curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"pageSize": 123,
"pageToken": "<string>",
"query": "<string>"
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search"
payload = {
"pageSize": 123,
"pageToken": "<string>",
"query": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({pageSize: 123, pageToken: '<string>', query: '<string>'})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'pageSize' => 123,
'pageToken' => '<string>',
'query' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search"
payload := strings.NewReader("{\n \"pageSize\": 123,\n \"pageToken\": \"<string>\",\n \"query\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"pageSize\": 123,\n \"pageToken\": \"<string>\",\n \"query\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"pageSize\": 123,\n \"pageToken\": \"<string>\",\n \"query\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"nextPageToken": "<string>",
"users": [
{
"group": {
"alias": "<string>",
"annotations": {},
"appId": "<string>",
"appResourceId": "<string>",
"appResourceTypeId": "<string>",
"certifyPolicyId": "<string>",
"complianceFrameworkValueIds": [
"<string>"
],
"createdAt": "2023-11-07T05:31:56Z",
"defaultValuesApplied": true,
"deletedAt": "2023-11-07T05:31:56Z",
"deprovisionerPolicy": {
"action": {
"actionName": "<string>",
"appId": "<string>",
"connectorId": "<string>",
"displayName": "<string>"
},
"connector": {
"account": {
"config": {},
"connectorId": "<string>",
"doNotSave": {},
"saveToVault": {
"vaultIds": [
"<string>"
]
},
"schemaId": "<string>"
},
"defaultBehavior": {
"connectorId": "<string>"
},
"deleteAccount": {
"connectorId": "<string>"
}
},
"delegated": {
"appId": "<string>",
"entitlementId": "<string>",
"implicit": true
},
"devicePlacement": {
"vaultBoundaryId": "<string>"
},
"externalTicket": {
"appId": "<string>",
"connectorId": "<string>",
"externalTicketProvisionerConfigId": "<string>",
"instructions": "<string>"
},
"manual": {
"assignee": {
"appOwners": {
"allowReassignment": true,
"fallbackUserIds": [
"<string>"
]
},
"entitlementOwners": {
"allowReassignment": true,
"fallbackUserIds": [
"<string>"
]
},
"expression": {
"allowReassignment": true,
"expressions": [
"<string>"
],
"fallbackUserIds": [
"<string>"
]
},
"group": {
"allowReassignment": true,
"appGroupId": "<string>",
"appId": "<string>",
"fallbackUserIds": [
"<string>"
]
},
"manager": {
"allowReassignment": true,
"fallbackUserIds": [
"<string>"
]
},
"users": {
"allowReassignment": true,
"userIds": [
"<string>"
]
}
},
"instructions": "<string>",
"userIds": [
"<string>"
]
},
"multiStep": {
"provisionSteps": "<array>"
},
"unconfigured": {},
"webhook": {
"webhookId": "<string>"
}
},
"description": "<string>",
"displayName": "<string>",
"durationGrant": "<string>",
"durationUnset": {},
"emergencyGrantEnabled": true,
"emergencyGrantPolicyId": "<string>",
"externalId": "<string>",
"grantCount": "<string>",
"grantPolicyId": "<string>",
"id": "<string>",
"isAutomationEnabled": true,
"isManuallyManaged": true,
"matchBatonId": "<string>",
"overrideAccessRequestsDefaults": true,
"provisionerPolicy": {
"action": {
"actionName": "<string>",
"appId": "<string>",
"connectorId": "<string>",
"displayName": "<string>"
},
"connector": {
"account": {
"config": {},
"connectorId": "<string>",
"doNotSave": {},
"saveToVault": {
"vaultIds": [
"<string>"
]
},
"schemaId": "<string>"
},
"defaultBehavior": {
"connectorId": "<string>"
},
"deleteAccount": {
"connectorId": "<string>"
}
},
"delegated": {
"appId": "<string>",
"entitlementId": "<string>",
"implicit": true
},
"devicePlacement": {
"vaultBoundaryId": "<string>"
},
"externalTicket": {
"appId": "<string>",
"connectorId": "<string>",
"externalTicketProvisionerConfigId": "<string>",
"instructions": "<string>"
},
"manual": {
"assignee": {
"appOwners": {
"allowReassignment": true,
"fallbackUserIds": [
"<string>"
]
},
"entitlementOwners": {
"allowReassignment": true,
"fallbackUserIds": [
"<string>"
]
},
"expression": {
"allowReassignment": true,
"expressions": [
"<string>"
],
"fallbackUserIds": [
"<string>"
]
},
"group": {
"allowReassignment": true,
"appGroupId": "<string>",
"appId": "<string>",
"fallbackUserIds": [
"<string>"
]
},
"manager": {
"allowReassignment": true,
"fallbackUserIds": [
"<string>"
]
},
"users": {
"allowReassignment": true,
"userIds": [
"<string>"
]
}
},
"instructions": "<string>",
"userIds": [
"<string>"
]
},
"multiStep": {
"provisionSteps": "<array>"
},
"unconfigured": {},
"webhook": {
"webhookId": "<string>"
}
},
"purpose": "APP_ENTITLEMENT_PURPOSE_VALUE_UNSPECIFIED",
"requestSchemaId": "<string>",
"revokePolicyId": "<string>",
"riskLevelValueId": "<string>",
"slug": "<string>",
"sourceConnectorIds": {},
"systemBuiltin": true,
"updatedAt": "2023-11-07T05:31:56Z",
"userEditedMask": "<string>"
},
"source": "EFFECTIVE_SESSION_POLICY_SOURCE_UNSPECIFIED",
"user": {
"createdAt": "2023-11-07T05:31:56Z",
"delegatedUserId": "<string>",
"deletedAt": "2023-11-07T05:31:56Z",
"department": "<string>",
"departmentSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"directoryIds": [
"<string>"
],
"directoryStatus": "UNKNOWN",
"directoryStatusSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"displayName": "<string>",
"email": "<string>",
"emailSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"emails": [
"<string>"
],
"employeeIdSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"employeeIds": [
"<string>"
],
"employmentStatus": "<string>",
"employmentStatusSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"employmentType": "<string>",
"employmentTypeSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"id": "<string>",
"jobTitle": "<string>",
"jobTitleSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"managerIds": [
"<string>"
],
"managerSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"origin": "USER_ORIGIN_UNSPECIFIED",
"profile": {},
"roleIds": [
"<string>"
],
"status": "UNKNOWN",
"type": "USER_TYPE_UNSPECIFIED",
"updatedAt": "2023-11-07T05:31:56Z",
"username": "<string>",
"usernameSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"usernames": [
"<string>"
]
}
}
]
}Search Policy Users
Searches the users a policy applies to, expanded: direct assignments plus per-user expansion of conferred groups, one page at a time. Served from the asynchronously-replicated Postgres mirror of the binding store, so a just-made assignment may not appear immediately; the user-scoped reads (GetEffectiveSessionPolicy, ListUserPolicies) reflect current state. Search, not List: the results are a filtered, server-paginated discovery over the binding store (query and source facets), not a bounded collection of a named object.
curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"pageSize": 123,
"pageToken": "<string>",
"query": "<string>"
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search"
payload = {
"pageSize": 123,
"pageToken": "<string>",
"query": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({pageSize: 123, pageToken: '<string>', query: '<string>'})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'pageSize' => 123,
'pageToken' => '<string>',
'query' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search"
payload := strings.NewReader("{\n \"pageSize\": 123,\n \"pageToken\": \"<string>\",\n \"query\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"pageSize\": 123,\n \"pageToken\": \"<string>\",\n \"query\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/session-policies/{id}/users/search")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"pageSize\": 123,\n \"pageToken\": \"<string>\",\n \"query\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"nextPageToken": "<string>",
"users": [
{
"group": {
"alias": "<string>",
"annotations": {},
"appId": "<string>",
"appResourceId": "<string>",
"appResourceTypeId": "<string>",
"certifyPolicyId": "<string>",
"complianceFrameworkValueIds": [
"<string>"
],
"createdAt": "2023-11-07T05:31:56Z",
"defaultValuesApplied": true,
"deletedAt": "2023-11-07T05:31:56Z",
"deprovisionerPolicy": {
"action": {
"actionName": "<string>",
"appId": "<string>",
"connectorId": "<string>",
"displayName": "<string>"
},
"connector": {
"account": {
"config": {},
"connectorId": "<string>",
"doNotSave": {},
"saveToVault": {
"vaultIds": [
"<string>"
]
},
"schemaId": "<string>"
},
"defaultBehavior": {
"connectorId": "<string>"
},
"deleteAccount": {
"connectorId": "<string>"
}
},
"delegated": {
"appId": "<string>",
"entitlementId": "<string>",
"implicit": true
},
"devicePlacement": {
"vaultBoundaryId": "<string>"
},
"externalTicket": {
"appId": "<string>",
"connectorId": "<string>",
"externalTicketProvisionerConfigId": "<string>",
"instructions": "<string>"
},
"manual": {
"assignee": {
"appOwners": {
"allowReassignment": true,
"fallbackUserIds": [
"<string>"
]
},
"entitlementOwners": {
"allowReassignment": true,
"fallbackUserIds": [
"<string>"
]
},
"expression": {
"allowReassignment": true,
"expressions": [
"<string>"
],
"fallbackUserIds": [
"<string>"
]
},
"group": {
"allowReassignment": true,
"appGroupId": "<string>",
"appId": "<string>",
"fallbackUserIds": [
"<string>"
]
},
"manager": {
"allowReassignment": true,
"fallbackUserIds": [
"<string>"
]
},
"users": {
"allowReassignment": true,
"userIds": [
"<string>"
]
}
},
"instructions": "<string>",
"userIds": [
"<string>"
]
},
"multiStep": {
"provisionSteps": "<array>"
},
"unconfigured": {},
"webhook": {
"webhookId": "<string>"
}
},
"description": "<string>",
"displayName": "<string>",
"durationGrant": "<string>",
"durationUnset": {},
"emergencyGrantEnabled": true,
"emergencyGrantPolicyId": "<string>",
"externalId": "<string>",
"grantCount": "<string>",
"grantPolicyId": "<string>",
"id": "<string>",
"isAutomationEnabled": true,
"isManuallyManaged": true,
"matchBatonId": "<string>",
"overrideAccessRequestsDefaults": true,
"provisionerPolicy": {
"action": {
"actionName": "<string>",
"appId": "<string>",
"connectorId": "<string>",
"displayName": "<string>"
},
"connector": {
"account": {
"config": {},
"connectorId": "<string>",
"doNotSave": {},
"saveToVault": {
"vaultIds": [
"<string>"
]
},
"schemaId": "<string>"
},
"defaultBehavior": {
"connectorId": "<string>"
},
"deleteAccount": {
"connectorId": "<string>"
}
},
"delegated": {
"appId": "<string>",
"entitlementId": "<string>",
"implicit": true
},
"devicePlacement": {
"vaultBoundaryId": "<string>"
},
"externalTicket": {
"appId": "<string>",
"connectorId": "<string>",
"externalTicketProvisionerConfigId": "<string>",
"instructions": "<string>"
},
"manual": {
"assignee": {
"appOwners": {
"allowReassignment": true,
"fallbackUserIds": [
"<string>"
]
},
"entitlementOwners": {
"allowReassignment": true,
"fallbackUserIds": [
"<string>"
]
},
"expression": {
"allowReassignment": true,
"expressions": [
"<string>"
],
"fallbackUserIds": [
"<string>"
]
},
"group": {
"allowReassignment": true,
"appGroupId": "<string>",
"appId": "<string>",
"fallbackUserIds": [
"<string>"
]
},
"manager": {
"allowReassignment": true,
"fallbackUserIds": [
"<string>"
]
},
"users": {
"allowReassignment": true,
"userIds": [
"<string>"
]
}
},
"instructions": "<string>",
"userIds": [
"<string>"
]
},
"multiStep": {
"provisionSteps": "<array>"
},
"unconfigured": {},
"webhook": {
"webhookId": "<string>"
}
},
"purpose": "APP_ENTITLEMENT_PURPOSE_VALUE_UNSPECIFIED",
"requestSchemaId": "<string>",
"revokePolicyId": "<string>",
"riskLevelValueId": "<string>",
"slug": "<string>",
"sourceConnectorIds": {},
"systemBuiltin": true,
"updatedAt": "2023-11-07T05:31:56Z",
"userEditedMask": "<string>"
},
"source": "EFFECTIVE_SESSION_POLICY_SOURCE_UNSPECIFIED",
"user": {
"createdAt": "2023-11-07T05:31:56Z",
"delegatedUserId": "<string>",
"deletedAt": "2023-11-07T05:31:56Z",
"department": "<string>",
"departmentSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"directoryIds": [
"<string>"
],
"directoryStatus": "UNKNOWN",
"directoryStatusSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"displayName": "<string>",
"email": "<string>",
"emailSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"emails": [
"<string>"
],
"employeeIdSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"employeeIds": [
"<string>"
],
"employmentStatus": "<string>",
"employmentStatusSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"employmentType": "<string>",
"employmentTypeSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"id": "<string>",
"jobTitle": "<string>",
"jobTitleSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"managerIds": [
"<string>"
],
"managerSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"origin": "USER_ORIGIN_UNSPECIFIED",
"profile": {},
"roleIds": [
"<string>"
],
"status": "UNKNOWN",
"type": "USER_TYPE_UNSPECIFIED",
"updatedAt": "2023-11-07T05:31:56Z",
"username": "<string>",
"usernameSources": [
{
"appId": "<string>",
"appUserId": "<string>",
"appUserProfileAttributeKey": "<string>",
"priority": 123,
"userAttributeMappingId": "<string>",
"value": "<string>"
}
],
"usernames": [
"<string>"
]
}
}
]
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
This API uses OAuth2 with the Client Credential flow. Client Credentials must be sent in the BODY, not the headers. For an example of how to implement this, refer to the c1TokenSource.Token() function.
Path Parameters
The session policy whose applied users to search.
Body
SessionPolicyServiceSearchPolicyUsersRequest searches the users a policy applies to, one page at a time. This read is served from the asynchronously-replicated Postgres mirror of the binding store, so a just-made assignment may not appear immediately; the user-scoped reads (GetEffectiveSessionPolicy, ListUserPolicies) reflect current state.
The maximum number of users to return per page. The server clamps this to its own bounds (currently 5..100). Always follow next_page_token to complete the search.
The page token from the previous response.
Fuzzy search on user display name and email. Empty matches all users the policy applies to. Applied in the query together with the source facet, so pages carry only matching rows.
When set, restrict results to this source. UNSPECIFIED returns all users.
EFFECTIVE_SESSION_POLICY_SOURCE_FILTER_UNSPECIFIED, EFFECTIVE_SESSION_POLICY_SOURCE_FILTER_DIRECT, EFFECTIVE_SESSION_POLICY_SOURCE_FILTER_GROUP Response
SessionPolicyServiceSearchPolicyUsersResponse carries one page of the users a policy applies to.
Was this page helpful?