---
title: "Create Function"
method: POST
path: "/api/v1/functions"
tags: ["Function"]
---

# Create Function

`POST /api/v1/functions`

CreateFunction registers a new serverless function and creates its initial code commit.

## Request body

- C1ApiFunctionsV1FunctionsServiceCreateFunctionRequest — The FunctionsServiceCreateFunctionRequest message.
  - `commitMessage` string — The commit message describing the initial code submission.
  - `description` string — A description of what the function does.
  - `displayName` string — The human-readable name for the function.
  - `functionType` 'FUNCTION_TYPE_UNSPECIFIED' | 'FUNCTION_TYPE_ANY' | 'FUNCTION_TYPE_CODE_MODE' — The type of function to create, controlling its execution environment and capabilities.
  - `initialContent` object — Map of filename to file content for the initial code commit.

## Response `200`

Successful response

- C1ApiFunctionsV1FunctionsServiceCreateFunctionResponse — The FunctionsServiceCreateFunctionResponse message.
  - `commit` C1ApiFunctionsV1FunctionCommit — FunctionCommit represents a single commit in a function's history
    - `author` string — The author field.
    - `createdAt` string, date-time
    - `functionId` string — The functionId field.
    - `id` string — The id field.
    - `message` string — The message field.
  - `function` C1ApiFunctionsV1Function — Function represents a customer-provided code extension in the API
    - `createdAt` string, date-time
    - `deletedAt` string, date-time
    - `description` string — The description field.
    - `displayName` string — The displayName field.
    - `functionType` 'FUNCTION_TYPE_UNSPECIFIED' | 'FUNCTION_TYPE_ANY' | 'FUNCTION_TYPE_CODE_MODE' — The functionType field.
    - `head` string — The head field.
    - `id` string — The id field.
    - `isDraft` boolean — The isDraft field.
    - `outboundNetworkAllowlist` string[], nullable — The outboundNetworkAllowlist field.
    - `publishedCommitId` string — The publishedCommitId field.
    - `scopedRoleIds` string[], nullable — Scoped role IDs define the permissions granted to this function when calling ConductorOne APIs. These are role IDs (not service roles) that get resolved to their service roles at authentication time. Currently only the "Read-Only Administrator" role (system:viewer) is supported. The role ID can be obtained from the roles API.
    - `secret` object — The secret field.
    - `updatedAt` string, date-time
    - `useSpn` boolean — FN-347 transition flag. When true, the function authenticates to c1-api as user:<sp_id> via the AssumeIdentity token exchange using its ServicePrincipalBinding; when false, it authenticates as function:<id>. Read-only from clients: set by CreateFunction (when the tenant has completed the FunctionsToSPN migration) and by the migration itself, never by UpdateFunction. Retired once all functions are on SPN.

---

[API](https://skmtc.net/conductorone/apis/c1-api.md) · [All operations](https://skmtc.net/conductorone/apis/c1-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/conductorone/c1-api/versions/d391405a35d3/schema)
