> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-muhammad-kumail-github-mcp-tab.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Search

> Search access profiles across the tenant, filtered by application,
 resource server, or text query, or fetch a specific set by ref.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/search/xaa/access_profiles
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/search/xaa/access_profiles:
    post:
      tags:
        - Cross-App Access
      summary: Search
      description: |-
        Search access profiles across the tenant, filtered by application,
         resource server, or text query, or fetch a specific set by ref.
      operationId: c1.api.cross_app_access.v1.XAAAccessProfileService.Search
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceSearchRequest
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileServiceSearchResponse
          description: >-
            XAAAccessProfileServiceSearchResponse returns matching access
            profiles.
      x-codeSamples:
        - lang: go
          label: Search
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.XAAAccessProfile.Search(ctx, nil)\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.XAAAccessProfileServiceSearchResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    c1.api.cross_app_access.v1.XAAAccessProfileServiceSearchRequest:
      description: >-
        XAAAccessProfileServiceSearchRequest searches access profiles with
        filters.
      properties:
        appIds:
          description: Optional filter by applications. Empty matches any application.
          items:
            type: string
          type:
            - array
            - 'null'
        pageSize:
          description: Page size (max 100).
          format: int32
          type: integer
        pageToken:
          description: Page token for pagination.
          type: string
        query:
          description: Optional text query matched against display_name.
          type: string
        refs:
          description: |-
            Optional: fetch a specific set of access profiles by ref (used by
             websocket notify to re-fetch individual rows).
          items:
            $ref: >-
              #/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileRef
          type:
            - array
            - 'null'
        xaaResourceServerIds:
          description: >-
            Optional filter by resource servers. Empty matches any resource
            server.
          items:
            type: string
          type:
            - array
            - 'null'
      title: Xaa Access Profile Service Search Request
      type: object
      x-speakeasy-name-override: XAAAccessProfileServiceSearchRequest
    c1.api.cross_app_access.v1.XAAAccessProfileServiceSearchResponse:
      description: XAAAccessProfileServiceSearchResponse returns matching access profiles.
      properties:
        list:
          description: Matching access profiles.
          items:
            $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfile'
          type:
            - array
            - 'null'
        nextPageToken:
          description: Token for the next page.
          type: string
      title: Xaa Access Profile Service Search Response
      type: object
      x-speakeasy-name-override: XAAAccessProfileServiceSearchResponse
    c1.api.cross_app_access.v1.XAAAccessProfileRef:
      description: >-
        XAAAccessProfileRef is a lightweight reference to an access profile,
        used for
         websocket notifications and search filter refs.
      properties:
        appId:
          description: The appId field.
          type: string
        id:
          description: The id field.
          type: string
      title: Xaa Access Profile Ref
      type: object
      x-speakeasy-name-override: XAAAccessProfileRef
    c1.api.cross_app_access.v1.XAAAccessProfile:
      description: >-
        XAAAccessProfile is a requestable bundle of scopes for one resource
        server.
      properties:
        appEntitlementId:
          description: The AppEntitlement created for this profile.
          type: string
        appId:
          description: The application that owns the resource server.
          type: string
        createdAt:
          format: date-time
          type:
            - string
            - 'null'
        deletedAt:
          format: date-time
          type:
            - string
            - 'null'
        description:
          description: Description of what access this profile grants.
          type: string
        displayName:
          description: Display name for the profile.
          type: string
        id:
          description: Unique identifier for this access profile.
          type: string
        scopeCount:
          description: The number of scopes currently bound to this profile.
          format: int32
          type: integer
        updatedAt:
          format: date-time
          type:
            - string
            - 'null'
        xaaResourceServerId:
          description: The resource server this profile grants access to.
          type: string
      title: Xaa Access Profile
      type: object
      x-speakeasy-name-override: XAAAccessProfile
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````