---
title: "GET /api/v1/agent-vault/proxies"
method: GET
path: "/api/v1/agent-vault/proxies"
tags: ["Agent Vault Proxies"]
---

# GET /api/v1/agent-vault/proxies

`GET /api/v1/agent-vault/proxies`

List the organization's Agent Vault proxies

## Query parameters

- `orderBy` 'name' | 'createdAt'
- `orderDirection` 'asc' | 'desc'
- `search` string
- `limit` integer
- `offset` integer

## Response `200`

Default Response

- object
  - `proxies` union[], required
    - union
      - object
        - `id` string, uuid, required — The ID of the proxy.
        - `name` string, required — The name of the proxy.
        - `heartbeat` string, date-time, nullable, required — When the proxy last checked in, or `null` if it never has.
        - `isHealthy` boolean, required — Whether the proxy has checked in recently enough to be considered up.
        - `rootCaFingerprint` string, nullable, required — The SHA-256 fingerprint of the proxy's certificate authority. Pin this if you want to verify the proxy an agent connects to.
        - `rootCaExpiresAt` string, date-time, nullable, required — When the proxy's certificate authority expires.
        - `trafficPolicy` 'any-host' | 'bundle-hosts', required — Which hosts an agent may reach through this proxy. `any-host` lets every request out; `bundle-hosts` allows only hosts an access bundle covers, plus anything in `allowedHosts`, and refuses the rest with a 403.
        - `allowedHosts` string, nullable, required — Hosts that stay reachable under the `bundle-hosts` traffic policy even though no access bundle covers them. Still intercepted, and given no credential.
        - `pollInterval` number, required — How often, in seconds, the proxy refreshes its sessions and settings. Between 10 and 300.
        - `createdAt` string, date-time, required — When the proxy was registered.
      - object
        - `id` string, uuid, required — The ID of the proxy.
        - `name` string, required — The name of the proxy.
        - `heartbeat` string, date-time, nullable, required — When the proxy last checked in, or `null` if it never has.
        - `isHealthy` boolean, required — Whether the proxy has checked in recently enough to be considered up.
        - `rootCaFingerprint` string, nullable, required — The SHA-256 fingerprint of the proxy's certificate authority. Pin this if you want to verify the proxy an agent connects to.
        - `rootCaExpiresAt` string, date-time, nullable, required — When the proxy's certificate authority expires.
  - `totalCount` number, required

## Other responses

- `400` — Default Response
- `401` — Default Response
- `403` — Default Response
- `404` — Default Response
- `422` — Default Response
- `500` — Default Response

## Changes

- **2026-09-22** `62b0ba9edfe9` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/infisical/apis/infisical-api/changes/api/v1/agent-vault/proxies/get.md)

---

[API](https://skmtc.dev/infisical/apis/infisical-api.md) · [All operations](https://skmtc.dev/infisical/apis/infisical-api/llms.txt) · [OpenAPI document](https://skmtc.dev/infisical/apis/infisical-api/revisions/b1861c910818?raw)
