Skip to content
API Reference

List delegated grants

zones.delegated_grants.list(strzone_id, DelegatedGrantListParams**kwargs) -> DelegatedGrantListResponse
GET/zones/{zoneId}/delegated-grants

Returns a list of delegated grants in the specified zone. Can be filtered by user, resource, or status.

ParametersExpand Collapse
zone_id: str
active: Optional[Literal["true"]]
after: Optional[str]

Cursor for forward pagination

minLength1
maxLength255
before: Optional[str]

Cursor for backward pagination

minLength1
maxLength255
expand: Optional[Union[Literal["total_count"], List[Literal["total_count"]]]]
Accepts one of the following:
Literal["total_count"]
List[Literal["total_count"]]
limit: Optional[int]

Maximum number of items to return

minimum1
maximum100
resource_id: Optional[str]

Filter by resource ID

status: Optional[Literal["active", "expired", "revoked"]]
Accepts one of the following:
"active"
"expired"
"revoked"
user_id: Optional[str]

Filter by user ID

ReturnsExpand Collapse
class DelegatedGrantListResponse:
items: List[Grant]
id: str

Unique identifier of the delegated grant

created_at: datetime

Entity creation timestamp

formatdate-time
expires_at: datetime

Date when grant expires

formatdate-time
organization_id: str

Organization that owns this grant

provider_id: str

ID of the provider that issued this grant

refresh_token_set: bool

Indicates whether a refresh token is stored for this grant. Grants with refresh tokens can be refreshed even after access token expiration.

resource_id: str

ID of resource receiving grant

scopes: List[str]

Granted OAuth scopes

status: Literal["active", "expired", "revoked"]
Accepts one of the following:
"active"
"expired"
"revoked"
updated_at: datetime

Entity update timestamp

formatdate-time
user_id: str

Reference to the user granting permission

zone_id: str

Zone this grant belongs to

Deprecatedactive: Optional[bool]

Whether the grant is currently active (deprecated - use status instead)

Deprecatedprovider: Optional[Provider]

A Provider is a system that supplies access to Resources and allows actors (Users or Applications) to authenticate.

id: str

Unique identifier of the provider

created_at: datetime

Entity creation timestamp

formatdate-time
identifier: str

User specified identifier, unique within the zone

minLength1
maxLength2048
name: str

Human-readable name

minLength1
maxLength255
organization_id: str

Organization that owns this provider

owner_type: Literal["platform", "customer"]

Who owns this provider. Platform-owned providers cannot be modified via API.

Accepts one of the following:
"platform"
"customer"
slug: str

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: datetime

Entity update timestamp

formatdate-time
zone_id: str

Zone this provider belongs to

client_id: Optional[str]

OAuth 2.0 client identifier

client_secret_set: Optional[bool]

Indicates whether a client secret is configured

description: Optional[str]

Human-readable description

maxLength2048
metadata: Optional[object]

Provider metadata

protocols: Optional[Protocols]

Protocol-specific configuration

oauth2: Optional[ProtocolsOauth2]

OAuth 2.0 protocol configuration

issuer: str

OIDC issuer URL used for discovery and token validation.

formaturi
authorization_endpoint: Optional[str]
formaturi
authorization_parameters: Optional[Dict[str, str]]

Custom query parameters appended to authorization redirect URLs. Use for non-standard providers (e.g. Google prompt=consent, access_type=offline).

authorization_resource_enabled: Optional[bool]

Whether to include the resource parameter in authorization requests.

authorization_resource_parameter: Optional[str]

The resource parameter value to include in authorization requests. Defaults to "resource" when authorization_resource_enabled is true.

code_challenge_methods_supported: Optional[List[str]]
jwks_uri: Optional[str]
formaturi
registration_endpoint: Optional[str]
formaturi
scope_parameter: Optional[str]

The query parameter name for scopes in authorization requests. Defaults to "scope". Slack v2 uses "user_scope".

scope_separator: Optional[str]

The separator character for scope values. Defaults to " " (space). Slack v2 uses ",".

scopes_supported: Optional[List[str]]
token_endpoint: Optional[str]
formaturi
token_response_access_token_pointer: Optional[str]

Dot-separated path to the access token in the token response body. Defaults to "access_token". Slack v2 uses "authed_user.access_token".

openid: Optional[ProtocolsOpenid]

OpenID Connect protocol configuration

userinfo_endpoint: Optional[str]
formaturi
type: Optional[Literal["external", "keycard-vault", "keycard-sts"]]
Accepts one of the following:
"external"
"keycard-vault"
"keycard-sts"
refreshed_at: Optional[datetime]

Timestamp when this grant's tokens were last refreshed. Omitted if grant was never refreshed.

formatdate-time
Deprecatedresource: Optional[Resource]

A Resource is a system that exposes protected information or functionality. It requires authentication of the requesting actor, which may be a user or application, before allowing access.

id: str

Unique identifier of the resource

application_type: Literal["native", "web"]

The expected type of client for this credential. Native clients must use localhost URLs for redirect_uris or URIs with custom schemes. Web clients must use https URLs and must not use localhost as the hostname.

Accepts one of the following:
"native"
"web"
created_at: datetime

Entity creation timestamp

formatdate-time
identifier: str

User specified identifier, unique within the zone

minLength1
maxLength2048
name: str

Human-readable name

minLength1
maxLength255
organization_id: str

Organization that owns this resource

owner_type: Literal["platform", "customer"]

Who owns this resource. Platform-owned resources cannot be modified via API.

Accepts one of the following:
"platform"
"customer"
slug: str

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: datetime

Entity update timestamp

formatdate-time
zone_id: str

Zone this resource belongs to

Deprecatedapplication: Optional[Application]

An Application is a software system with an associated identity that can access Resources. It may act on its own behalf (machine-to-machine) or on behalf of a user (delegated access).

id: str

Unique identifier of the application

created_at: datetime

Entity creation timestamp

formatdate-time
dependencies_count: int

Number of resource dependencies

identifier: str

User specified identifier, unique within the zone

minLength1
maxLength2048
name: str

Human-readable name

minLength1
maxLength255
organization_id: str

Organization that owns this application

owner_type: Literal["platform", "customer"]

Who owns this application. Platform-owned applications cannot be modified via API.

Accepts one of the following:
"platform"
"customer"
slug: str

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: datetime

Entity update timestamp

formatdate-time
zone_id: str

Zone this application belongs to

description: Optional[str]

Human-readable description

maxLength2048
metadata: Optional[Metadata]

Entity metadata

docs_url: Optional[str]

Documentation URL

formaturi
maxLength2048
protocols: Optional[Protocols]

Protocol-specific configuration

oauth2: Optional[ProtocolsOauth2]

OAuth 2.0 protocol configuration

post_logout_redirect_uris: Optional[List[str]]

OAuth 2.0 post-logout redirect URIs for this application

redirect_uris: Optional[List[str]]

OAuth 2.0 redirect URIs for this application

application_id: Optional[str]

ID of the application that provides this resource

Deprecatedcredential_provider: Optional[Provider]

A Provider is a system that supplies access to Resources and allows actors (Users or Applications) to authenticate.

id: str

Unique identifier of the provider

created_at: datetime

Entity creation timestamp

formatdate-time
identifier: str

User specified identifier, unique within the zone

minLength1
maxLength2048
name: str

Human-readable name

minLength1
maxLength255
organization_id: str

Organization that owns this provider

owner_type: Literal["platform", "customer"]

Who owns this provider. Platform-owned providers cannot be modified via API.

Accepts one of the following:
"platform"
"customer"
slug: str

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: datetime

Entity update timestamp

formatdate-time
zone_id: str

Zone this provider belongs to

client_id: Optional[str]

OAuth 2.0 client identifier

client_secret_set: Optional[bool]

Indicates whether a client secret is configured

description: Optional[str]

Human-readable description

maxLength2048
metadata: Optional[object]

Provider metadata

protocols: Optional[Protocols]

Protocol-specific configuration

oauth2: Optional[ProtocolsOauth2]

OAuth 2.0 protocol configuration

issuer: str

OIDC issuer URL used for discovery and token validation.

formaturi
authorization_endpoint: Optional[str]
formaturi
authorization_parameters: Optional[Dict[str, str]]

Custom query parameters appended to authorization redirect URLs. Use for non-standard providers (e.g. Google prompt=consent, access_type=offline).

authorization_resource_enabled: Optional[bool]

Whether to include the resource parameter in authorization requests.

authorization_resource_parameter: Optional[str]

The resource parameter value to include in authorization requests. Defaults to "resource" when authorization_resource_enabled is true.

code_challenge_methods_supported: Optional[List[str]]
jwks_uri: Optional[str]
formaturi
registration_endpoint: Optional[str]
formaturi
scope_parameter: Optional[str]

The query parameter name for scopes in authorization requests. Defaults to "scope". Slack v2 uses "user_scope".

scope_separator: Optional[str]

The separator character for scope values. Defaults to " " (space). Slack v2 uses ",".

scopes_supported: Optional[List[str]]
token_endpoint: Optional[str]
formaturi
token_response_access_token_pointer: Optional[str]

Dot-separated path to the access token in the token response body. Defaults to "access_token". Slack v2 uses "authed_user.access_token".

openid: Optional[ProtocolsOpenid]

OpenID Connect protocol configuration

userinfo_endpoint: Optional[str]
formaturi
type: Optional[Literal["external", "keycard-vault", "keycard-sts"]]
Accepts one of the following:
"external"
"keycard-vault"
"keycard-sts"
credential_provider_id: Optional[str]

ID of the credential provider for this resource

description: Optional[str]

Human-readable description

maxLength2048
metadata: Optional[Metadata]

Entity metadata

docs_url: Optional[str]

Documentation URL

formaturi
maxLength2048
scopes: Optional[List[str]]

Scopes supported by the resource

when_accessing: Optional[List[str]]

List of resource IDs that, when accessed, make this dependency available. Only present when this resource is returned as a dependency.

Deprecateduser: Optional[User]

An authenticated user entity

id: str

Unique identifier of the user

created_at: datetime

Entity creation timestamp

formatdate-time
email: str

Email address of the user

formatemail
email_verified: bool

Whether the email address has been verified

organization_id: str

Organization that owns this user

updated_at: datetime

Entity update timestamp

formatdate-time
zone_id: str

Zone this user belongs to

authenticated_at: Optional[str]

Date when the user was last authenticated

issuer: Optional[str]

Issuer identifier of the identity provider

provider_id: Optional[str]

Reference to the identity provider. This field is undefined when the source identity provider is deleted but the user is not deleted.

subject: Optional[str]

Subject identifier from the identity provider

List delegated grants

from keycardai_api import KeycardAPI

client = KeycardAPI()
delegated_grants = client.zones.delegated_grants.list(
    zone_id="zoneId",
)
print(delegated_grants.items)
{
  "items": [
    {
      "id": "id",
      "created_at": "2019-12-27T18:11:19.117Z",
      "expires_at": "2019-12-27T18:11:19.117Z",
      "organization_id": "organization_id",
      "provider_id": "provider_id",
      "refresh_token_set": true,
      "resource_id": "resource_id",
      "scopes": [
        "string"
      ],
      "status": "active",
      "updated_at": "2019-12-27T18:11:19.117Z",
      "user_id": "user_id",
      "zone_id": "zone_id",
      "active": true,
      "provider": {
        "id": "id",
        "created_at": "2019-12-27T18:11:19.117Z",
        "identifier": "x",
        "name": "x",
        "organization_id": "organization_id",
        "owner_type": "platform",
        "slug": "slug",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "client_id": "client_id",
        "client_secret_set": true,
        "description": "description",
        "metadata": {},
        "protocols": {
          "oauth2": {
            "issuer": "https://example.com",
            "authorization_endpoint": "https://example.com",
            "authorization_parameters": {
              "foo": "string"
            },
            "authorization_resource_enabled": true,
            "authorization_resource_parameter": "authorization_resource_parameter",
            "code_challenge_methods_supported": [
              "string"
            ],
            "jwks_uri": "https://example.com",
            "registration_endpoint": "https://example.com",
            "scope_parameter": "scope_parameter",
            "scope_separator": "scope_separator",
            "scopes_supported": [
              "string"
            ],
            "token_endpoint": "https://example.com",
            "token_response_access_token_pointer": "token_response_access_token_pointer"
          },
          "openid": {
            "userinfo_endpoint": "https://example.com"
          }
        },
        "type": "external"
      },
      "refreshed_at": "2019-12-27T18:11:19.117Z",
      "resource": {
        "id": "id",
        "application_type": "native",
        "created_at": "2019-12-27T18:11:19.117Z",
        "identifier": "x",
        "name": "x",
        "organization_id": "organization_id",
        "owner_type": "platform",
        "slug": "slug",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "application": {
          "id": "id",
          "created_at": "2019-12-27T18:11:19.117Z",
          "dependencies_count": 0,
          "identifier": "x",
          "name": "x",
          "organization_id": "organization_id",
          "owner_type": "platform",
          "slug": "slug",
          "updated_at": "2019-12-27T18:11:19.117Z",
          "zone_id": "zone_id",
          "description": "description",
          "metadata": {
            "docs_url": "https://example.com"
          },
          "protocols": {
            "oauth2": {
              "post_logout_redirect_uris": [
                "https://example.com"
              ],
              "redirect_uris": [
                "https://example.com"
              ]
            }
          }
        },
        "application_id": "application_id",
        "credential_provider": {
          "id": "id",
          "created_at": "2019-12-27T18:11:19.117Z",
          "identifier": "x",
          "name": "x",
          "organization_id": "organization_id",
          "owner_type": "platform",
          "slug": "slug",
          "updated_at": "2019-12-27T18:11:19.117Z",
          "zone_id": "zone_id",
          "client_id": "client_id",
          "client_secret_set": true,
          "description": "description",
          "metadata": {},
          "protocols": {
            "oauth2": {
              "issuer": "https://example.com",
              "authorization_endpoint": "https://example.com",
              "authorization_parameters": {
                "foo": "string"
              },
              "authorization_resource_enabled": true,
              "authorization_resource_parameter": "authorization_resource_parameter",
              "code_challenge_methods_supported": [
                "string"
              ],
              "jwks_uri": "https://example.com",
              "registration_endpoint": "https://example.com",
              "scope_parameter": "scope_parameter",
              "scope_separator": "scope_separator",
              "scopes_supported": [
                "string"
              ],
              "token_endpoint": "https://example.com",
              "token_response_access_token_pointer": "token_response_access_token_pointer"
            },
            "openid": {
              "userinfo_endpoint": "https://example.com"
            }
          },
          "type": "external"
        },
        "credential_provider_id": "credential_provider_id",
        "description": "description",
        "metadata": {
          "docs_url": "https://example.com"
        },
        "scopes": [
          "string"
        ],
        "when_accessing": [
          "string"
        ]
      },
      "user": {
        "id": "id",
        "created_at": "2019-12-27T18:11:19.117Z",
        "email": "dev@stainless.com",
        "email_verified": true,
        "organization_id": "organization_id",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "authenticated_at": "authenticated_at",
        "issuer": "issuer",
        "provider_id": "provider_id",
        "subject": "subject"
      }
    }
  ],
  "pagination": {
    "after_cursor": "x",
    "before_cursor": "x",
    "total_count": 0
  }
}
Returns Examples
{
  "items": [
    {
      "id": "id",
      "created_at": "2019-12-27T18:11:19.117Z",
      "expires_at": "2019-12-27T18:11:19.117Z",
      "organization_id": "organization_id",
      "provider_id": "provider_id",
      "refresh_token_set": true,
      "resource_id": "resource_id",
      "scopes": [
        "string"
      ],
      "status": "active",
      "updated_at": "2019-12-27T18:11:19.117Z",
      "user_id": "user_id",
      "zone_id": "zone_id",
      "active": true,
      "provider": {
        "id": "id",
        "created_at": "2019-12-27T18:11:19.117Z",
        "identifier": "x",
        "name": "x",
        "organization_id": "organization_id",
        "owner_type": "platform",
        "slug": "slug",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "client_id": "client_id",
        "client_secret_set": true,
        "description": "description",
        "metadata": {},
        "protocols": {
          "oauth2": {
            "issuer": "https://example.com",
            "authorization_endpoint": "https://example.com",
            "authorization_parameters": {
              "foo": "string"
            },
            "authorization_resource_enabled": true,
            "authorization_resource_parameter": "authorization_resource_parameter",
            "code_challenge_methods_supported": [
              "string"
            ],
            "jwks_uri": "https://example.com",
            "registration_endpoint": "https://example.com",
            "scope_parameter": "scope_parameter",
            "scope_separator": "scope_separator",
            "scopes_supported": [
              "string"
            ],
            "token_endpoint": "https://example.com",
            "token_response_access_token_pointer": "token_response_access_token_pointer"
          },
          "openid": {
            "userinfo_endpoint": "https://example.com"
          }
        },
        "type": "external"
      },
      "refreshed_at": "2019-12-27T18:11:19.117Z",
      "resource": {
        "id": "id",
        "application_type": "native",
        "created_at": "2019-12-27T18:11:19.117Z",
        "identifier": "x",
        "name": "x",
        "organization_id": "organization_id",
        "owner_type": "platform",
        "slug": "slug",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "application": {
          "id": "id",
          "created_at": "2019-12-27T18:11:19.117Z",
          "dependencies_count": 0,
          "identifier": "x",
          "name": "x",
          "organization_id": "organization_id",
          "owner_type": "platform",
          "slug": "slug",
          "updated_at": "2019-12-27T18:11:19.117Z",
          "zone_id": "zone_id",
          "description": "description",
          "metadata": {
            "docs_url": "https://example.com"
          },
          "protocols": {
            "oauth2": {
              "post_logout_redirect_uris": [
                "https://example.com"
              ],
              "redirect_uris": [
                "https://example.com"
              ]
            }
          }
        },
        "application_id": "application_id",
        "credential_provider": {
          "id": "id",
          "created_at": "2019-12-27T18:11:19.117Z",
          "identifier": "x",
          "name": "x",
          "organization_id": "organization_id",
          "owner_type": "platform",
          "slug": "slug",
          "updated_at": "2019-12-27T18:11:19.117Z",
          "zone_id": "zone_id",
          "client_id": "client_id",
          "client_secret_set": true,
          "description": "description",
          "metadata": {},
          "protocols": {
            "oauth2": {
              "issuer": "https://example.com",
              "authorization_endpoint": "https://example.com",
              "authorization_parameters": {
                "foo": "string"
              },
              "authorization_resource_enabled": true,
              "authorization_resource_parameter": "authorization_resource_parameter",
              "code_challenge_methods_supported": [
                "string"
              ],
              "jwks_uri": "https://example.com",
              "registration_endpoint": "https://example.com",
              "scope_parameter": "scope_parameter",
              "scope_separator": "scope_separator",
              "scopes_supported": [
                "string"
              ],
              "token_endpoint": "https://example.com",
              "token_response_access_token_pointer": "token_response_access_token_pointer"
            },
            "openid": {
              "userinfo_endpoint": "https://example.com"
            }
          },
          "type": "external"
        },
        "credential_provider_id": "credential_provider_id",
        "description": "description",
        "metadata": {
          "docs_url": "https://example.com"
        },
        "scopes": [
          "string"
        ],
        "when_accessing": [
          "string"
        ]
      },
      "user": {
        "id": "id",
        "created_at": "2019-12-27T18:11:19.117Z",
        "email": "dev@stainless.com",
        "email_verified": true,
        "organization_id": "organization_id",
        "updated_at": "2019-12-27T18:11:19.117Z",
        "zone_id": "zone_id",
        "authenticated_at": "authenticated_at",
        "issuer": "issuer",
        "provider_id": "provider_id",
        "subject": "subject"
      }
    }
  ],
  "pagination": {
    "after_cursor": "x",
    "before_cursor": "x",
    "total_count": 0
  }
}