---
title: "List OAuth grants"
method: GET
path: "/admin/oauth-grants"
tags: ["OAuth"]
---

# List OAuth grants

`GET /admin/oauth-grants`

List consent→agent grants across all clients and agents.

The admin cross-view over the grant registry: filter by client, agent,
consenting user, or status. Each item carries the client's display name
and redirect-URI origin plus the consenting ``user_id`` — after an agent
ownership transfer the grant stays with the original consenter, so this
column is how an admin spots stranded grants.

## Query parameters

- `client_id` string, nullable — Filter by the client's public client_id.
- `agent_id` string, nullable — Filter by bound agent.
- `user_id` string, nullable — Filter by consenting user.
- `status` 'active' | 'revoked', nullable — Filter by grant lifecycle state.
- `limit` integer
- `cursor` string, nullable

## Response `200`

Successful Response

- OAuthGrantAdminListResponse — A paginated list of OAuth grants (admin cross-view).
  - `data` OAuthGrantAdminResponse[], required
    - `agent_id` string, required — The agent this grant binds the client to.
    - `agent_status` string, nullable — Lifecycle state of the bound agent (`active`, `disabled`, `archived`, …). A grant on a non-active agent is dormant: the row stays `active` (disable is reversible — re-enable restores the standing consent without a new consent round) but no token resolves while the agent is non-active. Lets listings tell a working connection from a dormant one (#1233).
    - `can_revoke` boolean, required — Whether the CALLER may revoke this grant (the consenting user, or an admin holding the revoke permission set). May be false even for callers who can list — e.g. a read-only admin.
    - `client_name` string, nullable, required — Display name of the registered client, if the row still exists.
    - `client_origin` string, nullable, required — Origin (scheme://host) of the client's first redirect URI — the 'authorized apps' display pattern.
    - `created_at` string, date-time, required
    - `id` string, required — Grant ID (ksuid, `ocg_` prefix).
    - `last_used_at` string, date-time, nullable, required — Last time the client obtained tokens under this grant (stamped at exchange/refresh, not per request).
    - `oauth_client_id` string, required — The client's public client_id — the same identifier stamped on tokens minted under this grant.
    - `revoked_at` string, date-time, nullable, required
    - `scopes` string[], required — Scopes granted at consent (the D2 intersection).
    - `status` string, required — Grant lifecycle state: ``active`` or ``revoked``.
    - `user_id` string, required — The consenting user who approved this grant. Shown even after an agent ownership transfer: the grant stays with the original consenter (it is their consent, not the agent's).
  - `has_more` boolean, required
  - `next_cursor` string, nullable

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `422` — Unprocessable Entity
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-09-11** `4c1dd933286c` — 1 info
  - added the optional property `data/items/agent_status` to the response with the `200` status
- **2026-09-02** `03e3ca4f329f` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/jentic/apis/jentic-control-plane-api/changes/admin/oauth-grants/get.md)

---

[API](https://skmtc.dev/jentic/apis/jentic-control-plane-api.md) · [All operations](https://skmtc.dev/jentic/apis/jentic-control-plane-api/llms.txt) · [OpenAPI document](https://skmtc.dev/jentic/apis/jentic-control-plane-api/revisions/e4688b93dfc7?raw)
