---
title: "Browse"
method: POST
path: "/v2/browse/first"
tags: ["General"]
---

# Browse

`POST /v2/browse/first`

Browse a a node to discover its references. For more information consult <a href="https://reference.opcfoundation.org/Core/Part4/v105/docs/5.8.2"> the relevant section of the OPC UA reference specification</a>. The operation might return a continuation token. The continuation token can be used in the BrowseNext method call to retrieve the remainder of references or additional continuation tokens.

## Request body

- BrowseFirstRequestModelRequestEnvelope — Wraps a request and a connection to bind to a body more easily for api that requires a connection endpoint
  - `connection` ConnectionModel, required — Connection model
    - `endpoint` EndpointModel, required — Endpoint model
      - `url` string, required — Endpoint url to use to connect with
      - `alternativeUrls` string[] — Alternative endpoint urls that can be used for accessing and validating the server
      - `securityMode` 'Best' | 'Sign' | 'SignAndEncrypt' | 'None' | 'NotNone' — Specifies the security mode for OPC UA endpoint connections. Determines how messages are protected during transmission between the Publisher and OPC UA servers. Proper security mode selection is crucial for protecting sensitive data and credentials.
      - `securityPolicy` string — Security policy uri to use for communication. default to best.
      - `certificate` string — Endpoint certificate thumbprint
    - `user` CredentialModel — Credential model. For backwards compatibility the actual credentials to pass to the server is set through the value property.
      - `type` 'None' | 'UserName' | 'X509Certificate' | 'JwtToken' — Type of credentials to use for authentication
      - `value` UserIdentityModel — User identity model
        - `user` string — For Azure.IIoT.OpcUa.Publisher.Models.CredentialType.UserName authentication this is the name of the user. For Azure.IIoT.OpcUa.Publisher.Models.CredentialType.X509Certificate authentication this is the subject name of the certificate that has been configured. Either Azure.IIoT.OpcUa.Publisher.Models.UserIdentityModel.User or Azure.IIoT.OpcUa.Publisher.Models.UserIdentityModel.Thumbprint must be used to select the certificate in the user certificate store. Not used for the other authentication types.
        - `password` string — For Azure.IIoT.OpcUa.Publisher.Models.CredentialType.UserName authentication this is the password of the user. For Azure.IIoT.OpcUa.Publisher.Models.CredentialType.X509Certificate authentication this is the passcode to export the configured certificate's private key. Not used for the other authentication types.
        - `thumbprint` string — For Azure.IIoT.OpcUa.Publisher.Models.CredentialType.X509Certificate authentication this is the thumbprint of the configured certificate to use. Either Azure.IIoT.OpcUa.Publisher.Models.UserIdentityModel.User or Azure.IIoT.OpcUa.Publisher.Models.UserIdentityModel.Thumbprint must be used to select the certificate in the user certificate store. Not used for the other authentication types.
    - `diagnostics` DiagnosticsModel — Diagnostics configuration
      - `level` 'None' | 'Status' | 'Information' | 'Debug' | 'Verbose' — Level of diagnostics requested in responses
      - `auditId` string — Client audit log entry. (default: client generated)
      - `timeStamp` string, date-time — Timestamp of request. (default: client generated)
    - `group` string — Connection group allows splitting connections per purpose.
    - `locales` string[] — Optional list of preferred locales in preference order.
    - `options` 'None' | 'UseReverseConnect' | 'NoComplexTypeSystem' | 'NoSubscriptionTransfer' | 'DumpDiagnostics' — Options that can be applied to a connection
  - `request` BrowseFirstRequestModel — Browse request model
    - `nodeId` string — Node to browse. (defaults to root folder).
    - `direction` 'Forward' | 'Backward' | 'Both' — Direction to browse
    - `view` BrowseViewModel — View to browse
      - `viewId` string, required — Node of the view to browse
      - `version` integer — Browses specific version of the view.
      - `timestamp` string, date-time — Browses at or before this timestamp.
    - `referenceTypeId` string — Reference types to browse. (default: hierarchical).
    - `noSubtypes` boolean — Whether to include subtypes of the reference type. (default is false)
    - `maxReferencesToReturn` integer — Max number of references to return. There might be less returned as this is up to the client restrictions. Set to 0 to return no references or target nodes. (default is decided by client e.g. 60)
    - `targetNodesOnly` boolean — Whether to collapse all references into a set of unique target nodes and not show reference information. (default is false)
    - `readVariableValues` boolean — Whether to read variable values on target nodes. (default is false)
    - `nodeClassFilter` 'Object' | 'Variable' | 'Method' | 'ObjectType' | 'VariableType' | 'ReferenceType' | 'DataType' | 'View' — Filter returned target nodes by only returning nodes that have classes defined in this array. (default: null - all targets are returned)
    - `header` RequestHeaderModel — Request header model
      - `elevation` CredentialModel — Credential model. For backwards compatibility the actual credentials to pass to the server is set through the value property.
        - `type` 'None' | 'UserName' | 'X509Certificate' | 'JwtToken' — Type of credentials to use for authentication
        - `value` UserIdentityModel — User identity model
          - `user` string — For Azure.IIoT.OpcUa.Publisher.Models.CredentialType.UserName authentication this is the name of the user. For Azure.IIoT.OpcUa.Publisher.Models.CredentialType.X509Certificate authentication this is the subject name of the certificate that has been configured. Either Azure.IIoT.OpcUa.Publisher.Models.UserIdentityModel.User or Azure.IIoT.OpcUa.Publisher.Models.UserIdentityModel.Thumbprint must be used to select the certificate in the user certificate store. Not used for the other authentication types.
          - `password` string — For Azure.IIoT.OpcUa.Publisher.Models.CredentialType.UserName authentication this is the password of the user. For Azure.IIoT.OpcUa.Publisher.Models.CredentialType.X509Certificate authentication this is the passcode to export the configured certificate's private key. Not used for the other authentication types.
          - `thumbprint` string — For Azure.IIoT.OpcUa.Publisher.Models.CredentialType.X509Certificate authentication this is the thumbprint of the configured certificate to use. Either Azure.IIoT.OpcUa.Publisher.Models.UserIdentityModel.User or Azure.IIoT.OpcUa.Publisher.Models.UserIdentityModel.Thumbprint must be used to select the certificate in the user certificate store. Not used for the other authentication types.
      - `locales` string[] — Optional list of preferred locales in preference order to be used during connecting the session. We suggest to use the connection object to set the locales
      - `diagnostics` DiagnosticsModel — Diagnostics configuration
        - `level` 'None' | 'Status' | 'Information' | 'Debug' | 'Verbose' — Level of diagnostics requested in responses
        - `auditId` string — Client audit log entry. (default: client generated)
        - `timeStamp` string, date-time — Timestamp of request. (default: client generated)
      - `namespaceFormat` 'Uri' | 'Index' | 'Expanded' | 'ExpandedWithNamespace0' — Namespace serialization format for node ids and qualified names.
      - `operationTimeout` integer — Operation timeout in ms. This applies to every operation that is invoked, not to the entire transaction and overrides the configured operation timeout.
      - `serviceCallTimeout` integer — Service call timeout in ms. As opposed to the operation timeout this terminates the entire transaction if it takes longer than the timeout to complete. Note that a connect and reconnect during the service call is gated by the connect timeout setting. If a connect timeout is not specified this timeout is used also for connect timeout.
      - `connectTimeout` integer — Connect timeout in ms. As opposed to the service call timeout this terminates the entire transaction if it takes longer than the timeout to connect a session A connect and reconnect during the service call resets the timeout therefore the overall time for the call to complete can be longer than specified.
    - `nodeIdsOnly` boolean — Whether to only return the raw node id information and not read the target node. (default is false)

## Response `200`

The operation was successful or the response payload contains relevant error information.

- BrowseFirstResponseModel — Browse response model
  - `node` NodeModel, required — Node model
    - `nodeClass` 'Object' | 'Variable' | 'Method' | 'ObjectType' | 'VariableType' | 'ReferenceType' | 'DataType' | 'View' — Node class
    - `displayName` string — Display name
    - `nodeId` string, required — Id of node. (Mandatory).
    - `description` string — Description if any
    - `browseName` string — Browse name
    - `value` object — Value of variable or default value of the subtyped variable in case node is a variable type, otherwise null.
    - `sourcePicoseconds` integer — Pico seconds part of when value was read at source.
    - `sourceTimestamp` string, date-time — Timestamp of when value was read at source.
    - `serverPicoseconds` integer — Pico seconds part of when value was read at server.
    - `serverTimestamp` string, date-time — Timestamp of when value was read at server.
    - `errorInfo` ServiceResultModel — Service result
      - `statusCode` integer — Error code - if null operation succeeded.
      - `errorMessage` string — Error message in case of error or null.
      - `symbolicId` string — Symbolic identifier
      - `locale` string — Locale of the error message
      - `additionalInfo` string — Additional information if available
      - `namespaceUri` string — Namespace uri
      - `inner` ServiceResultModel — recursive
    - `accessRestrictions` 'None' | 'SigningRequired' | 'EncryptionRequired' | 'SessionRequired' — Flags that can be read or written in the AccessRestrictions attribute.
    - `writeMask` integer — Default write mask for the node (default: 0)
    - `userWriteMask` integer — User write mask for the node (default: 0)
    - `isAbstract` boolean — Whether type is abstract, if type can be abstract. Null if not type node. (default: false)
    - `containsNoLoops` boolean — Whether a view contains loops. Null if not a view.
    - `eventNotifier` 'SubscribeToEvents' | 'HistoryRead' | 'HistoryWrite' — Flags that can be set for the EventNotifier attribute.
    - `executable` boolean — If method node class, whether method can be called.
    - `userExecutable` boolean — If method node class, whether method can be called by current user. (default: false if not executable)
    - `dataTypeDefinition` object — Data type definition in case node is a data type node and definition is available, otherwise null.
    - `accessLevel` 'None' | 'CurrentRead' | 'CurrentWrite' | 'HistoryRead' | 'HistoryWrite' | 'SemanticChange' | 'StatusWrite' | 'TimestampWrite' | 'NonatomicRead' | 'NonatomicWrite' | 'WriteFullArrayOnly' — Flags that can be set for the AccessLevel attribute.
    - `userAccessLevel` 'None' | 'CurrentRead' | 'CurrentWrite' | 'HistoryRead' | 'HistoryWrite' | 'SemanticChange' | 'StatusWrite' | 'TimestampWrite' | 'NonatomicRead' | 'NonatomicWrite' | 'WriteFullArrayOnly' — Flags that can be set for the AccessLevel attribute.
    - `dataType` string — If variable the datatype of the variable. (default: null)
    - `valueRank` 'OneOrMoreDimensions' | 'OneDimension' | 'TwoDimensions' | 'ScalarOrOneDimension' | 'Any' | 'Scalar' — Constants defined for the ValueRank attribute.
    - `arrayDimensions` integer — Array dimensions of variable or variable type. (default: empty array)
    - `historizing` boolean — Whether the value of a variable is historizing. (default: false)
    - `minimumSamplingInterval` number, double — Minimum sampling interval for the variable value, otherwise null if not a variable node. (default: null)
    - `inverseName` string — Inverse name of the reference if the node is a reference type, otherwise null.
    - `symmetric` boolean — Whether the reference is symmetric in case the node is a reference type, otherwise null.
    - `rolePermissions` RolePermissionModel[] — Role permissions
      - `roleId` string, required — Identifier of the role object.
      - `permissions` 'None' | 'Browse' | 'ReadRolePermissions' | 'WriteAttribute' | 'WriteRolePermissions' | 'WriteHistorizing' | 'Read' | 'Write' | 'ReadHistory' | 'InsertHistory' | 'ModifyHistory' | 'DeleteHistory' | 'ReceiveEvents' | 'Call' | 'AddReference' | 'RemoveReference' | 'DeleteNode' | 'AddNode' — Individual permissions assigned to a role
    - `userRolePermissions` RolePermissionModel[] — User Role permissions
      - `roleId` string, required — Identifier of the role object.
      - `permissions` 'None' | 'Browse' | 'ReadRolePermissions' | 'WriteAttribute' | 'WriteRolePermissions' | 'WriteHistorizing' | 'Read' | 'Write' | 'ReadHistory' | 'InsertHistory' | 'ModifyHistory' | 'DeleteHistory' | 'ReceiveEvents' | 'Call' | 'AddReference' | 'RemoveReference' | 'DeleteNode' | 'AddNode' — Individual permissions assigned to a role
    - `typeDefinitionId` string — Optional type definition of the node
    - `children` boolean — Whether node has children which are defined as any forward hierarchical references. (default: unknown)
  - `references` NodeReferenceModel[], required — References returned
    - `referenceTypeId` string — Reference Type id
    - `direction` 'Forward' | 'Backward' | 'Both' — Direction to browse
    - `target` NodeModel, required — Node model
      - `nodeClass` 'Object' | 'Variable' | 'Method' | 'ObjectType' | 'VariableType' | 'ReferenceType' | 'DataType' | 'View' — Node class
      - `displayName` string — Display name
      - `nodeId` string, required — Id of node. (Mandatory).
      - `description` string — Description if any
      - `browseName` string — Browse name
      - `value` object — Value of variable or default value of the subtyped variable in case node is a variable type, otherwise null.
      - `sourcePicoseconds` integer — Pico seconds part of when value was read at source.
      - `sourceTimestamp` string, date-time — Timestamp of when value was read at source.
      - `serverPicoseconds` integer — Pico seconds part of when value was read at server.
      - `serverTimestamp` string, date-time — Timestamp of when value was read at server.
      - `errorInfo` ServiceResultModel — Service result
        - `statusCode` integer — Error code - if null operation succeeded.
        - `errorMessage` string — Error message in case of error or null.
        - `symbolicId` string — Symbolic identifier
        - `locale` string — Locale of the error message
        - `additionalInfo` string — Additional information if available
        - `namespaceUri` string — Namespace uri
        - `inner` ServiceResultModel — recursive
      - `accessRestrictions` 'None' | 'SigningRequired' | 'EncryptionRequired' | 'SessionRequired' — Flags that can be read or written in the AccessRestrictions attribute.
      - `writeMask` integer — Default write mask for the node (default: 0)
      - `userWriteMask` integer — User write mask for the node (default: 0)
      - `isAbstract` boolean — Whether type is abstract, if type can be abstract. Null if not type node. (default: false)
      - `containsNoLoops` boolean — Whether a view contains loops. Null if not a view.
      - `eventNotifier` 'SubscribeToEvents' | 'HistoryRead' | 'HistoryWrite' — Flags that can be set for the EventNotifier attribute.
      - `executable` boolean — If method node class, whether method can be called.
      - `userExecutable` boolean — If method node class, whether method can be called by current user. (default: false if not executable)
      - `dataTypeDefinition` object — Data type definition in case node is a data type node and definition is available, otherwise null.
      - `accessLevel` 'None' | 'CurrentRead' | 'CurrentWrite' | 'HistoryRead' | 'HistoryWrite' | 'SemanticChange' | 'StatusWrite' | 'TimestampWrite' | 'NonatomicRead' | 'NonatomicWrite' | 'WriteFullArrayOnly' — Flags that can be set for the AccessLevel attribute.
      - `userAccessLevel` 'None' | 'CurrentRead' | 'CurrentWrite' | 'HistoryRead' | 'HistoryWrite' | 'SemanticChange' | 'StatusWrite' | 'TimestampWrite' | 'NonatomicRead' | 'NonatomicWrite' | 'WriteFullArrayOnly' — Flags that can be set for the AccessLevel attribute.
      - `dataType` string — If variable the datatype of the variable. (default: null)
      - `valueRank` 'OneOrMoreDimensions' | 'OneDimension' | 'TwoDimensions' | 'ScalarOrOneDimension' | 'Any' | 'Scalar' — Constants defined for the ValueRank attribute.
      - `arrayDimensions` integer — Array dimensions of variable or variable type. (default: empty array)
      - `historizing` boolean — Whether the value of a variable is historizing. (default: false)
      - `minimumSamplingInterval` number, double — Minimum sampling interval for the variable value, otherwise null if not a variable node. (default: null)
      - `inverseName` string — Inverse name of the reference if the node is a reference type, otherwise null.
      - `symmetric` boolean — Whether the reference is symmetric in case the node is a reference type, otherwise null.
      - `rolePermissions` RolePermissionModel[] — Role permissions
        - `roleId` string, required — Identifier of the role object.
        - `permissions` 'None' | 'Browse' | 'ReadRolePermissions' | 'WriteAttribute' | 'WriteRolePermissions' | 'WriteHistorizing' | 'Read' | 'Write' | 'ReadHistory' | 'InsertHistory' | 'ModifyHistory' | 'DeleteHistory' | 'ReceiveEvents' | 'Call' | 'AddReference' | 'RemoveReference' | 'DeleteNode' | 'AddNode' — Individual permissions assigned to a role
      - `userRolePermissions` RolePermissionModel[] — User Role permissions
        - `roleId` string, required — Identifier of the role object.
        - `permissions` 'None' | 'Browse' | 'ReadRolePermissions' | 'WriteAttribute' | 'WriteRolePermissions' | 'WriteHistorizing' | 'Read' | 'Write' | 'ReadHistory' | 'InsertHistory' | 'ModifyHistory' | 'DeleteHistory' | 'ReceiveEvents' | 'Call' | 'AddReference' | 'RemoveReference' | 'DeleteNode' | 'AddNode' — Individual permissions assigned to a role
      - `typeDefinitionId` string — Optional type definition of the node
      - `children` boolean — Whether node has children which are defined as any forward hierarchical references. (default: unknown)
    - `errorInfo` ServiceResultModel — Service result
      - `statusCode` integer — Error code - if null operation succeeded.
      - `errorMessage` string — Error message in case of error or null.
      - `symbolicId` string — Symbolic identifier
      - `locale` string — Locale of the error message
      - `additionalInfo` string — Additional information if available
      - `namespaceUri` string — Namespace uri
      - `inner` ServiceResultModel — recursive
  - `continuationToken` string — Continuation token if more results pending.
  - `errorInfo` ServiceResultModel — Service result
    - `statusCode` integer — Error code - if null operation succeeded.
    - `errorMessage` string — Error message in case of error or null.
    - `symbolicId` string — Symbolic identifier
    - `locale` string — Locale of the error message
    - `additionalInfo` string — Additional information if available
    - `namespaceUri` string — Namespace uri
    - `inner` ServiceResultModel — recursive

## Other responses

- `400` — The passed in information is invalid
- `408` — The operation timed out.
- `500` — An unexpected error occurred

---

[API](https://skmtc.net/azure/apis/opcpublisher.md) · [All operations](https://skmtc.net/azure/apis/opcpublisher/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/azure/opcpublisher/versions/8eac19a554d6/schema)
