---
title: "Search"
method: POST
path: "/api/v1/search/functions"
tags: ["Function"]
---

# Search

`POST /api/v1/search/functions`

Search searches for functions based on criteria

## Request body

- C1ApiFunctionsV1FunctionsSearchRequest — The FunctionsSearchRequest message.
  - `functionTypes` string[], nullable — The functionTypes field.
  - `pageSize` integer — The pageSize field.
  - `pageToken` string — The pageToken field.
  - `query` string — The query field.

## Response `200`

Successful response

- C1ApiFunctionsV1FunctionsSearchResponse — The FunctionsSearchResponse message.
  - `list` C1ApiFunctionsV1Function[], nullable — The list field.
    - `createdAt` string, date-time, nullable
    - `deletedAt` string, date-time, nullable
    - `description` string — The description field.
    - `displayName` string — The displayName field.
    - `functionType` 'FUNCTION_TYPE_UNSPECIFIED' | 'FUNCTION_TYPE_ANY' | 'FUNCTION_TYPE_CODE_MODE' — The functionType field.
    - `head` string — The head field.
    - `hookRefs` string[], nullable — IDs of every non-deleted hook that still references this function. Read-only: maintained by the Hook API, not by CreateFunction/UpdateFunction. Non-empty means DeleteFunction will refuse to delete until these are removed or retargeted.
    - `id` string — The id field.
    - `isDraft` boolean — The isDraft field.
    - `outboundNetworkAllowlist` string[], nullable — The outboundNetworkAllowlist field.
    - `provisionedConcurrency` integer — Number of pre-warmed Lambda instances. 0 (default) leaves the function cold-started on first invoke. > 0 reserves and provisions that many execution environments via AWS Lambda provisioned concurrency. Ignored for FUNCTION_TYPE_CODE_MODE functions — that value is driven by AIGovernanceSettings.code_mode_concurrency.
    - `publishedCommitId` string — The publishedCommitId field.
    - `scopedRoleIds` string[], nullable — Scoped role IDs define the permissions granted to this function when calling ConductorOne APIs. These are role IDs (not service roles) that get resolved to their service roles at authentication time. Currently only the "Read-Only Administrator" role (system:viewer) is supported. The role ID can be obtained from the roles API.
    - `secret` object — The secret field.
    - `updatedAt` string, date-time, nullable
    - `useSpn` boolean — FN-347 transition flag. When true, the function authenticates to c1-api as user:<sp_id> via the AssumeIdentity token exchange using its ServicePrincipalBinding; when false, it authenticates as function:<id>. Read-only from clients: set by CreateFunction (when the tenant has completed the FunctionsToSPN migration) and by the migration itself, never by UpdateFunction. Retired once all functions are on SPN.
    - `workflowTemplateRefs` string[], nullable — IDs of every non-deleted workflow template whose CallFunction step still references this function. Read-only, same semantics as hook_refs.
  - `nextPageToken` string — The nextPageToken field.

---

[API](https://skmtc.net/conductorone/apis/c1-api.md) · [All operations](https://skmtc.net/conductorone/apis/c1-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/conductorone/c1-api/revisions/f2cf3228f366/schema)
