> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-leet-slack-mcp-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Create

> Register a resource server (a third-party authorization server) as a
 permitted cross-app-access audience for an application. The audience must
 be unique within the application and must not equal your own tenant's
 issuer — C1 cannot be both the granting IdP and the resource server in the
 same flow.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/apps/{app_id}/xaa/resource_servers
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/apps/{app_id}/xaa/resource_servers:
    post:
      tags:
        - Cross-App Access
      summary: Create
      description: |-
        Register a resource server (a third-party authorization server) as a
         permitted cross-app-access audience for an application. The audience must
         be unique within the application and must not equal your own tenant's
         issuer — C1 cannot be both the granting IdP and the resource server in the
         same flow.
      operationId: c1.api.cross_app_access.v1.XAAResourceServerService.Create
      parameters:
        - in: path
          name: app_id
          required: true
          schema:
            description: The application this resource server fronts.
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceCreateRequestInput
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.cross_app_access.v1.XAAResourceServerServiceCreateResponse
          description: >-
            XAAResourceServerServiceCreateResponse returns the registered
            resource server.
      x-codeSamples:
        - lang: go
          label: Create
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/operations\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.XAAResourceServer.Create(ctx, operations.C1APICrossAppAccessV1XAAResourceServerServiceCreateRequest{\n        AppID: \"<id>\",\n    })\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.XAAResourceServerServiceCreateResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    c1.api.cross_app_access.v1.XAAResourceServerServiceCreateRequestInput:
      description: XAAResourceServerServiceCreateRequest registers a new resource server.
      properties:
        description:
          description: Description of the resource server.
          type: string
        disabled:
          description: >-
            When true, the resource server is registered but exchange requests
            are
             rejected.
          type: boolean
        displayName:
          description: Display name for the resource server.
          type: string
        maxGrantLifetime:
          format: duration
          type:
            - string
            - 'null'
        modifyClaimsHook:
          oneOf:
            - $ref: >-
                #/components/schemas/c1.api.cross_app_access.v1.XAAModifyClaimsHook
            - type: 'null'
        normalizedAudience:
          description: >-
            The resource authorization server's issuer identifier. Must not
            equal your
             own tenant's issuer. Normalized and immutable after creation.
          type: string
        requireProofOfPossession:
          description: When true, mint proof-of-possession-bound grants.
          type: boolean
        resourceUris:
          description: Resource identifiers this server governs (RFC 8707).
          items:
            type: string
          type:
            - array
            - 'null'
        signingAlgorithm:
          description: >-
            JWS algorithm for grants minted for this server. UNSPECIFIED uses
            the
             tenant default.
          enum:
            - XAA_SIGNING_ALGORITHM_UNSPECIFIED
            - XAA_SIGNING_ALGORITHM_EDDSA
            - XAA_SIGNING_ALGORITHM_RS256
            - XAA_SIGNING_ALGORITHM_ES256
          type: string
          x-speakeasy-unknown-values: allow
      title: Xaa Resource Server Service Create Request
      type: object
      x-speakeasy-name-override: XAAResourceServerServiceCreateRequest
    c1.api.cross_app_access.v1.XAAResourceServerServiceCreateResponse:
      description: >-
        XAAResourceServerServiceCreateResponse returns the registered resource
        server.
      properties:
        resourceServer:
          oneOf:
            - $ref: >-
                #/components/schemas/c1.api.cross_app_access.v1.XAAResourceServer
            - type: 'null'
      title: Xaa Resource Server Service Create Response
      type: object
      x-speakeasy-name-override: XAAResourceServerServiceCreateResponse
    c1.api.cross_app_access.v1.XAAModifyClaimsHook:
      description: >-
        XAAModifyClaimsHook registers a tenant Function invoked just before a
        grant
         is signed. The function may deny issuance or narrow the outgoing claims. It
         always runs blocking and fails closed: any error, timeout, or invalid result
         denies the grant.
      properties:
        commitId:
          description: |-
            Pin to a specific commit of the function. Empty uses the function's
             published commit, resolved when the resource server is saved.
          type: string
        disabled:
          description: When true, the hook is configured but not invoked.
          type: boolean
        functionId:
          description: The Function to invoke.
          type: string
      title: Xaa Modify Claims Hook
      type: object
      x-speakeasy-name-override: XAAModifyClaimsHook
    c1.api.cross_app_access.v1.XAAResourceServer:
      description: |-
        XAAResourceServer is a third-party authorization server registered as a
         permitted cross-app-access audience for one application.
      properties:
        appId:
          description: The application this resource server fronts.
          type: string
        createdAt:
          format: date-time
          type:
            - string
            - 'null'
        deletedAt:
          format: date-time
          type:
            - string
            - 'null'
        description:
          description: Description of the resource server.
          type: string
        disabled:
          description: >-
            When true, exchange requests for this resource server are rejected
            without
             removing the registration (a kill switch).
          type: boolean
        displayName:
          description: Display name for the resource server.
          type: string
        id:
          description: Unique identifier for this resource server.
          type: string
        maxGrantLifetime:
          format: duration
          type:
            - string
            - 'null'
        modifyClaimsHook:
          oneOf:
            - $ref: >-
                #/components/schemas/c1.api.cross_app_access.v1.XAAModifyClaimsHook
            - type: 'null'
        normalizedAudience:
          description: >-
            The resource authorization server's issuer identifier (RFC 8414).
            Becomes
             the audience of every grant minted for this server. Stored normalized:
             lowercase scheme and host, no trailing slash, https only. Immutable after
             creation. Must not equal your own tenant's issuer.
          type: string
        requireProofOfPossession:
          description: >-
            When true, mint proof-of-possession-bound grants for clients
            presenting a
             DPoP proof.
          type: boolean
        resourceUris:
          description: >-
            The resource identifiers this server governs (RFC 8707). An
            allowlist for
             the token-exchange resource parameter; empty rejects any request that
             carries a resource parameter.
          items:
            type: string
          type:
            - array
            - 'null'
        sectorId:
          description: |-
            Optional pairwise sector override. Empty means the resource server's
             audience is its own sector. Set to the well-known global sentinel sector to
             opt into a correlatable shared `sub`, or to a shared value to share one
             pairwise `sub` across a trust group of audiences. Immutable once set.
          type: string
        signingAlgorithm:
          description: >-
            JWS algorithm for grants minted for this server. UNSPECIFIED uses
            the
             tenant default. Minting fails if no active signing key exists for the
             resolved algorithm.
          enum:
            - XAA_SIGNING_ALGORITHM_UNSPECIFIED
            - XAA_SIGNING_ALGORITHM_EDDSA
            - XAA_SIGNING_ALGORITHM_RS256
            - XAA_SIGNING_ALGORITHM_ES256
          type: string
          x-speakeasy-unknown-values: allow
        updatedAt:
          format: date-time
          type:
            - string
            - 'null'
      title: Xaa Resource Server
      type: object
      x-speakeasy-name-override: XAAResourceServer
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````