API ReferenceManagementScim Management
GET
/v1/mgmt/scim/key

Authorization

Descope Project ID and Management Key
AuthorizationBearer <token>

Project ID:Management Key as bearer token.

In: header

Query Parameters

tenantId?string
ssoId?string

Omit to return the tenant's SCIM keys across every SSO configuration.

Load the SCIM access keys of a tenant, using a valid management key. Returns key metadata only - the cleartext of an access key is available exactly once, when the key is created or rotated, and is never returned again.

curl -X GET "https://api.descope.com/v1/mgmt/scim/key"
{  "keys": [    {      "key": {        "id": "string",        "name": "string",        "roleNames": [          "string"        ],        "keyTenants": [          {            "tenantId": "string",            "roleNames": [              "string"            ],            "tenantName": "string"          }        ],        "status": "string",        "createdTime": 0,        "expireTime": 0,        "createdBy": "string",        "clientId": "string",        "boundUserId": "string",        "customClaims": {          "claim-name": "claim-value"        },        "editable": true,        "description": "string",        "permittedIps": [          "string"        ],        "customAttributes": {          "attribute-key": "attribute-value"        }      },      "ssoId": "string"    }  ]}
export interface Response {keys?: SCIMAccessKey[]}export interface SCIMAccessKey {key?: {id?: stringname?: stringroleNames?: string[]keyTenants?: AssociatedTenantAK[]status?: stringcreatedTime?: numberexpireTime?: numbercreatedBy?: stringclientId?: stringboundUserId?: string/** * Custom claims to include in the JWT as key-value pairs. Keys must be strings; values can be strings, numbers, or booleans. */customClaims?: {[k: string]: string}editable?: booleandescription?: stringpermittedIps?: string[]/** * Custom attributes as key-value pairs. Keys must be strings; values can be strings, numbers, booleans, or arrays. */customAttributes?: {[k: string]: string}}/** * The SSO configuration this key provisions into. */ssoId?: string}export interface AssociatedTenantAK {tenantId?: stringroleNames?: string[]tenantName?: string}
Was this helpful?