> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-leet-slack-mcp-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Search

> Search scopes across the tenant, filtered by resource server, state,
 classification, source, or text query, or fetch a specific set by ref.
 Filter on PENDING_REVIEW to find scopes awaiting approval.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/search/xaa/scopes
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/search/xaa/scopes:
    post:
      tags:
        - Cross-App Access
      summary: Search
      description: |-
        Search scopes across the tenant, filtered by resource server, state,
         classification, source, or text query, or fetch a specific set by ref.
         Filter on PENDING_REVIEW to find scopes awaiting approval.
      operationId: c1.api.cross_app_access.v1.XAAScopeService.Search
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceSearchRequest
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceSearchResponse
          description: XAAScopeServiceSearchResponse returns matching scopes.
      x-codeSamples:
        - lang: go
          label: Search
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.XAAScope.Search(ctx, nil)\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.XAAScopeServiceSearchResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    c1.api.cross_app_access.v1.XAAScopeServiceSearchRequest:
      description: XAAScopeServiceSearchRequest searches scopes with filters.
      properties:
        appIds:
          description: Optional filter by applications. Empty matches any application.
          items:
            type: string
          type:
            - array
            - 'null'
        classificationFilter:
          description: Optional filter by classification. UNSPECIFIED means no filter.
          items:
            enum:
              - XAA_SCOPE_CLASSIFICATION_UNSPECIFIED
              - XAA_SCOPE_CLASSIFICATION_READ
              - XAA_SCOPE_CLASSIFICATION_WRITE
              - XAA_SCOPE_CLASSIFICATION_DESTRUCTIVE
              - XAA_SCOPE_CLASSIFICATION_SENSITIVE
              - XAA_SCOPE_CLASSIFICATION_DANGEROUS
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        pageSize:
          description: Page size (max 100).
          format: int32
          type: integer
        pageToken:
          description: Page token for pagination.
          type: string
        query:
          description: Optional text query matched against scope_value and display_name.
          type: string
        refs:
          description: >-
            Optional: fetch a specific set of scopes by ref (used by websocket
            notify
             to re-fetch individual rows).
          items:
            $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScopeRef'
          type:
            - array
            - 'null'
        sourceFilter:
          description: Optional filter by source. UNSPECIFIED means no filter.
          items:
            enum:
              - XAA_SCOPE_SOURCE_UNSPECIFIED
              - XAA_SCOPE_SOURCE_ADMIN_DECLARED
              - XAA_SCOPE_SOURCE_DISCOVERED
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        stateFilter:
          description: Optional filter by state. UNSPECIFIED means no filter.
          items:
            enum:
              - XAA_SCOPE_STATE_UNSPECIFIED
              - XAA_SCOPE_STATE_PENDING_REVIEW
              - XAA_SCOPE_STATE_ENABLED
              - XAA_SCOPE_STATE_DISABLED
              - XAA_SCOPE_STATE_REMOVED
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        xaaResourceServerIds:
          description: >-
            Optional filter by resource servers. Empty matches any resource
            server.
          items:
            type: string
          type:
            - array
            - 'null'
      title: Xaa Scope Service Search Request
      type: object
      x-speakeasy-name-override: XAAScopeServiceSearchRequest
    c1.api.cross_app_access.v1.XAAScopeServiceSearchResponse:
      description: XAAScopeServiceSearchResponse returns matching scopes.
      properties:
        list:
          description: Matching scopes.
          items:
            $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScope'
          type:
            - array
            - 'null'
        nextPageToken:
          description: Token for the next page.
          type: string
      title: Xaa Scope Service Search Response
      type: object
      x-speakeasy-name-override: XAAScopeServiceSearchResponse
    c1.api.cross_app_access.v1.XAAScopeRef:
      description: |-
        XAAScopeRef is a lightweight reference to a scope, used for websocket
         notifications and search filter refs.
      properties:
        appId:
          description: The appId field.
          type: string
        id:
          description: The id field.
          type: string
      title: Xaa Scope Ref
      type: object
      x-speakeasy-name-override: XAAScopeRef
    c1.api.cross_app_access.v1.XAAScope:
      description: >-
        XAAScope is a single OAuth scope exposed by a resource server, elevated
        into
         a governable object bound to its own entitlement.
      properties:
        appEntitlementId:
          description: The AppEntitlement created for this scope.
          type: string
        appId:
          description: The application that owns the resource server.
          type: string
        classification:
          description: Risk classification.
          enum:
            - XAA_SCOPE_CLASSIFICATION_UNSPECIFIED
            - XAA_SCOPE_CLASSIFICATION_READ
            - XAA_SCOPE_CLASSIFICATION_WRITE
            - XAA_SCOPE_CLASSIFICATION_DESTRUCTIVE
            - XAA_SCOPE_CLASSIFICATION_SENSITIVE
            - XAA_SCOPE_CLASSIFICATION_DANGEROUS
          type: string
          x-speakeasy-unknown-values: allow
        createdAt:
          format: date-time
          type:
            - string
            - 'null'
        deletedAt:
          format: date-time
          type:
            - string
            - 'null'
        description:
          description: Description of what the scope grants.
          type: string
        displayName:
          description: Display name for the scope.
          type: string
        id:
          description: Unique identifier for this scope.
          type: string
        lastDiscoveredAt:
          format: date-time
          type:
            - string
            - 'null'
        scopeValue:
          description: >-
            The literal OAuth scope string minted into the grant. Immutable
            after
             creation (RFC 6749 charset, max 256 bytes).
          type: string
        source:
          description: How C1 learned of the scope.
          enum:
            - XAA_SCOPE_SOURCE_UNSPECIFIED
            - XAA_SCOPE_SOURCE_ADMIN_DECLARED
            - XAA_SCOPE_SOURCE_DISCOVERED
          type: string
          x-speakeasy-unknown-values: allow
        state:
          description: Approval/lifecycle state.
          enum:
            - XAA_SCOPE_STATE_UNSPECIFIED
            - XAA_SCOPE_STATE_PENDING_REVIEW
            - XAA_SCOPE_STATE_ENABLED
            - XAA_SCOPE_STATE_DISABLED
            - XAA_SCOPE_STATE_REMOVED
          type: string
          x-speakeasy-unknown-values: allow
        updatedAt:
          format: date-time
          type:
            - string
            - 'null'
        xaaResourceServerId:
          description: The resource server this scope belongs to.
          type: string
      title: Xaa Scope
      type: object
      x-speakeasy-name-override: XAAScope
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````