OpenapiIam
Returns the applications in one organization, newest first — each product or…
Returns the applications in one organization, newest first — each product or site your people sign in to, with the sign-in methods and redirect URIs it…
GET /v1/iam/applications
| Address | https://api.hanzo.ai/v1/iam/applications |
| Method | GET |
| Operation | get_iam_applications |
| Auth | Authorization: Bearer $HANZO_API_KEY |
Returns the applications in one organization, newest first — each product or site your people sign in to, with the sign-in methods and redirect URIs it allows.
Request
1 field.
| Field | In | Type | Required | Description |
|---|---|---|---|---|
owner | query | string | yes |
Response
| Status | Body | Meaning |
|---|---|---|
200 | iam.ApplicationListResult | ok |
200 body — 286 fields.
| Field | In | Type | Always | Description |
|---|---|---|---|---|
applications | body | iam.Application[] | — | |
applications[].affiliationUrl | body | string | — | |
applications[].category | body | string | — | |
applications[].cert | body | string | — | |
applications[].certObj | body | iam.Cert | — | |
applications[].certObj.accessKey | body | string | — | |
applications[].certObj.accessSecret | body | string | — | |
applications[].certObj.account | body | string | — | |
applications[].certObj.bitSize | body | integer | — | |
applications[].certObj.certificate | body | string | — | |
applications[].certObj.createdAt | body | string (date-time) | — | |
applications[].certObj.createdTime | body | string | — | |
applications[].certObj.cryptoAlgorithm | body | string | — | |
applications[].certObj.deleted | body | boolean | — | |
applications[].certObj.displayName | body | string | — | |
applications[].certObj.domainExpireTime | body | string | — | |
applications[].certObj.expireInYears | body | integer | — | |
applications[].certObj.expireTime | body | string | — | |
applications[].certObj.id | body | string | — | |
applications[].certObj.name | body | string | — | |
applications[].certObj.owner | body | string | — | |
applications[].certObj.provider | body | string | — | |
applications[].certObj.scope | body | string | — | |
applications[].certObj.type | body | string | — | |
applications[].certObj.updatedAt | body | string (date-time) | — | |
applications[].certPublicKey | body | string | — | |
applications[].clientCert | body | string | — | |
applications[].clientId | body | string | — | ClientId is the OAuth2/OIDC client identifier and the GLOBAL key every confidential-client resolver authenticates against (store.GetApplicationByClientId, the… |
applications[].clientSecret | body | string | — | |
applications[].codeResendTimeout | body | integer | — | |
applications[].cookieExpireInHours | body | integer | — | |
applications[].createdAt | body | string (date-time) | — | |
applications[].createdTime | body | string | — | |
applications[].customScopes | body | iam.ScopeDescription[] | — | |
applications[].customScopes[].description | body | string | — | |
applications[].customScopes[].displayName | body | string | — | |
applications[].customScopes[].scope | body | string | — | |
applications[].defaultGroup | body | string | — | |
applications[].deleted | body | boolean | — | |
applications[].description | body | string | — | |
applications[].disableSamlAttributes | body | boolean | — | |
applications[].disableSignin | body | boolean | — | |
applications[].displayName | body | string | — | |
applications[].domain | body | string | — | |
applications[].enableAutoSignin | body | boolean | — | |
applications[].enableCodeSignin | body | boolean | — | |
applications[].enableExclusiveSignin | body | boolean | — | |
applications[].enableLinkWithEmail | body | boolean | — | |
applications[].enablePassword | body | boolean | — | |
applications[].enableSamlAssertionSignature | body | boolean | — | |
applications[].enableSamlC14n10 | body | boolean | — | |
applications[].enableSamlCompress | body | boolean | — | |
applications[].enableSamlPostBinding | body | boolean | — | |
applications[].enableSignUp | body | boolean | — | |
applications[].enableSigninSession | body | boolean | — | |
applications[].enableWebAuthn | body | boolean | — | |
applications[].environment | body | string | — | |
applications[].expireInHours | body | number | — | |
applications[].failedSigninFrozenTime | body | integer | — | |
applications[].failedSigninLimit | body | integer | — | |
applications[].favicon | body | string | — | |
applications[].footerHtml | body | string | — | |
applications[].forcedRedirectOrigin | body | string | — | |
applications[].forgetUrl | body | string | — | |
applications[].formBackgroundUrl | body | string | — | |
applications[].formBackgroundUrlMobile | body | string | — | |
applications[].formCss | body | string | — | |
applications[].formCssMobile | body | string | — | |
applications[].formOffset | body | integer | — | |
applications[].formSideHtml | body | string | — | |
applications[].grantTypes | body | string[] | — | |
applications[].headerHtml | body | string | — | |
applications[].homepageUrl | body | string | — | |
applications[].id | body | string | — | |
applications[].ipRestriction | body | string | — | |
applications[].ipWhitelist | body | string | — | |
applications[].isShared | body | boolean | — | |
applications[].logo | body | string | — | |
applications[].name | body | string | — | |
applications[].order | body | integer | — | |
applications[].orgChoiceMode | body | string | — | |
applications[].organization | body | string | — | |
applications[].organizationObj | body | iam.Organization | — | |
applications[].organizationObj.accountItems | body | iam.AccountItem[] | — | |
applications[].organizationObj.accountItems[].modifyRule | body | string | — | |
applications[].organizationObj.accountItems[].name | body | string | — | |
applications[].organizationObj.accountItems[].regex | body | string | — | |
applications[].organizationObj.accountItems[].tab | body | string | — | |
applications[].organizationObj.accountItems[].viewRule | body | string | — | |
applications[].organizationObj.accountItems[].visible | body | boolean | — | |
applications[].organizationObj.accountMenu | body | string | — | |
applications[].organizationObj.avatar | body | string | — | How the organization appears across Hanzo — the square mark beside its name — as an image or as one emoji, never both. |
applications[].organizationObj.balanceCredit | body | number | — | |
applications[].organizationObj.balanceCurrency | body | string | — | |
applications[].organizationObj.countryCodes | body | string[] | — | |
applications[].organizationObj.createdAt | body | string (date-time) | — | |
applications[].organizationObj.createdTime | body | string | — | |
applications[].organizationObj.dcrPolicy | body | string | — | |
applications[].organizationObj.defaultApplication | body | string | — | |
applications[].organizationObj.defaultAvatar | body | string | — | |
applications[].organizationObj.defaultPassword | body | string | — | |
applications[].organizationObj.deleted | body | boolean | — | |
applications[].organizationObj.disableSignin | body | boolean | — | |
applications[].organizationObj.displayName | body | string | — | |
applications[].organizationObj.emoji | body | string | — | |
applications[].organizationObj.enableSoftDeletion | body | boolean | — | |
applications[].organizationObj.enableTour | body | boolean | — | |
applications[].organizationObj.failedSigninFrozenTime | body | integer | — | |
applications[].organizationObj.failedSigninLimit | body | integer | — | Per-organization signin throttle. Zero means "inherit the application default"; a non-zero value overrides it. |
applications[].organizationObj.favicon | body | string | — | |
applications[].organizationObj.founder | body | string | — | Founder is the stable storage id of the identity that provisioned this org (self-service onboarding). |
applications[].organizationObj.hasPrivilegeConsent | body | boolean | — | |
applications[].organizationObj.id | body | string | — | |
applications[].organizationObj.initScore | body | integer | — | |
applications[].organizationObj.ipRestriction | body | string | — | |
applications[].organizationObj.ipWhitelist | body | string | — | |
applications[].organizationObj.isPersonal | body | boolean | — | |
applications[].organizationObj.isProfilePublic | body | boolean | — | |
applications[].organizationObj.kerberosKdcHost | body | string | — | |
applications[].organizationObj.kerberosKeytab | body | string | — | |
applications[].organizationObj.kerberosRealm | body | string | — | |
applications[].organizationObj.kerberosServiceName | body | string | — | |
applications[].organizationObj.languages | body | string[] | — | |
applications[].organizationObj.ldapAttributes | body | string[] | — | |
applications[].organizationObj.logo | body | string | — | |
applications[].organizationObj.logoDark | body | string | — | |
applications[].organizationObj.masterPassword | body | string | — | |
applications[].organizationObj.masterVerificationCode | body | string | — | |
applications[].organizationObj.mfaItems | body | iam.MfaItem[] | — | |
applications[].organizationObj.mfaItems[].name | body | string | — | |
applications[].organizationObj.mfaItems[].rule | body | string | — | |
applications[].organizationObj.mfaRememberInHours | body | integer | — | |
applications[].organizationObj.name | body | string | — | |
applications[].organizationObj.navItems | body | string[] | — | |
applications[].organizationObj.orgBalance | body | number | — | Balance fields are read-only mirrors; authoritative balances live in Commerce (billing.hanzo.ai). |
applications[].organizationObj.owner | body | string | — | |
applications[].organizationObj.passwordExpireDays | body | integer | — | |
applications[].organizationObj.passwordObfuscatorKey | body | string | — | |
applications[].organizationObj.passwordObfuscatorType | body | string | — | |
applications[].organizationObj.passwordOptions | body | string[] | — | |
applications[].organizationObj.passwordSalt | body | string | — | |
applications[].organizationObj.passwordType | body | string | — | |
applications[].organizationObj.tags | body | string[] | — | |
applications[].organizationObj.themeData | body | iam.ThemeData | — | |
applications[].organizationObj.themeData.borderRadius | body | integer | — | |
applications[].organizationObj.themeData.colorPrimary | body | string | — | |
applications[].organizationObj.themeData.isCompact | body | boolean | — | |
applications[].organizationObj.themeData.isEnabled | body | boolean | — | |
applications[].organizationObj.themeData.themeType | body | string | — | |
applications[].organizationObj.updatedAt | body | string (date-time) | — | |
applications[].organizationObj.useEmailAsUsername | body | boolean | — | |
applications[].organizationObj.usePermanentAvatar | body | boolean | — | |
applications[].organizationObj.userBalance | body | number | — | |
applications[].organizationObj.userNavItems | body | string[] | — | |
applications[].organizationObj.userTypes | body | string[] | — | |
applications[].organizationObj.websiteUrl | body | string | — | |
applications[].organizationObj.widgetItems | body | string[] | — | |
applications[].otherDomains | body | string[] | — | |
applications[].owner | body | string | — | |
applications[].project | body | string | — | |
applications[].providers | body | iam.ProviderItem[] | — | |
applications[].providers[].bindingRule | body | string[] | — | |
applications[].providers[].canSignIn | body | boolean | — | |
applications[].providers[].canSignUp | body | boolean | — | |
applications[].providers[].canUnlink | body | boolean | — | |
applications[].providers[].countryCodes | body | string[] | — | |
applications[].providers[].name | body | string | — | |
applications[].providers[].owner | body | string | — | |
applications[].providers[].prompted | body | boolean | — | |
applications[].providers[].provider | body | iam.Provider | — | |
applications[].providers[].provider.appId | body | string | — | |
applications[].providers[].provider.bucket | body | string | — | |
applications[].providers[].provider.category | body | string | — | |
applications[].providers[].provider.cert | body | string | — | |
applications[].providers[].provider.clientId | body | string | — | |
applications[].providers[].provider.clientId2 | body | string | — | |
applications[].providers[].provider.clientSecret | body | string | — | |
applications[].providers[].provider.clientSecret2 | body | string | — | |
applications[].providers[].provider.content | body | string | — | |
applications[].providers[].provider.createdAt | body | string (date-time) | — | |
applications[].providers[].provider.createdTime | body | string | — | |
applications[].providers[].provider.customAuthUrl | body | string | — | |
applications[].providers[].provider.customLogo | body | string | — | |
applications[].providers[].provider.customTokenUrl | body | string | — | |
applications[].providers[].provider.customUserInfoUrl | body | string | — | |
applications[].providers[].provider.deleted | body | boolean | — | |
applications[].providers[].provider.disableSsl | body | boolean | — | |
applications[].providers[].provider.displayName | body | string | — | |
applications[].providers[].provider.domain | body | string | — | |
applications[].providers[].provider.emailRegex | body | string | — | |
applications[].providers[].provider.enablePkce | body | boolean | — | |
applications[].providers[].provider.enableProxy | body | boolean | — | |
applications[].providers[].provider.enableSignAuthnRequest | body | boolean | — | |
applications[].providers[].provider.endpoint | body | string | — | |
applications[].providers[].provider.host | body | string | — | |
applications[].providers[].provider.httpHeaders | body | object | — | |
applications[].providers[].provider.httpHeaders.* | body | string | — | |
applications[].providers[].provider.id | body | string | — | |
applications[].providers[].provider.idP | body | string | — | |
applications[].providers[].provider.intranetEndpoint | body | string | — | |
applications[].providers[].provider.issuerUrl | body | string | — | |
applications[].providers[].provider.metadata | body | string | — | |
applications[].providers[].provider.method | body | string | — | |
applications[].providers[].provider.name | body | string | — | |
applications[].providers[].provider.owner | body | string | — | |
applications[].providers[].provider.pathPrefix | body | string | — | |
applications[].providers[].provider.port | body | integer | — | |
applications[].providers[].provider.providerUrl | body | string | — | |
applications[].providers[].provider.receiver | body | string | — | |
applications[].providers[].provider.regionId | body | string | — | |
applications[].providers[].provider.scopes | body | string | — | |
applications[].providers[].provider.signName | body | string | — | |
applications[].providers[].provider.sslMode | body | string | — | |
applications[].providers[].provider.subType | body | string | — | |
applications[].providers[].provider.templateCode | body | string | — | |
applications[].providers[].provider.title | body | string | — | |
applications[].providers[].provider.type | body | string | — | |
applications[].providers[].provider.updatedAt | body | string (date-time) | — | |
applications[].providers[].provider.userMapping | body | object | — | |
applications[].providers[].provider.userMapping.* | body | string | — | |
applications[].providers[].rule | body | string | — | |
applications[].providers[].signupGroup | body | string | — | |
applications[].redirectUris | body | string[] | — | |
applications[].refreshExpireInHours | body | number | — | |
applications[].samlAttributes | body | iam.SamlItem[] | — | |
applications[].samlAttributes[].name | body | string | — | |
applications[].samlAttributes[].nameFormat | body | string | — | |
applications[].samlAttributes[].value | body | string | — | |
applications[].samlHashAlgorithm | body | string | — | |
applications[].samlReplyUrl | body | string | — | |
applications[].scopes | body | iam.ScopeItem[] | — | |
applications[].scopes[].description | body | string | — | |
applications[].scopes[].displayName | body | string | — | |
applications[].scopes[].name | body | string | — | |
applications[].scopes[].tools | body | string[] | — | |
applications[].signinHtml | body | string | — | |
applications[].signinItems | body | iam.SigninItem[] | — | |
applications[].signinItems[].customCss | body | string | — | |
applications[].signinItems[].isCustom | body | boolean | — | |
applications[].signinItems[].label | body | string | — | |
applications[].signinItems[].name | body | string | — | |
applications[].signinItems[].placeholder | body | string | — | |
applications[].signinItems[].rule | body | string | — | |
applications[].signinItems[].visible | body | boolean | — | |
applications[].signinMethods | body | iam.SigninMethod[] | — | |
applications[].signinMethods[].displayName | body | string | — | |
applications[].signinMethods[].name | body | string | — | |
applications[].signinMethods[].rule | body | string | — | |
applications[].signinUrl | body | string | — | |
applications[].signupHtml | body | string | — | |
applications[].signupItems | body | iam.SignupItem[] | — | |
applications[].signupItems[].customCss | body | string | — | |
applications[].signupItems[].label | body | string | — | |
applications[].signupItems[].name | body | string | — | |
applications[].signupItems[].options | body | string[] | — | |
applications[].signupItems[].placeholder | body | string | — | |
applications[].signupItems[].prompted | body | boolean | — | |
applications[].signupItems[].regex | body | string | — | |
applications[].signupItems[].required | body | boolean | — | |
applications[].signupItems[].rule | body | string | — | |
applications[].signupItems[].type | body | string | — | |
applications[].signupItems[].visible | body | boolean | — | |
applications[].signupUrl | body | string | — | |
applications[].sslCert | body | string | — | |
applications[].sslMode | body | string | — | |
applications[].tags | body | string[] | — | |
applications[].termsOfUse | body | string | — | |
applications[].themeData | body | iam.ThemeData | — | |
applications[].themeData.borderRadius | body | integer | — | |
applications[].themeData.colorPrimary | body | string | — | |
applications[].themeData.isCompact | body | boolean | — | |
applications[].themeData.isEnabled | body | boolean | — | |
applications[].themeData.themeType | body | string | — | |
applications[].title | body | string | — | |
applications[].tokenAttributes | body | iam.JwtItem[] | — | |
applications[].tokenAttributes[].category | body | string | — | |
applications[].tokenAttributes[].name | body | string | — | |
applications[].tokenAttributes[].type | body | string | — | |
applications[].tokenAttributes[].value | body | string | — | |
applications[].tokenFields | body | string[] | — | |
applications[].tokenFormat | body | string | — | |
applications[].tokenSigningMethod | body | string | — | |
applications[].type | body | string | — | |
applications[].updatedAt | body | string (date-time) | — | |
applications[].upstreamHost | body | string | — | |
applications[].useEmailAsSamlNameId | body | boolean | — |
Failure carries the platform error shape — see Errors.
Examples
hanzo iam applications get --owner <owner>import { Configuration, IamApi } from 'hanzoai';
const api = new IamApi(new Configuration({ accessToken: process.env.HANZO_API_KEY }));
const { data } = await api.getIamApplications({ owner: 'owner' });from hanzoai.cloud import ApiClient, Configuration
from hanzoai.cloud.api import IamApi
client = ApiClient(Configuration(access_token=os.environ["HANZO_API_KEY"]))
result = IamApi(client).get_iam_applications(owner='owner')cfg := cloud.NewConfiguration()
cfg.AddDefaultHeader("Authorization", "Bearer "+os.Getenv("HANZO_API_KEY"))
client := cloud.NewAPIClient(cfg)
resp, _, err := client.IamAPI.GetIamApplications(context.Background()).Execute()
if err != nil {
return err
}use hanzo_cloud::apis::{configuration::Configuration, iam_api};
let mut cfg = Configuration::new();
cfg.bearer_access_token = std::env::var("HANZO_API_KEY").ok();
let result = iam_api::get_iam_applications(&cfg, Default::default()).await?;import ai.hanzo.cloud.ApiClient;
import ai.hanzo.cloud.api.IamApi;
ApiClient client = new ApiClient();
client.setRequestInterceptor(b -> b.header("Authorization", "Bearer " + System.getenv("HANZO_API_KEY")));
var result = new IamApi(client).getIamApplications();curl https://api.hanzo.ai/v1/iam/applications?owner=%3Cowner%3E \
-H "Authorization: Bearer $HANZO_API_KEY"The door reaches iam through the iam tool, which names its 75 operations with its own verbs — this one among them, under a name only the door declares. describe explains any of them:
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "describe",
"arguments": {
"op": "list__well_known_jwks"
}
}
}'How is this guide?