> ## Documentation Index
> Fetch the complete documentation index at: https://developers.authlete.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Granted Scopes

> Get the set of scopes that a user has granted to a client application.

<Accordion title="Full description" defaultOpen={false}>
  Possible values for `requestableScopes` parameter in the response from this API are as follows.

  ## null

  The user has not granted authorization to the client application in the past, or records about the
  combination of the user and the client application have been deleted from Authlete's DB.

  ## An empty set

  The user has granted authorization to the client application in the past, but no scopes are associated
  with the authorization.

  ## A set with at least one element

  The user has granted authorization to the client application in the past and some scopes are associated
  with the authorization. These scopes are returned.
  Example: `[ "profile", "email" ]`
  The subject parameter is required and must be provided as a query parameter.
</Accordion>


## OpenAPI

````yaml https://spec.speakeasy.com/authlete/sdk-workspace/authlete-api-explorer-with-code-samples get /api/{serviceId}/client/granted_scopes/get/{clientId}
openapi: 3.0.3
info:
  title: Authlete API
  description: ''
  version: 3.0.16
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
servers:
  - description: 🇺🇸 US Cluster
    url: https://us.authlete.com
  - description: 🇯🇵 Japan Cluster
    url: https://jp.authlete.com
  - description: 🇪🇺 Europe Cluster
    url: https://eu.authlete.com
  - description: 🇧🇷 Brazil Cluster
    url: https://br.authlete.com
security:
  - bearer: []
tags:
  - name: Service Management
    description: >-
      API endpoints for managing services, including creation, update, and
      deletion of services.
    x-tag-expanded: false
  - name: Client Management
    description: >-
      API endpoints for managing OAuth clients, including creation, update, and
      deletion of clients.
    x-tag-expanded: false
  - name: Authorization Endpoint
    description: API endpoints for implementing OAuth 2.0 Authorization Endpoint.
    x-tag-expanded: false
  - name: Pushed Authorization Endpoint
    description: >-
      API endpoints for implementing OAuth 2.0 Pushed Authorization Requests
      (PAR).
    x-tag-expanded: false
  - name: Token Endpoint
    description: API endpoints for implementing OAuth 2.0 Token Endpoint.
    x-tag-expanded: false
  - name: Token Operations
    description: >-
      API endpoints for various token related operations, including creating,
      revoking and deleting access_tokens with specified scopes.
    x-tag-expanded: false
  - name: Introspection Endpoint
    description: API endpoints for implementing OAuth 2.0 Introspection Endpoint.
    x-tag-expanded: false
  - name: Revocation Endpoint
    description: API endpoint for implementing OAuth 2.0 Revocation Endpoint.
    x-tag-expanded: false
  - name: UserInfo Endpoint
    description: API endpoints for implementing OpenID Connect UserInfo Endpoint.
    x-tag-expanded: false
  - name: JWK Set Endpoint
    description: API endpoints for to generate JSON Web Key Set (JWKS) for a service.
    x-tag-expanded: false
  - name: Discovery Endpoint
    description: API endpoints for implementing OpenID Connect Discovery.
    x-tag-expanded: false
  - name: Configuration Endpoint
    description: API endpoint for accessing configuration settings for a service.
    x-tag-expanded: false
  - name: Dynamic Client Registration
    description: API endpoints for implementing OAuth 2.0 Dynamic Client Registration.
    x-tag-expanded: false
  - name: CIBA
    description: >-
      API endpoints for implementing Client-Initiated Backchannel Authentication
      (CIBA).
    x-tag-expanded: false
  - name: Grant Management Endpoint
    description: >-
      API endpoint for implementing OAuth 2.0 grants, including grant management
      actions like updating and revoking grants.
    x-tag-expanded: false
  - name: Jose Object
    description: API endpoints for JOSE objects.
    x-tag-expanded: false
  - name: Device Flow
    description: API endpoints for implementing OAuth 2.0 Device Flow
    x-tag-expanded: false
  - name: Federation Endpoint
    description: API endpoints for implementing OpenID Federation using Authlete.
    x-tag-expanded: false
  - name: Verifiable Credential Issuer
    description: >-
      API endpoints for implementing and running a Verifiable Credential Issuer
      (VCI).
    x-tag-expanded: false
  - name: Hardware Security Key
    description: API endpoints for managing hardware security keys (HSK).
    x-tag-expanded: false
  - name: Utility Endpoints
    description: API endpoints for various utility operations.
    x-tag-expanded: false
  - name: Native SSO
    description: API endpoints for Native SSO
    x-tag-expanded: false
paths:
  /api/{serviceId}/client/granted_scopes/get/{clientId}:
    get:
      tags:
        - Client Management
      summary: Get Granted Scopes
      description: |
        Get the set of scopes that a user has granted to a client application.
      operationId: client_granted_scopes_get_api
      parameters:
        - in: path
          name: serviceId
          description: A service ID.
          required: true
          schema:
            type: string
          example: '715948317'
        - in: path
          name: clientId
          schema:
            type: string
          required: true
          description: |
            A client ID.
          example: '1140735077'
        - in: query
          name: subject
          schema:
            type: string
          required: true
          description: |
            Unique user ID of an end-user.
      responses:
        '200':
          description: Successfully retrieved granted scopes
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/client_authorization_delete_response'
              example:
                type: GrantedScopesGetResponse
                serviceApiKey: 21653835348762
                clientId: 26478243745571
                subject: john
                latestGrantedScopes:
                  - history.read
                mergedGrantedScopes:
                  - history.read
                  - timeline.read
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '403':
          $ref: '#/components/responses/403'
        '500':
          $ref: '#/components/responses/500'
      x-codeSamples:
        - lang: typescript
          label: Typescript (SDK)
          source: |-
            import { Authlete } from "@authlete/typescript-sdk";

            const authlete = new Authlete({
              bearer: process.env["AUTHLETE_BEARER"] ?? "",
            });

            async function run() {
              const result = await authlete.clientManagement.clientGrantedScopesGetApi({
                serviceId: "715948317",
                clientId: "1140735077",
                subject: "<value>",
              });

              console.log(result);
            }

            run();
        - lang: ruby
          label: Ruby (SDK)
          source: >-
            require 'authlete_ruby_sdk'


            Models = ::Authlete::Models

            s = ::Authlete::Client.new(
              bearer: '<YOUR_BEARER_TOKEN_HERE>'
            )

            res = s.client_management.client_granted_scopes_get_api(service_id:
            '715948317', client_id: '1140735077', subject: '<value>')


            unless res.client_authorization_delete_response.nil?
              # handle response
            end
        - lang: go
          label: Go (SDK)
          source: "package main\n\nimport(\n\t\"context\"\n\t\"os\"\n\tauthlete \"github.com/authlete/authlete-go-sdk\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := authlete.New(\n        authlete.WithSecurity(os.Getenv(\"AUTHLETE_BEARER\")),\n    )\n\n    res, err := s.Client.Management.GetGrantedScopesForClient(ctx, \"715948317\", \"1140735077\", \"<value>\")\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.ClientAuthorizationDeleteResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    client_authorization_delete_response:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
        serviceApiKey:
          type: integer
          format: int64
          description: A short message which explains the result of the API call.
        clientId:
          type: integer
          format: int64
          description: Get the client ID.
        subject:
          type: string
          description: |
            Get the subject (= unique identifier) of the user
            who has granted authorization to the client.
        latestGrantedScopes:
          type: array
          items:
            type: string
          description: |
            Get the scopes granted to the client application by the last
            authorization process by the user (who is identified by the
            subject).
        mergedGrantedScopes:
          type: array
          items:
            type: string
          description: |
            Get the scopes granted to the client application by all the
            past authorization processes. Note that revoked scopes are
            not included.
        modifiedAt:
          type: integer
          format: int64
          description: |
            Get the timestamp in milliseconds since Unix epoch
            at which this record was modified.
    result:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
  responses:
    '400':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001201
            resultMessage: '[A001201] /auth/authorization, TLS must be used.'
    '401':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001202
            resultMessage: '[A001202] /auth/authorization, Authorization header is missing.'
    '403':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001215
            resultMessage: >-
              [A001215] /auth/authorization, The client (ID = 26837717140341) is
              locked.
    '500':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001101
            resultMessage: '[A001101] /auth/authorization, Authlete Server error.'
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Authenticate every request with a **Service Access Token** or
        **Organization Token**.

        Set the token value in the `Authorization: Bearer <token>` header.


        **Service Access Token**: Scoped to a single service. Use when
        automating service-level configuration or runtime flows.


        **Organization Token**: Scoped to the organization; inherits permissions
        across services. Use for org-wide automation or when managing multiple
        services programmatically.


        Both token types are issued by the Authlete console or provisioning
        APIs.

````