> ## Documentation Index
> Fetch the complete documentation index at: https://pipedream.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# List SCIM tokens

> List the workspace's SCIM provisioning token metadata; bearer secrets are never returned

Requires the `provisioning:read` scope.



## OpenAPI

````yaml /conduit/openapi/api.yaml get /conduit.v1.ConduitService/ListSCIMTokens
openapi: 3.1.0
info:
  title: Conduit API
  version: v1
  description: |
    Machine-to-machine API for Conduit workspaces. Authenticate a
    workspace API client with OAuth 2.0 client credentials at
    `/oauth/token`, then call these methods with the resulting bearer token.
    Read-only methods are documented as `GET`, with their JSON request encoded
    in the `message` query parameter. Mutating methods use `POST` with a JSON
    body. The server also accepts `POST` for reads. See the API guide for
    auth, scopes, and error handling.
servers:
  - url: https://conduit.example.com
    description: Your Conduit instance — replace with your CONDUIT_BASE_URL
security:
  - bearerAuth: []
tags:
  - name: connectors
    x-group: Connectors
    description: Create and manage connectors and the workspace's Pipedream configuration.
  - name: policies-and-groups
    x-group: Policies & groups
    description: Allow policies, groups, group membership, and effective-access debugging.
  - name: members
    x-group: Members
    description: Read the workspace's member roster.
  - name: single-sign-on
    x-group: Single sign-on
    description: Read sanitized workspace identity-provider configuration.
  - name: provisioning
    x-group: Provisioning
    description: Read sanitized SCIM metadata, provisioning rules, and resource mappings.
  - name: workspace-settings
    x-group: Workspace settings
    description: Change general workspace settings.
  - name: audit-log
    x-group: Audit log
    description: Read the workspace audit log.
paths:
  /conduit.v1.ConduitService/ListSCIMTokens:
    get:
      tags:
        - provisioning
      summary: List SCIM tokens
      description: >-
        List the workspace's SCIM provisioning token metadata; bearer secrets
        are never returned


        Requires the `provisioning:read` scope.
      operationId: ListSCIMTokens
      parameters:
        - name: Connect-Protocol-Version
          in: header
          required: true
          schema:
            $ref: '#/components/schemas/connect-protocol-version'
        - name: Connect-Timeout-Ms
          in: header
          schema:
            $ref: '#/components/schemas/connect-timeout-header'
        - name: message
          in: query
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/conduit.v1.ListSCIMTokensRequest'
        - name: encoding
          in: query
          required: true
          schema:
            $ref: '#/components/schemas/encoding'
        - name: base64
          in: query
          schema:
            $ref: '#/components/schemas/base64'
        - name: compression
          in: query
          schema:
            $ref: '#/components/schemas/compression'
        - name: connect
          in: query
          schema:
            $ref: '#/components/schemas/connect'
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/conduit.v1.ListSCIMTokensResponse'
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
components:
  schemas:
    connect-protocol-version:
      type: number
      title: Connect-Protocol-Version
      enum:
        - 1
      description: Define the version of the Connect protocol
      const: 1
    connect-timeout-header:
      type: number
      title: Connect-Timeout-Ms
      description: Define the timeout, in ms
    conduit.v1.ListSCIMTokensRequest:
      type: object
      properties:
        organizationId:
          type: string
          title: organization_id
      title: ListSCIMTokensRequest
      additionalProperties: false
    encoding:
      title: encoding
      enum:
        - proto
        - json
      description: Define which encoding or 'Message-Codec' to use
    base64:
      type: boolean
      title: base64
      description: >-
        Specifies if the message query param is base64 encoded, which may be
        required for binary data
    compression:
      title: compression
      enum:
        - identity
        - gzip
        - br
      description: Which compression algorithm to use for this request
    connect:
      title: connect
      enum:
        - v1
      description: Define the version of the Connect protocol
    conduit.v1.ListSCIMTokensResponse:
      type: object
      properties:
        tokens:
          type: array
          items:
            $ref: '#/components/schemas/conduit.v1.SCIMToken'
          title: tokens
        baseUrl:
          type: string
          title: base_url
          description: |-
            The base URL an IdP should point its SCIM connector at (e.g.
             https://conduit.example.com/scim/v2). Convenience for the settings UI.
        availableIdps:
          type: array
          items:
            $ref: '#/components/schemas/conduit.v1.SCIMIdp'
          title: available_idps
          description: >-
            The identity providers a new token may be bound to: the workspace's
            own
             IdPs, plus instance IdPs in single-workspace mode. Mirrors the server-side
             validation on CreateSCIMToken.
      title: ListSCIMTokensResponse
      additionalProperties: false
    connect.error:
      type: object
      properties:
        code:
          type: string
          examples:
            - not_found
          enum:
            - canceled
            - unknown
            - invalid_argument
            - deadline_exceeded
            - not_found
            - already_exists
            - permission_denied
            - resource_exhausted
            - failed_precondition
            - aborted
            - out_of_range
            - unimplemented
            - internal
            - unavailable
            - data_loss
            - unauthenticated
          description: >-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
        message:
          type: string
          description: >-
            A developer-facing error message, which should be in English. Any
            user-facing error message should be localized and sent in the
            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized by the client.
        details:
          type: array
          items:
            $ref: '#/components/schemas/connect.error_details.Any'
          description: >-
            A list of messages that carry the error details. There is no limit
            on the number of messages.
      title: Connect Error
      additionalProperties: true
      description: >-
        Error type returned by Connect:
        https://connectrpc.com/docs/go/errors/#http-representation
    conduit.v1.SCIMToken:
      type: object
      properties:
        id:
          type: string
          title: id
        label:
          type: string
          title: label
        enabled:
          type: boolean
          title: enabled
        createdAt:
          type:
            - integer
            - string
          title: created_at
          format: int64
        lastUsedAt:
          type:
            - integer
            - string
          title: last_used_at
          format: int64
          description: >-
            Unix seconds of the last successful auth with this token; 0 if never
            used.
        identityProviderId:
          type: string
          title: identity_provider_id
          description: >-
            The identity provider this token is bound to. Users pushed with this
            token
             bind under that provider's account namespace (keyed on subject, not email).
      title: SCIMToken
      additionalProperties: false
    conduit.v1.SCIMIdp:
      type: object
      properties:
        id:
          type: string
          title: id
        name:
          type: string
          title: name
      title: SCIMIdp
      additionalProperties: false
      description: >-
        SCIMIdp is the id + display name of an identity provider a SCIM token
        can be
         bound to (a slim view — full IdP config stays behind the SSO admin RPCs).
    connect.error_details.Any:
      type: object
      properties:
        type:
          type: string
          description: >-
            A URL that acts as a globally unique identifier for the type of the
            serialized message. For example:
            `type.googleapis.com/google.rpc.ErrorInfo`. This is used to
            determine the schema of the data in the `value` field and is the
            discriminator for the `debug` field.
        value:
          type: string
          format: binary
          description: >-
            The Protobuf message, serialized as bytes and base64-encoded. The
            specific message type is identified by the `type` field.
        debug:
          oneOf:
            - type: object
              title: Any
              additionalProperties: true
              description: Detailed error information.
          discriminator:
            propertyName: type
          title: Debug
          description: >-
            Deserialized error detail payload. The 'type' field indicates the
            schema. This field is for easier debugging and should not be relied
            upon for application logic.
      additionalProperties: true
      description: >-
        Contains an arbitrary serialized message along with a @type that
        describes the type of the serialized message, with an additional debug
        field for ConnectRPC error details.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: opaque

````