> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-leet-slack-mcp-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Search

> Search client audience mappings across the tenant, filtered by resource
 server, disabled state, or text query, or fetch a specific set by ref.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/search/xaa/client_audience_mappings
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/search/xaa/client_audience_mappings:
    post:
      tags:
        - Cross-App Access
      summary: Search
      description: |-
        Search client audience mappings across the tenant, filtered by resource
         server, disabled state, or text query, or fetch a specific set by ref.
      operationId: c1.api.cross_app_access.v1.XAAClientAudienceMappingService.Search
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceSearchRequest
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceSearchResponse
          description: >-
            XAAClientAudienceMappingServiceSearchResponse returns matching
            mappings.
      x-codeSamples:
        - lang: go
          label: Search
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.XAAClientAudienceMapping.Search(ctx, nil)\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.XAAClientAudienceMappingServiceSearchResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceSearchRequest:
      description: >-
        XAAClientAudienceMappingServiceSearchRequest searches mappings with
        filters.
      properties:
        disabled:
          description: Optional filter by disabled state.
          type:
            - boolean
            - 'null'
        pageSize:
          description: Page size (max 100).
          format: int32
          type: integer
        pageToken:
          description: Page token for pagination.
          type: string
        query:
          description: >-
            Optional text query matched against client_key and
            audience_client_id.
          type: string
        refs:
          description: |-
            Optional: fetch a specific set of mappings by ref (used by websocket
             notify to re-fetch individual rows).
          items:
            $ref: >-
              #/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMappingRef
          type:
            - array
            - 'null'
        xaaResourceServerIds:
          description: >-
            Optional filter by resource servers. Empty matches any resource
            server.
          items:
            type: string
          type:
            - array
            - 'null'
      title: Xaa Client Audience Mapping Service Search Request
      type: object
      x-speakeasy-name-override: XAAClientAudienceMappingServiceSearchRequest
    c1.api.cross_app_access.v1.XAAClientAudienceMappingServiceSearchResponse:
      description: XAAClientAudienceMappingServiceSearchResponse returns matching mappings.
      properties:
        list:
          description: Matching mappings.
          items:
            $ref: >-
              #/components/schemas/c1.api.cross_app_access.v1.XAAClientAudienceMapping
          type:
            - array
            - 'null'
        nextPageToken:
          description: Token for the next page.
          type: string
      title: Xaa Client Audience Mapping Service Search Response
      type: object
      x-speakeasy-name-override: XAAClientAudienceMappingServiceSearchResponse
    c1.api.cross_app_access.v1.XAAClientAudienceMappingRef:
      description: >-
        XAAClientAudienceMappingRef is a lightweight reference to a mapping,
        used for
         websocket notifications and search filter refs.
      properties:
        clientKey:
          description: The clientKey field.
          type: string
        xaaResourceServerId:
          description: The xaaResourceServerId field.
          type: string
      title: Xaa Client Audience Mapping Ref
      type: object
      x-speakeasy-name-override: XAAClientAudienceMappingRef
    c1.api.cross_app_access.v1.XAAClientAudienceMapping:
      description: |-
        XAAClientAudienceMapping maps a client to its identifier at one resource
         server. Never stores credential material.
      properties:
        audienceClientId:
          description: >-
            The client's identifier at the resource authorization server.
            Stamped
             verbatim into the grant's client_id claim.
          type: string
        clientKey:
          description: |-
            Stable client registration key. One of: a DCR software_id form
             (dcr://<software_id>), a CIMD client_id URL, a native C1 form
             (c1://<service_principal_id>), or a raw client_id.
          type: string
        createdAt:
          format: date-time
          type:
            - string
            - 'null'
        deletedAt:
          format: date-time
          type:
            - string
            - 'null'
        disabled:
          description: >-
            When true, exchange requests from this client for this resource
            server are
             rejected without removing the mapping (a kill switch).
          type: boolean
        updatedAt:
          format: date-time
          type:
            - string
            - 'null'
        xaaResourceServerId:
          description: The resource server this mapping applies to.
          type: string
      title: Xaa Client Audience Mapping
      type: object
      x-speakeasy-name-override: XAAClientAudienceMapping
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````