> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-luisinasantos-sync-coupa-v0-1-13-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# List

> List retrieves Edges for an app.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples get /api/v1/apps/{app_id}/edges
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/apps/{app_id}/edges:
    get:
      tags:
        - Edge
      summary: List
      description: List retrieves Edges for an app.
      operationId: c1.api.edge.v1.EdgeService.List
      parameters:
        - in: path
          name: app_id
          required: true
          schema:
            description: App identifier.
            type: string
        - in: query
          name: page_size
          schema:
            description: Page size (max 100).
            format: int32
            type: integer
        - in: query
          name: page_token
          schema:
            description: Page token for pagination.
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/c1.api.edge.v1.EdgeServiceListResponse'
          description: EdgeServiceListResponse lists Edges for an app.
components:
  schemas:
    c1.api.edge.v1.EdgeServiceListResponse:
      description: EdgeServiceListResponse lists Edges for an app.
      properties:
        list:
          description: The list field.
          items:
            $ref: '#/components/schemas/c1.api.edge.v1.Edge'
          type:
            - array
            - 'null'
        nextPageToken:
          description: Token for next page.
          type: string
      title: Edge Service List Response
      type: object
      x-speakeasy-name-override: EdgeServiceListResponse
    c1.api.edge.v1.Edge:
      description: >-
        Edge is an application-owned configuration for egress and inference
        services.
      properties:
        appId:
          description: App identifier.
          type: string
        createdAt:
          format: date-time
          type:
            - string
            - 'null'
        credentialInjections:
          description: >-
            Vault-backed headers the hosted Edge adds to matching egress
            requests.
             Grant the vault's OpenSecret entitlement to the Edge's service principal.
          items:
            $ref: '#/components/schemas/c1.api.edge.v1.EdgeCredentialInjection'
          type:
            - array
            - 'null'
        displayName:
          description: The displayName field.
          type: string
        egressConnectEntitlementId:
          description: >-
            The minted egress.connect entitlement (derived from the Edge id) --
            grant
             it to a caller to let it open an authenticated egress connection. Empty
             when egress is not in enabled_kinds.
          type: string
        egressRules:
          description: |-
            Ordered egress access rules, evaluated first-match-wins with default
             deny when none match. Order is significant: a customer expresses "allow
             all except this one user" by placing the specific rule first.
          items:
            $ref: '#/components/schemas/c1.api.edge.v1.EdgeEgressRule'
          type:
            - array
            - 'null'
        egressRulesConfigured:
          description: >-
            Whether egress_rules has ever been deliberately set (via an
            update_mask
             naming it), regardless of the resulting list's length. False means this
             Edge has never touched the feature -- egress is not destination-restricted
             -- even though egress_rules reads empty either way; true with an empty
             egress_rules means every destination is deliberately denied.
          type: boolean
        enabledKinds:
          description: >-
            The capabilities this Edge currently serves. A request naming a
            resource
             for a capability outside this set is denied, independent of mode. At
             least one kind is required.
          items:
            enum:
              - EDGE_CAPABILITY_KIND_UNSPECIFIED
              - EDGE_CAPABILITY_KIND_EGRESS
              - EDGE_CAPABILITY_KIND_INFERENCE
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        id:
          description: The id field.
          type: string
        inference:
          oneOf:
            - $ref: '#/components/schemas/c1.api.edge.v1.EdgeInferenceRoute'
            - type: 'null'
        inferenceInvokeEntitlementId:
          description: >-
            The minted inference.invoke entitlement (derived from the Edge id).
            Empty
             when inference is not in enabled_kinds.
          type: string
        inferenceModelsReadEntitlementId:
          description: >-
            The minted inference.models.read entitlement (derived from the Edge
            id).
             Empty when inference is not in enabled_kinds.
          type: string
        inferenceRoutes:
          description: |-
            Complete ordered set of tenant-unique inference routes. update_mask
             "inference_routes" atomically replaces the entire set (including empty).
             Up to 40 routes per Edge; replacing a set is atomic.
          items:
            $ref: '#/components/schemas/c1.api.edge.v1.EdgeInferenceRoute'
          type:
            - array
            - 'null'
        mode:
          description: >-
            Hosting state for the service configuration. DISABLED and
            UNSPECIFIED
             deny every request. ENFORCE and OBSERVE both still require capability
             authorization; content policy and routing remain configured on the Edge
             host. OBSERVE is currently identical to ENFORCE -- it exists so an
             operator can stage an Edge ahead of destination-level policy support,
             which does not exist yet.
          enum:
            - EDGE_MODE_UNSPECIFIED
            - EDGE_MODE_DISABLED
            - EDGE_MODE_OBSERVE
            - EDGE_MODE_ENFORCE
          type: string
          x-speakeasy-unknown-values: allow
        tokenAudience:
          description: >-
            The `audience` to send when exchanging a token for access to this
            Edge.
             Every Edge deployment in the tenant shares it, so it names the service;
             `token_resources` identify its service endpoints.
          type: string
        tokenResources:
          oneOf:
            - $ref: '#/components/schemas/c1.api.edge.v1.EdgeTokenResources'
            - type: 'null'
        tokenScopes:
          description: >-
            The scopes this Edge can issue. Explicit requests fail if any scope
            is
             ungranted; an omitted scope requests the granted capabilities of each resource.
          items:
            type: string
          type:
            - array
            - 'null'
        updatedAt:
          format: date-time
          type:
            - string
            - 'null'
      title: Edge
      type: object
      x-speakeasy-name-override: Edge
    c1.api.edge.v1.EdgeCredentialInjection:
      description: EdgeCredentialInjection binds one C1 vault secret to one request header.
      properties:
        contentType:
          description: The secret's stored content type. Defaults to "api_key".
          type: string
        headerName:
          description: Header to set, replacing any value supplied by the caller.
          type: string
        hostPattern:
          description: Destination host glob, e.g. "api.example.com" or "*.example.com".
          type: string
        pathPattern:
          description: Request path glob, e.g. "/v1/*". Empty matches every path.
          type: string
        secretId:
          description: Secret to inject.
          type: string
        valuePrefix:
          description: Literal text placed before the secret value, e.g. "Bearer ".
          type: string
        vaultId:
          description: Vault holding the secret.
          type: string
      title: Edge Credential Injection
      type: object
      x-speakeasy-name-override: EdgeCredentialInjection
    c1.api.edge.v1.EdgeEgressRule:
      description: EdgeEgressRule is one ordered row of an Edge's egress access policy.
      properties:
        effect:
          description: The effect field.
          enum:
            - EDGE_EGRESS_EFFECT_UNSPECIFIED
            - EDGE_EGRESS_EFFECT_ALLOW
            - EDGE_EGRESS_EFFECT_DENY
          type: string
          x-speakeasy-unknown-values: allow
        endpointPattern:
          description: |-
            Destination host to match: exact hostname, or a single leading "*."
             wildcard for subdomains (e.g. "*.example.com"). Port and path are out of
             scope for v1.
          type: string
        exemptCredentialKinds:
          description: >-
            Content-inspection finding classes this rule exempts from blocking
            on
             the *request* path, since the destination is already trusted for this
             principal. Never applies to response content; see
             exempt_response_credential_kinds for that, deliberately independent.
          items:
            enum:
              - CREDENTIAL_KIND_UNSPECIFIED
              - CREDENTIAL_KIND_JWT
              - CREDENTIAL_KIND_API_KEY
              - CREDENTIAL_KIND_PRIVATE_KEY
              - CREDENTIAL_KIND_VENDOR_CREDENTIAL
              - CREDENTIAL_KIND_PAN
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        exemptResponseCredentialKinds:
          description: >-
            Content-inspection finding classes this rule exempts from blocking
            on
             the *response* path -- e.g. a destination's own credential-issuance
             reply (temporary cloud credentials, a continuation token) that the
             caller's own service legitimately needs to consume. Deliberately a
             separate list from exempt_credential_kinds, defaulting empty: trusting a
             destination's outbound credential never implies trusting whatever it
             sends back, and an admin must opt a kind into this list explicitly.
          items:
            enum:
              - CREDENTIAL_KIND_UNSPECIFIED
              - CREDENTIAL_KIND_JWT
              - CREDENTIAL_KIND_API_KEY
              - CREDENTIAL_KIND_PRIVATE_KEY
              - CREDENTIAL_KIND_VENDOR_CREDENTIAL
              - CREDENTIAL_KIND_PAN
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        maxInspectedBodyBytes:
          description: |-
            Overrides, for destinations matching this rule, the largest body (in
             bytes) Time Bandit buffers for content inspection. 0 means unset: Time
             Bandit uses its fleet default (1 MiB). A body above the limit is still
             refused (fail closed) and is never forwarded uninspected. Only meaningful
             on ALLOW rules. Applies whether or not skip_content_inspection is set.
          format: uint64
          type: string
        principal:
          oneOf:
            - $ref: '#/components/schemas/c1.api.edge.v1.EdgeEgressPrincipal'
            - type: 'null'
        skipContentInspection:
          description: >-
            When true, decoding is optional for destinations matching this rule;
            inspection
             is not. Despite the name, this does NOT skip content inspection: every detector,
             guardrail and header scan still runs and any finding still denies. It only
             changes what happens when a body declares a Content-Encoding that Time Bandit
             has no decoder for. Without the flag the body is denied (fail closed); with it,
             the bytes are scanned as-is through the normal cascade. Trade-off: a secret
             inside genuine compression labelled with an unsupported token is not caught
             (plaintext and gzip still are). A supported encoding that is malformed or
             truncated, decoded output over the inspection cap, and bodies over the wire cap
             still fail closed. Off by default. Only meaningful on ALLOW rules.
          type: boolean
      title: Edge Egress Rule
      type: object
      x-speakeasy-name-override: EdgeEgressRule
    c1.api.edge.v1.EdgeInferenceRoute:
      description: >-
        EdgeInferenceRoute declares a caller-visible model selector and a
        bounded
         provider graph. Legacy scalar fields decode previously stored singletons;
         new configurations use native_format, targets, and selection.
      properties:
        allowHumanCallers:
          description: >-
            Explicitly authorize enabled human users holding per-capability app
            grants
             to exchange an SSO id_token with DPoP. False preserves workload-only routes.
          type: boolean
        callerServicePrincipalId:
          description: >-
            Required in workload mode; forbidden when allow_human_callers is
            true.
             Workload callers must hold both inference capability grants.
          type: string
        callerWorkloadFederationTrustId:
          description: >-
            The workload caller's exact federation trust; forbidden in human
            mode.
          type: string
        contentType:
          description: The contentType field.
          type: string
        expectedSecretVersion:
          deprecated: true
          description: >-
            Deprecated setup-time pin. New writes must leave it empty; the
            runtime
             resolves the active version of each target's Vault secret.
          type: string
        nativeFormat:
          description: >-
            Accepted native client request format; never inferred from caller
            headers.
          enum:
            - EDGE_INFERENCE_NATIVE_FORMAT_UNSPECIFIED
            - EDGE_INFERENCE_NATIVE_FORMAT_OPENAI_RESPONSES
            - EDGE_INFERENCE_NATIVE_FORMAT_OPENAI_CHAT
            - EDGE_INFERENCE_NATIVE_FORMAT_ANTHROPIC_MESSAGES
          type: string
          x-speakeasy-unknown-values: allow
        routeId:
          description: >-
            Tenant-owned route identifier, unique within the tenant.
            ListInferenceRoutes
             reports routes already configured for this application, not an allowlist.
          type: string
        secretId:
          description: The secretId field.
          type: string
        selection:
          oneOf:
            - $ref: '#/components/schemas/c1.api.edge.v1.EdgeInferenceSelection'
            - type: 'null'
        targets:
          description: >-
            Explicit upstream targets; no request may choose a target or
            destination.
          items:
            $ref: '#/components/schemas/c1.api.edge.v1.EdgeInferenceTarget'
          type:
            - array
            - 'null'
        upstreamModelId:
          description: Legacy singleton model, empty for graph routes.
          type: string
        vaultBoundaryId:
          description: Legacy singleton Vault reference, empty for graph routes.
          type: string
      title: Edge Inference Route
      type: object
      x-speakeasy-name-override: EdgeInferenceRoute
    c1.api.edge.v1.EdgeTokenResources:
      description: >-
        EdgeTokenResources names the resource URI for each supported Edge
        service.
         A field is empty when its capability is not in enabled_kinds.
      properties:
        egress:
          description: Resource URI used with the egress.connect scope.
          type: string
        inference:
          description: >-
            Resource URI used with the inference.models.read / inference.invoke
            scopes.
          type: string
      title: Edge Token Resources
      type: object
      x-speakeasy-name-override: EdgeTokenResources
    c1.api.edge.v1.EdgeEgressPrincipal:
      description: >
        EdgeEgressPrincipal is the caller a rule matches against. Exactly one
        arm
         must be set.

        This message contains a oneof named scope. Only a single field of the
        following list may be set at a time:
          - all
          - userId
          - entitlementId
      properties:
        all:
          description: >-
            The all field.

            This field is part of the `scope` oneof.

            See the documentation for `c1.api.edge.v1.EdgeEgressPrincipal` for
            more details.
          type:
            - boolean
            - 'null'
        entitlementId:
          description: >-
            An App Entitlement belonging to the same App the Edge belongs to.

            This field is part of the `scope` oneof.

            See the documentation for `c1.api.edge.v1.EdgeEgressPrincipal` for
            more details.
          type:
            - string
            - 'null'
        userId:
          description: >-
            The userId field.

            This field is part of the `scope` oneof.

            See the documentation for `c1.api.edge.v1.EdgeEgressPrincipal` for
            more details.
          type:
            - string
            - 'null'
      title: Edge Egress Principal
      type: object
      x-speakeasy-name-override: EdgeEgressPrincipal
    c1.api.edge.v1.EdgeInferenceSelection:
      description: The EdgeInferenceSelection message.
      properties:
        attemptTimeoutMs:
          description: The attemptTimeoutMs field.
          format: uint32
          type: integer
        confidenceThreshold:
          description: The confidenceThreshold field.
          type: number
        handoffNotes:
          oneOf:
            - $ref: '#/components/schemas/c1.api.edge.v1.EdgeInferenceHandoffNotes'
            - type: 'null'
        maxAttempts:
          description: The maxAttempts field.
          format: uint32
          type: integer
        pickerMode:
          description: The pickerMode field.
          enum:
            - EDGE_INFERENCE_STAGE_PICKER_MODE_UNSPECIFIED
            - EDGE_INFERENCE_STAGE_PICKER_MODE_EFFICIENT_FIRST
            - EDGE_INFERENCE_STAGE_PICKER_MODE_CAPABLE_FIRST
          type: string
          x-speakeasy-unknown-values: allow
        recentWindow:
          description: The recentWindow field.
          format: uint32
          type: integer
        routeDeadlineMs:
          description: The routeDeadlineMs field.
          format: uint32
          type: integer
        stages:
          description: The stages field.
          items:
            $ref: '#/components/schemas/c1.api.edge.v1.EdgeInferenceStage'
          type:
            - array
            - 'null'
        strategy:
          description: The strategy field.
          enum:
            - EDGE_INFERENCE_SELECTION_STRATEGY_UNSPECIFIED
            - EDGE_INFERENCE_SELECTION_STRATEGY_SINGLE
            - EDGE_INFERENCE_SELECTION_STRATEGY_FAILOVER
            - EDGE_INFERENCE_SELECTION_STRATEGY_STAGE_ROUTER
          type: string
          x-speakeasy-unknown-values: allow
        targetIds:
          description: The targetIds field.
          items:
            type: string
          type:
            - array
            - 'null'
      title: Edge Inference Selection
      type: object
      x-speakeasy-name-override: EdgeInferenceSelection
    c1.api.edge.v1.EdgeInferenceTarget:
      description: The EdgeInferenceTarget message.
      properties:
        circuitBreaker:
          oneOf:
            - $ref: '#/components/schemas/c1.api.edge.v1.EdgeInferenceCircuitBreaker'
            - type: 'null'
        contentType:
          description: The contentType field.
          type: string
        contextLength:
          description: The contextLength field.
          format: uint32
          type: integer
        credentialFailurePolicy:
          oneOf:
            - $ref: >-
                #/components/schemas/c1.api.edge.v1.EdgeInferenceCredentialFailurePolicy
            - type: 'null'
        credentialRecipe:
          description: The credentialRecipe field.
          type: string
        credentialSource:
          description: The credentialSource field.
          enum:
            - EDGE_INFERENCE_CREDENTIAL_SOURCE_UNSPECIFIED
            - EDGE_INFERENCE_CREDENTIAL_SOURCE_TENANT_VAULT
            - EDGE_INFERENCE_CREDENTIAL_SOURCE_AWS_WORKLOAD_IDENTITY
          type: string
          x-speakeasy-unknown-values: allow
        destination:
          description: The destination field.
          type: string
        expectedSecretVersion:
          description: >-
            Output-only: resolved active version in the distributed
            configuration.
          type: string
        modelIdGrammar:
          description: The modelIdGrammar field.
          type: string
        providerProfile:
          description: The providerProfile field.
          type: string
        reasoningEffort:
          description: The reasoningEffort field.
          type: string
        region:
          description: The region field.
          type: string
        secretId:
          description: The secretId field.
          type: string
        targetId:
          description: The targetId field.
          type: string
        upstreamModelId:
          description: The upstreamModelId field.
          type: string
        upstreamPath:
          description: The upstreamPath field.
          type: string
        vaultBoundaryId:
          description: The vaultBoundaryId field.
          type: string
      title: Edge Inference Target
      type: object
      x-speakeasy-name-override: EdgeInferenceTarget
    c1.api.edge.v1.EdgeInferenceHandoffNotes:
      description: The EdgeInferenceHandoffNotes message.
      properties:
        deescalationNote:
          description: The deescalationNote field.
          type: string
        escalationNote:
          description: The escalationNote field.
          type: string
        onlyOnWrongSignalEscalation:
          description: The onlyOnWrongSignalEscalation field.
          type: boolean
      title: Edge Inference Handoff Notes
      type: object
      x-speakeasy-name-override: EdgeInferenceHandoffNotes
    c1.api.edge.v1.EdgeInferenceStage:
      description: The EdgeInferenceStage message.
      properties:
        judge:
          oneOf:
            - $ref: '#/components/schemas/c1.api.edge.v1.EdgeInferenceJudge'
            - type: 'null'
        judgeTargetId:
          description: The judgeTargetId field.
          type: string
        stageId:
          description: The stageId field.
          type: string
        targetIds:
          description: The targetIds field.
          items:
            type: string
          type:
            - array
            - 'null'
        tierPrompt:
          description: The tierPrompt field.
          type: string
      title: Edge Inference Stage
      type: object
      x-speakeasy-name-override: EdgeInferenceStage
    c1.api.edge.v1.EdgeInferenceCircuitBreaker:
      description: The EdgeInferenceCircuitBreaker message.
      properties:
        cooldownMs:
          description: The cooldownMs field.
          format: uint32
          type: integer
        failureThreshold:
          description: The failureThreshold field.
          format: uint32
          type: integer
      title: Edge Inference Circuit Breaker
      type: object
      x-speakeasy-name-override: EdgeInferenceCircuitBreaker
    c1.api.edge.v1.EdgeInferenceCredentialFailurePolicy:
      description: The EdgeInferenceCredentialFailurePolicy message.
      properties:
        notApplicable:
          description: The notApplicable field.
          enum:
            - EDGE_INFERENCE_FAILURE_DISPOSITION_UNSPECIFIED
            - EDGE_INFERENCE_FAILURE_DISPOSITION_STOP
            - EDGE_INFERENCE_FAILURE_DISPOSITION_NEXT_TARGET
          type: string
          x-speakeasy-unknown-values: allow
        rejected401:
          description: The rejected401 field.
          enum:
            - EDGE_INFERENCE_FAILURE_DISPOSITION_UNSPECIFIED
            - EDGE_INFERENCE_FAILURE_DISPOSITION_STOP
            - EDGE_INFERENCE_FAILURE_DISPOSITION_NEXT_TARGET
          type: string
          x-speakeasy-unknown-values: allow
        unavailableOrExpired:
          description: The unavailableOrExpired field.
          enum:
            - EDGE_INFERENCE_FAILURE_DISPOSITION_UNSPECIFIED
            - EDGE_INFERENCE_FAILURE_DISPOSITION_STOP
            - EDGE_INFERENCE_FAILURE_DISPOSITION_NEXT_TARGET
          type: string
          x-speakeasy-unknown-values: allow
      title: Edge Inference Credential Failure Policy
      type: object
      x-speakeasy-name-override: EdgeInferenceCredentialFailurePolicy
    c1.api.edge.v1.EdgeInferenceJudge:
      description: The EdgeInferenceJudge message.
      properties:
        baseThreshold:
          description: The baseThreshold field.
          type: number
        maxOutputTokens:
          description: Maximum tokens available to classify a stage result (1 to 16,384).
          format: uint32
          type: integer
        prompt:
          description: The prompt field.
          type: string
        recentTurnWindow:
          description: The recentTurnWindow field.
          format: uint32
          type: integer
        thresholdStep:
          description: The thresholdStep field.
          type: number
      title: Edge Inference Judge
      type: object
      x-speakeasy-name-override: EdgeInferenceJudge
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````