---
title: "List group shares"
method: GET
path: "/api/apps/{app_id}/group-shares"
---

# List group shares

`GET /api/apps/{app_id}/group-shares`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Returns the workspace groups the app is shared with.

Every member of a shared group can use the app. A member's role in the app is the highest of the role you gave them directly and the roles of all the groups they're in that the app is shared with. Change a group's role with [Update group share](/api-reference/update-group-share), or stop sharing with [Remove group share](/api-reference/remove-group-share).

The response lists every share at once, with no paging. You need editor access to the app, and an editor or admin role in the app's workspace.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>

## Path parameters

- `app_id` string, required — ID of the app.

## Response `200`

The app's group shares.

- ShareListResponse
  - `shares` ShareSummary[], required — The app's group shares.
    - `id` string, required — ID of the share. Pass it as `share_id` to update or remove the share.
    - `group_id` string, required — ID of the workspace group the app is shared with.
    - `group_name` string, nullable, required — Name of the group, or `null` when the group was deleted. A share whose group was deleted grants no access, and you can still remove it.
    - `group_source` string, nullable, required — Where the group comes from: `custom` for a group created in Base44, or `idp` for a group your identity provider syncs over SCIM. `null` when the group was deleted.
    - `member_count` integer, required — Number of group members with a Base44 account.
    - `unresolved_count` integer, required — Number of group members your identity provider synced who don't have a Base44 account yet. They get access once they have one.
    - `role` string, nullable, required — App role the share gives the group's members, or `null` when it assigns none and members get the default `user` role.
    - `created_by` string, nullable, required — Email of the person who shared the app with the group.
    - `created_date` string, nullable, required — When the app was shared with the group, in UTC, as ISO 8601 without a timezone suffix.

## Other responses

- `401` — Missing or invalid credentials.
- `403` — You don't have editor access to this app, you aren't an editor or admin in the app's workspace, or your API key is read-only.
- `404` — App not found.

## Changes

- **2026-09-27** `5e69adeb8667` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/base44/apis/base44-app-management-api/changes/api/apps/:app_id/group-shares/get.md)

---

[API](https://skmtc.dev/base44/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/base44/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/base44/apis/base44-app-management-api/revisions/5e69adeb8667?raw)
