> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-leet-slack-mcp-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Search

> Search sign-in policies by name, or fetch a specific set by ID. Returns
 one page of matching policies at a time.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/search/sign-in-policies
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/search/sign-in-policies:
    post:
      tags:
        - Sign-In Policy
      summary: Search
      description: |-
        Search sign-in policies by name, or fetch a specific set by ID. Returns
         one page of matching policies at a time.
      operationId: c1.api.sign_in_policy.v1.SignInPolicyService.Search
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceSearchRequest
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceSearchResponse
          description: Successful response
      x-codeSamples:
        - lang: go
          label: Search
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.SignInPolicy.Search(ctx, nil)\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.SignInPolicyServiceSearchResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    c1.api.sign_in_policy.v1.SignInPolicyServiceSearchRequest:
      description: The SignInPolicyServiceSearchRequest message.
      properties:
        pageSize:
          description: The maximum number of results to return per page.
          format: int32
          type: integer
        pageToken:
          description: A pagination token from a previous Search response.
          type: string
        query:
          description: Free-text search over the policy name. Empty matches all policies.
          type: string
        refs:
          description: >-
            Restrict results to these specific policies. Empty matches all
            policies.
          items:
            $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyRef'
          type:
            - array
            - 'null'
      title: Sign In Policy Service Search Request
      type: object
      x-speakeasy-name-override: SignInPolicyServiceSearchRequest
    c1.api.sign_in_policy.v1.SignInPolicyServiceSearchResponse:
      description: The SignInPolicyServiceSearchResponse message.
      properties:
        list:
          description: The page of matching policies.
          items:
            $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy'
          type:
            - array
            - 'null'
        nextPageToken:
          description: >-
            A token to fetch the next page, or empty if there are no more
            results.
          type: string
      title: Sign In Policy Service Search Response
      type: object
      x-speakeasy-name-override: SignInPolicyServiceSearchResponse
    c1.api.sign_in_policy.v1.SignInPolicyRef:
      description: SignInPolicyRef is a lightweight reference to a sign-in policy by ID.
      properties:
        id:
          description: The id field.
          type: string
      title: Sign In Policy Ref
      type: object
      x-speakeasy-name-override: SignInPolicyRef
    c1.api.sign_in_policy.v1.SignInPolicy:
      description: SignInPolicy defines how users sign in.
      properties:
        allowedMfaTypes:
          description: >-
            The credential types accepted as a second factor. Must be a subset
            of the
             credential types their inventory policy permits.
          items:
            enum:
              - CREDENTIAL_TYPE_UNSPECIFIED
              - CREDENTIAL_TYPE_PASSKEY
              - CREDENTIAL_TYPE_PASSWORD
              - CREDENTIAL_TYPE_TOTP
              - CREDENTIAL_TYPE_EMAIL_OTP
              - CREDENTIAL_TYPE_RECOVERY_CODE
              - CREDENTIAL_TYPE_DELEGATED_GOOGLE
              - CREDENTIAL_TYPE_DELEGATED_MICROSOFT
              - CREDENTIAL_TYPE_UPSTREAM_IDP
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        allowedPrimaryTypes:
          description: >-
            The primary credential types users may sign in with. Must be a
            subset of
             the credential types their inventory policy permits.
          items:
            enum:
              - CREDENTIAL_TYPE_UNSPECIFIED
              - CREDENTIAL_TYPE_PASSKEY
              - CREDENTIAL_TYPE_PASSWORD
              - CREDENTIAL_TYPE_TOTP
              - CREDENTIAL_TYPE_EMAIL_OTP
              - CREDENTIAL_TYPE_RECOVERY_CODE
              - CREDENTIAL_TYPE_DELEGATED_GOOGLE
              - CREDENTIAL_TYPE_DELEGATED_MICROSOFT
              - CREDENTIAL_TYPE_UPSTREAM_IDP
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        createdAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        defaultOutcome:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyOutcome'
            - type: 'null'
        deletedAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        displayName:
          description: A human-readable name for the policy.
          type: string
        id:
          description: Unique identifier for the policy.
          readOnly: true
          type: string
        isBuiltin:
          description: >-
            True for built-in policies provided by ConductorOne. Built-in
            policies
             cannot be edited or deleted.
          readOnly: true
          type: boolean
        priority:
          description: >-
            When a user matches more than one policy, the policy with the
            highest
             priority applies.
          format: int32
          type: integer
        rules:
          description: The ordered rule cascade, evaluated top to bottom.
          items:
            $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyRule'
          type:
            - array
            - 'null'
        updatedAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
      title: Sign In Policy
      type: object
      x-speakeasy-entity: SignInPolicy
      x-speakeasy-name-override: SignInPolicy
    c1.api.sign_in_policy.v1.PolicyOutcome:
      description: >
        PolicyOutcome is the effect of a matched rule. Exactly one kind is set.


        This message contains a oneof named kind. Only a single field of the
        following list may be set at a time:
          - allow
          - deny
          - stepUpRequired
          - challengeRequired
          - enrollmentRequired
      properties:
        allow:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.Allow'
            - type: 'null'
        challengeRequired:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.ChallengeRequired'
            - type: 'null'
        deny:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.Deny'
            - type: 'null'
        enrollmentRequired:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.EnrollmentRequired'
            - type: 'null'
        stepUpRequired:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.StepUpRequired'
            - type: 'null'
      title: Policy Outcome
      type: object
      x-speakeasy-name-override: PolicyOutcome
    c1.api.sign_in_policy.v1.PolicyRule:
      description: >-
        PolicyRule is one rung of the ordered sign-in cascade. Rules are
        evaluated
         top to bottom; the first enforced rule whose condition matches supplies the
         outcome.
      properties:
        description:
          description: A human-readable description shown in the admin UI.
          type: string
        id:
          description: A stable identifier for the rule, surfaced in audit.
          type: string
        matchCel:
          description: >-
            A boolean condition expression evaluated against the sign-in
            context.
          type: string
        mode:
          description: Whether the rule is live, evaluated-only, or skipped.
          enum:
            - POLICY_RULE_MODE_UNSPECIFIED
            - POLICY_RULE_MODE_ENFORCE
            - POLICY_RULE_MODE_OBSERVE
            - POLICY_RULE_MODE_DISABLED
          type: string
          x-speakeasy-unknown-values: allow
        outcome:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyOutcome'
            - type: 'null'
      title: Policy Rule
      type: object
      x-speakeasy-name-override: PolicyRule
    c1.api.sign_in_policy.v1.Allow:
      description: Allow permits the sign-in.
      properties:
        floorLevel:
          description: >-
            The minimum assurance level that satisfies this rule. Required on
            enforced
             Allow rules.
          enum:
            - AUTH_LEVEL_UNSPECIFIED
            - AUTH_LEVEL_NONE
            - AUTH_LEVEL_SINGLE_FACTOR
            - AUTH_LEVEL_MULTI_FACTOR
            - AUTH_LEVEL_PHR
            - AUTH_LEVEL_PHRH
          type: string
          x-speakeasy-unknown-values: allow
      title: Allow
      type: object
      x-speakeasy-name-override: Allow
    c1.api.sign_in_policy.v1.ChallengeRequired:
      description: >-
        ChallengeRequired asks for an additional factor before the sign-in
        completes.
      properties:
        types:
          description: The credential types that may satisfy the challenge.
          items:
            enum:
              - CREDENTIAL_TYPE_UNSPECIFIED
              - CREDENTIAL_TYPE_PASSKEY
              - CREDENTIAL_TYPE_PASSWORD
              - CREDENTIAL_TYPE_TOTP
              - CREDENTIAL_TYPE_EMAIL_OTP
              - CREDENTIAL_TYPE_RECOVERY_CODE
              - CREDENTIAL_TYPE_DELEGATED_GOOGLE
              - CREDENTIAL_TYPE_DELEGATED_MICROSOFT
              - CREDENTIAL_TYPE_UPSTREAM_IDP
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
      title: Challenge Required
      type: object
      x-speakeasy-name-override: ChallengeRequired
    c1.api.sign_in_policy.v1.Deny:
      description: Deny rejects the sign-in.
      properties:
        reasonAdmin:
          description: Reason shown in admin-only audit.
          type: string
        reasonUser:
          description: Reason safe to show the end user.
          type: string
      title: Deny
      type: object
      x-speakeasy-name-override: Deny
    c1.api.sign_in_policy.v1.EnrollmentRequired:
      description: >-
        EnrollmentRequired tells the user to enroll a credential before
        continuing.
      properties:
        credentialTypes:
          description: >-
            The credential types the user may enroll. Empty means "complete
            identity
             verification first".
          items:
            enum:
              - CREDENTIAL_TYPE_UNSPECIFIED
              - CREDENTIAL_TYPE_PASSKEY
              - CREDENTIAL_TYPE_PASSWORD
              - CREDENTIAL_TYPE_TOTP
              - CREDENTIAL_TYPE_EMAIL_OTP
              - CREDENTIAL_TYPE_RECOVERY_CODE
              - CREDENTIAL_TYPE_DELEGATED_GOOGLE
              - CREDENTIAL_TYPE_DELEGATED_MICROSOFT
              - CREDENTIAL_TYPE_UPSTREAM_IDP
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
      title: Enrollment Required
      type: object
      x-speakeasy-name-override: EnrollmentRequired
    c1.api.sign_in_policy.v1.StepUpRequired:
      description: >-
        StepUpRequired demands a stronger re-authentication before access is
        granted.
      properties:
        level:
          description: The assurance level the step-up must reach.
          enum:
            - AUTH_LEVEL_UNSPECIFIED
            - AUTH_LEVEL_NONE
            - AUTH_LEVEL_SINGLE_FACTOR
            - AUTH_LEVEL_MULTI_FACTOR
            - AUTH_LEVEL_PHR
            - AUTH_LEVEL_PHRH
          type: string
          x-speakeasy-unknown-values: allow
        maxAgeSeconds:
          description: How fresh the step-up must be, in seconds.
          format: int32
          type: integer
        types:
          description: The credential types that may satisfy the step-up.
          items:
            enum:
              - CREDENTIAL_TYPE_UNSPECIFIED
              - CREDENTIAL_TYPE_PASSKEY
              - CREDENTIAL_TYPE_PASSWORD
              - CREDENTIAL_TYPE_TOTP
              - CREDENTIAL_TYPE_EMAIL_OTP
              - CREDENTIAL_TYPE_RECOVERY_CODE
              - CREDENTIAL_TYPE_DELEGATED_GOOGLE
              - CREDENTIAL_TYPE_DELEGATED_MICROSOFT
              - CREDENTIAL_TYPE_UPSTREAM_IDP
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
      title: Step Up Required
      type: object
      x-speakeasy-name-override: StepUpRequired
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````