---
title: "GET /requests/grant-requests/"
method: GET
path: "/requests/grant-requests/"
tags: ["requests"]
---

# GET /requests/grant-requests/

`GET /requests/grant-requests/`

## Query parameters

- `agent_owner` integer
- `created_by` integer
- `ordering` string
- `page` integer
- `page_size` integer
- `search` string
- `status` 'created' | 'approved' | 'denied' | 'revoked'

## Response `200`

- PaginatedGrantRequestList
  - `pagination` Pagination, required
    - `next` number, required
    - `previous` number, required
    - `count` number, required
    - `current` number, required
    - `total_pages` number, required
    - `start_index` number, required
    - `end_index` number, required
  - `results` GrantRequest[], required
    - `created` string, date-time, required
    - `created_by` PartialUser, required — Partial User Serializer, does not include child relations.
      - `pk` integer, required
      - `username` string, required — Required. 150 characters or fewer. Letters, digits and @/./+/-/_ only.
      - `name` string, required — User's display name.
      - `is_active` boolean — Designates whether this user should be treated as active. Unselect this instead of deleting accounts.
      - `last_login` string, date-time, nullable
      - `email` string, email
      - `attributes` object
      - `uid` string, required
    - `requester_data` object
    - `fulfiller_data` object
    - `revoked_by` PartialUser, required — Partial User Serializer, does not include child relations.
      - `pk` integer, required
      - `username` string, required — Required. 150 characters or fewer. Letters, digits and @/./+/-/_ only.
      - `name` string, required — User's display name.
      - `is_active` boolean — Designates whether this user should be treated as active. Unselect this instead of deleting accounts.
      - `last_login` string, date-time, nullable
      - `email` string, email
      - `attributes` object
      - `uid` string, required
    - `agent_owner` PartialUser, required — Partial User Serializer, does not include child relations.
      - `pk` integer, required
      - `username` string, required — Required. 150 characters or fewer. Letters, digits and @/./+/-/_ only.
      - `name` string, required — User's display name.
      - `is_active` boolean — Designates whether this user should be treated as active. Unselect this instead of deleting accounts.
      - `last_login` string, date-time, nullable
      - `email` string, email
      - `attributes` object
      - `uid` string, required
    - `is_active` boolean, required
    - `expires` string, date-time, nullable
    - `status` 'created' | 'approved' | 'denied' | 'revoked', required
    - `targets` string[], required
    - `target_objs` RequestableTarget[], required
      - `verbose_name` string, required — Return object's verbose_name
      - `verbose_name_plural` string, required — Return object's plural verbose_name
      - `meta_model_name` string, required — Return internal model name
      - `pbm_uuid` string, required
      - `label` string, required
      - `parent` Application, required — Application Serializer
        - `pk` string, uuid, required
        - `pbm_uuid` string, uuid, required
        - `name` string, required — Application's display Name.
        - `slug` string, required — Internal application name, used in URLs.
        - `provider` integer, nullable
        - `provider_obj` Provider, required — Provider Serializer
          - `pk` integer, required
          - `name` string, required
          - `authentication_flow` string, uuid, nullable — Flow used for authentication when the associated application is accessed by an un-authenticated user.
          - `authorization_flow` string, uuid, nullable — Flow used when authorizing this provider.
          - `invalidation_flow` string, uuid, nullable — Flow used ending the session from a provider.
          - `property_mappings` string[]
          - `component` string, required — Get object component so that we know how to edit the object
          - `assigned_application_slug` string, nullable, required — Internal application name, used in URLs.
          - `assigned_application_name` string, nullable, required — Application's display Name.
          - `assigned_backchannel_application_slug` string, nullable, required — Internal application name, used in URLs.
          - `assigned_backchannel_application_name` string, nullable, required — Application's display Name.
          - `verbose_name` string, required — Return object's verbose_name
          - `verbose_name_plural` string, required — Return object's plural verbose_name
          - `meta_model_name` string, required — Return internal model name
        - `backchannel_providers` integer[]
        - `backchannel_providers_obj` Provider[], required
          - `pk` integer, required
          - `name` string, required
          - `authentication_flow` string, uuid, nullable — Flow used for authentication when the associated application is accessed by an un-authenticated user.
          - `authorization_flow` string, uuid, nullable — Flow used when authorizing this provider.
          - `invalidation_flow` string, uuid, nullable — Flow used ending the session from a provider.
          - `property_mappings` string[]
          - `component` string, required — Get object component so that we know how to edit the object
          - `assigned_application_slug` string, nullable, required — Internal application name, used in URLs.
          - `assigned_application_name` string, nullable, required — Application's display Name.
          - `assigned_backchannel_application_slug` string, nullable, required — Internal application name, used in URLs.
          - `assigned_backchannel_application_name` string, nullable, required — Application's display Name.
          - `verbose_name` string, required — Return object's verbose_name
          - `verbose_name_plural` string, required — Return object's plural verbose_name
          - `meta_model_name` string, required — Return internal model name
        - `launch_url` string, nullable, required — Allow formatting of launch URL
        - `open_in_new_tab` boolean — Open launch URL in a new browser tab or window.
        - `meta_launch_url` string, uri
        - `meta_icon` string
        - `meta_icon_url` string, nullable, required — Get the URL to the App Icon image
        - `meta_icon_themed_urls` ThemedUrls, required — Themed URLs - maps theme names to URLs for light and dark themes
          - `light` string, nullable
          - `dark` string, nullable
        - `meta_description` string
        - `meta_publisher` string
        - `policy_engine_mode` 'all' | 'any'
        - `group` string
        - `meta_hide` boolean — Hide this application from the user's My applications page.
    - `uuid` string, uuid
  - `autocomplete` Autocomplete, required

## Other responses

- `400`
- `403`

---

[API](https://skmtc.dev/goauthentik/apis/authentik.md) · [All operations](https://skmtc.dev/goauthentik/apis/authentik/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/goauthentik/authentik/revisions/4e42e86021d7/schema)
