Constraints

N/A

Range

The value must comply with the regular expression ^[A-Za-z0-9+/=-_.]+$.

The value contains 4 to 400 characters.

Default Value

No default value

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

X-Security-Token

No

String

Definition

Security token (session token) of your temporary security credentials. If a temporary security credential is used, this header is required.

Constraints

N/A

Range

The value contains 0 to 32,768 characters.

Default Value

No default value

Response Parameters

Status code: 200

Table 3 Response body parameters

Parameter

Type

Description

delegated_administrators

Array of DelegatedAdministratorDto objects

Definition

List of delegated administrators in an organization.

Constraints

Mandatory

Range

N/A

Default Value

No default value

page_info

PageInfoDto object

Definition

Pagination information.

Constraints

N/A

Range

N/A

Default Value

No default value

Table 4 DelegatedAdministratorDto

Parameter

Type

Description

delegation_enabled_at

String

Definition

Date when the account was designated as a delegated administrator.

Constraints

Mandatory

Range

The value must be in ISO 8601 format.

Default Value

No default value

account_id

String

Definition

Unique ID of an account.

Constraints

Mandatory

Range

The value must comply with the regular expression ^[\w-]+$.

The value contains a maximum of 64 characters.

Default Value

No default value

account_urn

String

Definition

Uniform resource name of an account.

Constraints

Mandatory

Range

The value contains a maximum of 1,500 characters.

Default Value

No default value

join_method

String

Definition

How an account joined an organization. The value can be invited (an account can be invited to join an organization) or created (an account can be directly created in an organization).

Constraints

Mandatory

Range

The value contains 1 to 64 characters.

Default Value

No default value

joined_at

String

Definition

Date when an account became a part of an organization.

Constraints

Mandatory

Range

The value must be in ISO 8601 format.

Default Value

No default value

account_name

String

Definition

Account name.

Constraints

Mandatory

Range

The value must comply with the regular expression ^[a-zA-Z][0-9a-zA-Z_-]+$.

The value contains a maximum of 64 characters.

Default Value

No default value

Table 5 PageInfoDto

Parameter

Type

Description

next_marker

String

Definition

Marker for the next set of results. If present, more output is available than is included in the current response. Use this value in the marker request parameter in a subsequent call to the operation to get the next part of the output. You should repeat this until the next_marker response element comes back as null.

Constraints

Mandatory

Range

The value must comply with the regular expression ^[A-Za-z0-9+/=-_]+$.

Default Value

No default value

current_count

Integer

Definition

Number of records returned on this page.

Constraints

N/A

Range

The value ranges from 1 to 2000.

Default Value

No default value

Example Requests

Listing delegated administrator accounts

GET https://{endpoint}/v1/organizations/delegated-administrators

Example Responses

Status code: 200

Successful.

{
  "delegated_administrators" : [ {
    "delegation_enabled_at" : "2022-08-24T06:41:15Z",
    "account_id" : "0a6d25d23900d45c0faac010e0fb4de0",
    "account_urn" : "urnstring",
    "join_method" : "invited",
    "joined_at" : "2022-08-24T06:41:15Z",
    "account_name" : "paas_iam_573331"
  } ],
  "page_info" : {
    "next_marker" : "ou-taowxgy4xbme6m4x3c2iijbxw7yj8fcw",
    "current_count" : 100
  }
}

Status Codes

Status Code

Description

200

Successful.

Error Codes

See Error Codes.