> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-leet-slack-mcp-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Search

> Search scope bindings, filtered by access profile or by scope, or fetch a
 specific set by ref. The by-scope direction answers "which profiles
 contain this scope" for impact analysis.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/search/xaa/access_profile_scope_bindings
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/search/xaa/access_profile_scope_bindings:
    post:
      tags:
        - Cross-App Access
      summary: Search
      description: >-
        Search scope bindings, filtered by access profile or by scope, or fetch
        a
         specific set by ref. The by-scope direction answers "which profiles
         contain this scope" for impact analysis.
      operationId: c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingService.Search
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceSearchRequest
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceSearchResponse
          description: >-
            XAAAccessProfileScopeBindingServiceSearchResponse returns matching
            bindings.
      x-codeSamples:
        - lang: go
          label: Search
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.XAAAccessProfileScopeBinding.Search(ctx, nil)\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.XAAAccessProfileScopeBindingServiceSearchResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceSearchRequest:
      description: >-
        XAAAccessProfileScopeBindingServiceSearchRequest searches scope
        bindings.
      properties:
        accessProfileIds:
          description: >-
            Optional filter by access profiles. Empty matches any access
            profile.
          items:
            type: string
          type:
            - array
            - 'null'
        appId:
          description: The application that owns the resource server (required).
          type: string
        pageSize:
          description: Page size (max 100).
          format: int32
          type: integer
        pageToken:
          description: Page token for pagination.
          type: string
        refs:
          description: |-
            Optional: fetch a specific set of bindings by ref (used by websocket
             notify to re-fetch individual rows).
          items:
            $ref: >-
              #/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingRef
          type:
            - array
            - 'null'
        xaaScopeIds:
          description: |-
            Optional filter by scopes (impact analysis: which profiles contain a
             scope). Empty matches any scope.
          items:
            type: string
          type:
            - array
            - 'null'
      title: Xaa Access Profile Scope Binding Service Search Request
      type: object
      x-speakeasy-name-override: XAAAccessProfileScopeBindingServiceSearchRequest
    c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceSearchResponse:
      description: >-
        XAAAccessProfileScopeBindingServiceSearchResponse returns matching
        bindings.
      properties:
        list:
          description: Matching scope bindings.
          items:
            $ref: >-
              #/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBinding
          type:
            - array
            - 'null'
        nextPageToken:
          description: Token for the next page.
          type: string
      title: Xaa Access Profile Scope Binding Service Search Response
      type: object
      x-speakeasy-name-override: XAAAccessProfileScopeBindingServiceSearchResponse
    c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingRef:
      description: >-
        XAAAccessProfileScopeBindingRef is a lightweight reference to a binding,
        used
         for websocket notifications and search filter refs.
      properties:
        accessProfileId:
          description: The accessProfileId field.
          type: string
        appId:
          description: The appId field.
          type: string
        xaaScopeId:
          description: The xaaScopeId field.
          type: string
      title: Xaa Access Profile Scope Binding Ref
      type: object
      x-speakeasy-name-override: XAAAccessProfileScopeBindingRef
    c1.api.cross_app_access.v1.XAAAccessProfileScopeBinding:
      description: >-
        XAAAccessProfileScopeBinding is a binding between an access profile and
        a
         scope. Both ends belong to one resource server.
      properties:
        accessProfileId:
          description: The access profile end of the binding.
          type: string
        appId:
          description: The application that owns the resource server.
          type: string
        createdAt:
          format: date-time
          type:
            - string
            - 'null'
        deletedAt:
          format: date-time
          type:
            - string
            - 'null'
        updatedAt:
          format: date-time
          type:
            - string
            - 'null'
        xaaResourceServerId:
          description: The resource server both ends belong to.
          type: string
        xaaScopeId:
          description: The scope end of the binding.
          type: string
      title: Xaa Access Profile Scope Binding
      type: object
      x-speakeasy-name-override: XAAAccessProfileScopeBinding
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````