> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-muhammad-kumail-github-mcp-tab.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Search App Resources

> Search app resources based on filters specified in the request body.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/search/app_resources
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/search/app_resources:
    post:
      tags:
        - App Resource
      summary: Search App Resources
      description: Search app resources based on filters specified in the request body.
      operationId: c1.api.app.v1.AppResourceSearch.SearchAppResources
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/c1.api.app.v1.SearchAppResourcesRequest'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/c1.api.app.v1.SearchAppResourcesResponse'
          description: >-
            The SearchAppResourcesResponse message contains a list of results
            and a nextPageToken if applicable.
      x-codeSamples:
        - lang: go
          label: SearchAppResources
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.AppResourceSearch.SearchAppResources(ctx, nil)\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.SearchAppResourcesResponse != nil {\n        for {\n            // handle items\n\n            res, err = res.Next()\n\n            if err != nil {\n                // handle error\n            }\n\n            if res == nil {\n                break\n            }\n        }\n    }\n}"
        - lang: typescript
          label: Typescript (SDK)
          source: >-
            import { ConductoroneSDKTypescript } from
            "conductorone-sdk-typescript";


            const conductoroneSDKTypescript = new ConductoroneSDKTypescript({
              security: {
                bearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
                oauth: "<YOUR_OAUTH_HERE>",
              },
            });


            async function run() {
              const result = await conductoroneSDKTypescript.appResourceSearch.searchAppResources();

              for await (const page of result) {
                console.log(page);
              }
            }


            run();
components:
  schemas:
    c1.api.app.v1.SearchAppResourcesRequest:
      description: Search app resources based on filters specified in the request body.
      properties:
        agentStatuses:
          description: >-
            Restrict the search to AI-agent resources with one of the given
            agent
             lifecycle statuses (READY, DISABLED, DELETED). When empty, agent status is
             not used as a filter.
          items:
            enum:
              - AGENT_STATUS_UNSPECIFIED
              - AGENT_STATUS_READY
              - AGENT_STATUS_DISABLED
              - AGENT_STATUS_DELETED
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        appId:
          description: The app ID to restrict the search to.
          type: string
        appIds:
          description: >-
            A list of app IDs to restrict the search to. Mirrors the singular
            app_id;
             both fold into the same filter, so callers may set either or both.
          items:
            type: string
          type:
            - array
            - 'null'
        appUserIds:
          description: A list of app user IDs to restrict the search by.
          items:
            type: string
          type:
            - array
            - 'null'
        credentialTypes:
          description: >-
            Restrict the search to resources whose credential material spine
            (K1) matches
             one of the given CredentialType values. Applies to resources with a
             secret_trait. When empty, credential_type is not used as a filter.
          items:
            enum:
              - CREDENTIAL_TYPE_UNSPECIFIED
              - CREDENTIAL_TYPE_STATIC_SECRET
              - CREDENTIAL_TYPE_ASYMMETRIC_KEY
              - CREDENTIAL_TYPE_CERTIFICATE
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        direction:
          description: >-
            Direction to sort in. Unspecified falls back to ASC when sort_field
            is set.
             No defined_only validation here: protoc-gen-validate mis-resolves the
             cross-package enum name map to this file's c1.models.app.v1 import alias
             instead of c1.api.search.v1, which fails to compile. The query builder
             already treats any unrecognized value as ASC, so this is safe to omit.
          enum:
            - SORT_DIRECTION_UNSPECIFIED
            - SORT_DIRECTION_ASC
            - SORT_DIRECTION_DESC
          type: string
          x-speakeasy-unknown-values: allow
        excludeDeletedApps:
          description: When true, excludes resources belonging to soft-deleted apps.
          type: boolean
        excludeDeletedResourceBindings:
          description: If true, exclude resources whose bindings have been deleted.
          type: boolean
        excludeResourceIds:
          description: A list of resource IDs to exclude from the search results.
          items:
            type: string
          type:
            - array
            - 'null'
        excludeResourceTypeTraitIds:
          description: A list of resource type trait IDs to exclude from the search.
          items:
            type: string
          type:
            - array
            - 'null'
        nhiTypes:
          description: >-
            Restrict the search to resources whose NHI classification spine (K3)
            is one
             of the given NhiType values. When empty, nhi_type is not used as a filter.
          items:
            enum:
              - NHI_TYPE_UNSPECIFIED
              - NHI_TYPE_APP_REGISTRATION
              - NHI_TYPE_ASSUMABLE_ROLE
              - NHI_TYPE_MANAGED_IDENTITY
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        ownerUserIds:
          description: |-
            A list of C1 user IDs to filter resources by ownership. The sentinel
             value "none" matches resources with no owner. Mutually exclusive with
             unowned_only — combine "none" with real owner IDs instead of setting
             unowned_only alongside them.
          items:
            type: string
          type:
            - array
            - 'null'
        pageSize:
          description: The maximum number of results to return per page.
          format: int32
          type: integer
        pageToken:
          description: The token for fetching the next page of results.
          type: string
        query:
          description: Fuzzy search the display name of resources.
          type: string
        refs:
          description: >-
            A list of specific app resource references to restrict the search
            to.
          items:
            $ref: '#/components/schemas/c1.api.app.v1.AppResourceRef'
          type:
            - array
            - 'null'
        resourceIds:
          description: A list of resource IDs to restrict the search to.
          items:
            type: string
          type:
            - array
            - 'null'
        resourceTypeIds:
          description: A list of resource type IDs to restrict the search by.
          items:
            type: string
          type:
            - array
            - 'null'
        resourceTypeTraitIds:
          description: A list of resource type trait IDs to restrict the search by.
          items:
            type: string
          type:
            - array
            - 'null'
        secretAging:
          oneOf:
            - $ref: '#/components/schemas/c1.api.app.v1.SecretAgingFilter'
            - type: 'null'
        sortField:
          description: >-
            Column to sort by. Unspecified (0) keeps the server's default order
            (app, then display name).
          enum:
            - APP_RESOURCE_SORT_FIELD_UNSPECIFIED
            - APP_RESOURCE_SORT_FIELD_SECRET_CREATED_AT
            - APP_RESOURCE_SORT_FIELD_SECRET_EXPIRES_AT
            - APP_RESOURCE_SORT_FIELD_LAST_USED_AT
          type: string
          x-speakeasy-unknown-values: allow
        unownedOnly:
          description: >-
            When true, restrict results to resources with no ownership-v2
            primary-role
             owner. Mutually exclusive with owner_user_ids — use owner_user_ids:
             ["none"] instead if you also need to combine it with real owner IDs.
          type: boolean
        withOpenFindings:
          description: >-
            When true, restrict results to resources that have at least one open
            finding
             (index-backed EXISTS semi-join). When false/unset, results are unfiltered.
          type: boolean
      title: Search App Resources Request
      type: object
      x-speakeasy-name-override: SearchAppResourcesRequest
    c1.api.app.v1.SearchAppResourcesResponse:
      description: >-
        The SearchAppResourcesResponse message contains a list of results and a
        nextPageToken if applicable.
      properties:
        expanded:
          description: List of serialized related objects.
          items:
            additionalProperties: true
            description: >-
              Contains an arbitrary serialized message along with a @type that
              describes the type of the serialized message.
            properties:
              '@type':
                description: The type of the serialized message.
                type: string
            type: object
          type:
            - array
            - 'null'
        list:
          description: The list of app resource results.
          items:
            $ref: '#/components/schemas/c1.api.app.v1.AppResourceView'
          type:
            - array
            - 'null'
        nextPageToken:
          description: The token for fetching the next page of results.
          type: string
      title: Search App Resources Response
      type: object
      x-speakeasy-name-override: SearchAppResourcesResponse
    c1.api.app.v1.AppResourceRef:
      description: A reference to a specific app resource by its composite key.
      properties:
        appId:
          description: The ID of the app that owns the resource.
          type: string
        appResourceTypeId:
          description: The ID of the resource type that classifies this resource.
          type: string
        id:
          description: The unique ID of the app resource.
          type: string
      title: App Resource Ref
      type: object
      x-speakeasy-name-override: AppResourceRef
    c1.api.app.v1.SecretAgingFilter:
      description: >-
        SecretAgingFilter restricts a resource search to secrets
        (credential_type != 0)
         whose secret-trait timestamps fall in the given half-open ranges. Each bound is
         optional; leave one unset for an open-ended range. All set bounds are ANDed.
         Callers pass absolute timestamps (computed against their reference "now").
      properties:
        lastUsedAfter:
          format: date-time
          type:
            - string
            - 'null'
        lastUsedBefore:
          format: date-time
          type:
            - string
            - 'null'
        secretCreatedAfter:
          format: date-time
          type:
            - string
            - 'null'
        secretCreatedBefore:
          format: date-time
          type:
            - string
            - 'null'
        secretExpiresAfter:
          format: date-time
          type:
            - string
            - 'null'
        secretExpiresBefore:
          format: date-time
          type:
            - string
            - 'null'
      title: Secret Aging Filter
      type: object
      x-speakeasy-name-override: SecretAgingFilter
    c1.api.app.v1.AppResourceView:
      description: >-
        The app resource view returns an app resource with paths for items in
        the expand mask filled in when this response is returned and a request
        expand mask has "*" or "app_id" or "resource_type_id".
      properties:
        appPath:
          description: >-
            JSONPATH expression indicating the location of the App object in the
            array
          type: string
        appResource:
          oneOf:
            - $ref: '#/components/schemas/c1.api.app.v1.AppResource'
            - type: 'null'
        objectPermissions:
          oneOf:
            - $ref: '#/components/schemas/c1.api.iam.v1.ActorObjectPermissions'
            - type: 'null'
        parentResourcePath:
          description: >-
            JSONPATH expression indicating the location of the Parent Resource
            object in the array
          type: string
        parentResourceTypePath:
          description: >-
            JSONPATH expression indicating the location of the Parent Resource
            Type object in the array
          type: string
        resourceTypePath:
          description: >-
            JSONPATH expression indicating the location of the Resource Type
            object in the array
          type: string
      title: App Resource View
      type: object
      x-speakeasy-name-override: AppResourceView
    c1.api.app.v1.AppResource:
      description: >
        The app resource message is a single resource that can have
        entitlements.


        This message contains a oneof named metadata. Only a single field of the
        following list may be set at a time:
          - secretTrait
      properties:
        accessConfigId:
          description: |-
            The access config ID for this resource. May be empty.
             Must be one of the builtin access config IDs or empty.
          type: string
        agentTrait:
          oneOf:
            - $ref: '#/components/schemas/c1.api.app.v1.AgentTrait'
            - type: 'null'
        annotations:
          additionalProperties:
            type: string
          description: |-
            Bounded key/value metadata bag for IaC marking and customer tags.
             See .rfcs/object-annotations.md §2. Limits: ≤16 entries; keys 1–128
             chars matching ^[A-Za-z][A-Za-z0-9._/-]{0,127}$; values 0–256 chars
             URL-safe ASCII; total serialized ≤ 4096 bytes. Keys matching ^c1/
             are reserved.

             Well-known keys: `managed_by`, `iac_workspace`,
             `iac_resource_address`, `iac_tool_version`.

             Most AppResources are connector-synced; user-supplied annotations on
             a synced resource will be overwritten by the next sync. The
             annotations bag is most useful on user-created groups (the
             `conductorone_app_resource` TF resource).
          type: object
          x-speakeasy-terraform-plan-modifier:
            imports:
              - >-
                github.com/conductorone/terraform-provider-conductorone/internal/annotations
            schemaDefinition: annotations.PlanModifier()
        appId:
          description: The app that this resource belongs to.
          type: string
        appResourceTypeId:
          description: The resource type that this resource is.
          type: string
        createdAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        customDescription:
          description: A custom description that can be set for a resource.
          type: string
        deletedAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        description:
          description: The description set for the resource.
          type: string
        displayName:
          description: The display name for this resource.
          type: string
        externalId:
          description: >-
            The upstream product's native external ID for this resource (e.g. an
            Okta group ID).
             Populated from the connector's external ID during sync.
          readOnly: true
          type: string
        grantCount:
          description: The number of grants to this resource.
          format: int64
          type: string
        id:
          description: The id of the resource.
          type: string
        matchBatonId:
          description: The matchBatonId field.
          type: string
        nhiDetail:
          description: |-
            Axis-2 detail refining nhi_type (e.g. "aws.role.lambda"). Read-only;
             translated from the model.
          readOnly: true
          type: string
        nhiType:
          description: |-
            The NHI classification (K3 spine) for this resource. Populated for
             non-human-identity resources; UNSPECIFIED for everything else. Mirrors
             agent_trait: read-only and translated from the model enum at the API boundary.
          enum:
            - NHI_TYPE_UNSPECIFIED
            - NHI_TYPE_APP_REGISTRATION
            - NHI_TYPE_ASSUMABLE_ROLE
            - NHI_TYPE_MANAGED_IDENTITY
          readOnly: true
          type: string
          x-speakeasy-unknown-values: allow
        parentAppResourceId:
          description: >-
            The parent resource id, if this resource is a child of another
            resource.
          type: string
        parentAppResourceTypeId:
          description: >-
            The parent resource type id, if this resource is a child of another
            resource.
          type: string
        profile:
          additionalProperties: true
          readOnly: true
          type:
            - object
            - 'null'
        secretTrait:
          oneOf:
            - $ref: '#/components/schemas/c1.api.app.v1.SecretTrait'
            - type: 'null'
        updatedAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
      title: App Resource
      type: object
      x-speakeasy-entity: App Resource
      x-speakeasy-name-override: AppResource
    c1.api.iam.v1.ActorObjectPermissions:
      description: |-
        Legacy: do not use for new objects. Retained only for the existing
         AppResource / AppEntitlement / access-review consumers, which will migrate to
         c1.api.authorization.v1.ActorObjectPermissions in IGA-2331. New object views
         should reference c1.api.authorization.v1.ActorObjectPermissions instead.
      properties:
        delete:
          description: The delete field.
          type: boolean
        edit:
          description: The edit field.
          type: boolean
        extra:
          additionalProperties:
            type: boolean
          description: The extra field.
          type: object
        read:
          description: The read field.
          type: boolean
      title: Actor Object Permissions
      type: object
      x-speakeasy-name-override: ActorObjectPermissions
    c1.api.app.v1.AgentTrait:
      description: >-
        AgentTrait carries metadata for AI-agent resources surfaced in the
        Inventory.
      properties:
        identityAppUserId:
          description: >-
            The C1 app user ID of the service-account identity this agent
            authenticates as.
             Empty if the backing identity has not yet been resolved.
          type: string
        status:
          description: The agent's lifecycle status (READY, DISABLED, DELETED).
          enum:
            - AGENT_STATUS_UNSPECIFIED
            - AGENT_STATUS_READY
            - AGENT_STATUS_DISABLED
            - AGENT_STATUS_DELETED
          type: string
          x-speakeasy-unknown-values: allow
      title: Agent Trait
      type: object
      x-speakeasy-name-override: AgentTrait
    c1.api.app.v1.SecretTrait:
      description: The SecretTrait message.
      properties:
        createdByAppUserId:
          description: >-
            The AppUser id that created this credential. Read-only; resolved
            from
             the model during uplift. Distinct from identity_app_user_id (the
             holder) and from the resource's Owner (a separate assignment, not
             part of this message).
          type: string
        credentialDetail:
          description: >-
            Platform-specific credential subtype detail, finer than
            credential_type
             (e.g. "GCP service-account key"). Read-only; translated from the model.
          type: string
        identityAppUserId:
          description: The identityAppUserId field.
          type: string
        lastUsedAt:
          format: date-time
          type:
            - string
            - 'null'
        secretCreatedAt:
          format: date-time
          type:
            - string
            - 'null'
        secretExpiresAt:
          format: date-time
          type:
            - string
            - 'null'
      title: Secret Trait
      type: object
      x-speakeasy-name-override: SecretTrait
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````