## Retrieve

`zones.groups.retrieve(strgroup_id, GroupRetrieveParams**kwargs)  -> Group`

**get** `/zones/{zoneId}/groups/{groupId}`

Returns a group by ID. Pass `expand[]=member_count` for its member count and `expand[]=roles` for the identifiers of its assigned roles.

### Parameters

- `zone_id: str`

- `group_id: str`

- `expand: Optional[Union[Literal["member_count", "roles"], List[Literal["member_count", "roles"]]]]`

  - `Literal["member_count", "roles"]`

    - `"member_count"`

    - `"roles"`

  - `List[Literal["member_count", "roles"]]`

    - `"member_count"`

    - `"roles"`

### Returns

- `class Group: …`

  A zone-scoped group of users, assignable to roles and usable in policies. Roles assigned to a group are inherited by its members. `external` is false for groups managed in Keycard and true for groups synced from an external directory.

  - `id: str`

    Unique identifier of the group

  - `created_at: datetime`

    Entity creation timestamp

  - `external: bool`

    Whether the group is synced from an external directory. When true the group is directory-owned and its membership is read-only; when false it is managed in Keycard. Read-only: set by external sync, never by the caller.

  - `identifier: str`

    User-specified identifier, unique within the zone. Automatically assigned for groups from an external directory.

  - `name: str`

    Human-readable group name

  - `organization_id: str`

    Organization this group belongs to

  - `updated_at: datetime`

    Entity update timestamp

  - `zone_id: str`

    Zone this group belongs to

  - `member_count: Optional[int]`

    Number of users in the group. Included only when requested via `expand[]=member_count` (group get or list).

  - `roles: Optional[List[str]]`

    Identifiers of the roles assigned to the group; members inherit them. Deduped across scopes. Included only when requested via `expand[]=roles` (group get or list).

### Example

```python
import os
from keycardai_api import KeycardAPI

client = KeycardAPI(
    api_key=os.environ.get("KEYCARD_API_API_KEY"),  # This is the default and can be omitted
)
group = client.zones.groups.retrieve(
    group_id="groupId",
    zone_id="zoneId",
)
print(group.id)
```
