> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-muhammad-kumail-native-mcp-tabs-batch.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# List History

> ListHistory returns the change history (newest first) for a single scope —
 each entry is a snapshot plus who/when metadata.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples get /api/v1/apps/{app_id}/xaa/scopes/{id}/history
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/apps/{app_id}/xaa/scopes/{id}/history:
    get:
      tags:
        - Cross-App Access
      summary: List History
      description: >-
        ListHistory returns the change history (newest first) for a single scope
        —
         each entry is a snapshot plus who/when metadata.
      operationId: c1.api.cross_app_access.v1.XAAScopeService.ListHistory
      parameters:
        - in: path
          name: app_id
          required: true
          schema:
            description: The application this scope belongs to.
            type: string
        - in: path
          name: id
          required: true
          schema:
            description: Unique identifier for the scope.
            type: string
        - in: query
          name: page_size
          schema:
            description: Page size (max 200).
            format: int32
            type: integer
        - in: query
          name: page_token
          schema:
            description: Page token for pagination.
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.cross_app_access.v1.XAAScopeServiceListHistoryResponse
          description: XAAScopeServiceListHistoryResponse returns scope history entries.
      x-codeSamples:
        - lang: go
          label: ListHistory
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/operations\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.XAAScope.ListHistory(ctx, operations.C1APICrossAppAccessV1XAAScopeServiceListHistoryRequest{\n        AppID: \"<id>\",\n        ID: \"<id>\",\n    })\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.XAAScopeServiceListHistoryResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    c1.api.cross_app_access.v1.XAAScopeServiceListHistoryResponse:
      description: XAAScopeServiceListHistoryResponse returns scope history entries.
      properties:
        list:
          description: The page of history entries, newest first.
          items:
            $ref: >-
              #/components/schemas/c1.api.cross_app_access.v1.XAAScopeHistoryEntry
          type:
            - array
            - 'null'
        nextPageToken:
          description: >-
            Pagination token for the next page, or empty if there are no more
            results.
          type: string
      title: Xaa Scope Service List History Response
      type: object
      x-speakeasy-name-override: XAAScopeServiceListHistoryResponse
    c1.api.cross_app_access.v1.XAAScopeHistoryEntry:
      description: XAAScopeHistoryEntry is one version of a scope and its history metadata.
      properties:
        metadata:
          oneOf:
            - $ref: '#/components/schemas/c1.api.history.v1.HistoryEntryMetadata'
            - type: 'null'
        snapshot:
          oneOf:
            - $ref: '#/components/schemas/c1.api.cross_app_access.v1.XAAScope'
            - type: 'null'
      title: Xaa Scope History Entry
      type: object
      x-speakeasy-name-override: XAAScopeHistoryEntry
    c1.api.history.v1.HistoryEntryMetadata:
      description: |-
        HistoryEntryMetadata is the shared metadata envelope embedded on every
         per-service HistoryEntry. The strongly-typed snapshot lives on the
         per-service entry message alongside this envelope.
      properties:
        actor:
          oneOf:
            - $ref: '#/components/schemas/c1.api.history.v1.HistoryActor'
            - type: 'null'
        annotations:
          description: |-
            Server-rendered annotations: known keys carry display_label and
             (for ticket_id, etc.) display_url resolved from tenant config.
             Cap mirrors the per-object annotation ceiling (16).
          items:
            $ref: '#/components/schemas/c1.api.history.v1.HistoryAnnotation'
          type:
            - array
            - 'null'
        changeKind:
          description: |-
            Storage-model enum re-exported here for wire compatibility with the
             storage row. UNSPECIFIED should never appear on the wire.
          enum:
            - CHANGE_KIND_UNSPECIFIED
            - CHANGE_KIND_CREATE
            - CHANGE_KIND_PUT
            - CHANGE_KIND_HARD_DELETE
          type: string
          x-speakeasy-unknown-values: allow
        createdAt:
          format: date-time
          type:
            - string
            - 'null'
        id:
          description: KSUID. Same value as c1.models.history.v1.ObjectHistory.id.
          type: string
        syslogEventId:
          description: |-
            System Log event id — KSUID of the OCSF event recorded for this
             write. Empty for non-RPC writes (workflows, cron). Customer-facing
             copy says "System Log event"; the underlying format is OCSF.
          type: string
        traceId:
          description: |-
            OTel trace correlation. Empty when no valid span at write time.
             32-hex-char otel trace id or empty.
          type: string
      title: History Entry Metadata
      type: object
      x-speakeasy-name-override: HistoryEntryMetadata
    c1.api.cross_app_access.v1.XAAScope:
      description: >-
        XAAScope is a single OAuth scope exposed by a resource server, elevated
        into
         a governable object bound to its own entitlement.
      properties:
        appEntitlementId:
          description: The AppEntitlement created for this scope.
          type: string
        appId:
          description: The application that owns the resource server.
          type: string
        classification:
          description: Risk classification.
          enum:
            - XAA_SCOPE_CLASSIFICATION_UNSPECIFIED
            - XAA_SCOPE_CLASSIFICATION_READ
            - XAA_SCOPE_CLASSIFICATION_WRITE
            - XAA_SCOPE_CLASSIFICATION_DESTRUCTIVE
            - XAA_SCOPE_CLASSIFICATION_SENSITIVE
            - XAA_SCOPE_CLASSIFICATION_DANGEROUS
          type: string
          x-speakeasy-unknown-values: allow
        createdAt:
          format: date-time
          type:
            - string
            - 'null'
        deletedAt:
          format: date-time
          type:
            - string
            - 'null'
        description:
          description: Description of what the scope grants.
          type: string
        displayName:
          description: Display name for the scope.
          type: string
        id:
          description: Unique identifier for this scope.
          type: string
        lastDiscoveredAt:
          format: date-time
          type:
            - string
            - 'null'
        scopeValue:
          description: >-
            The literal OAuth scope string minted into the grant. Immutable
            after
             creation (RFC 6749 charset, max 256 bytes).
          type: string
        source:
          description: How C1 learned of the scope.
          enum:
            - XAA_SCOPE_SOURCE_UNSPECIFIED
            - XAA_SCOPE_SOURCE_ADMIN_DECLARED
            - XAA_SCOPE_SOURCE_DISCOVERED
          type: string
          x-speakeasy-unknown-values: allow
        state:
          description: Approval/lifecycle state.
          enum:
            - XAA_SCOPE_STATE_UNSPECIFIED
            - XAA_SCOPE_STATE_PENDING_REVIEW
            - XAA_SCOPE_STATE_ENABLED
            - XAA_SCOPE_STATE_DISABLED
            - XAA_SCOPE_STATE_REMOVED
          type: string
          x-speakeasy-unknown-values: allow
        updatedAt:
          format: date-time
          type:
            - string
            - 'null'
        xaaResourceServerId:
          description: The resource server this scope belongs to.
          type: string
      title: Xaa Scope
      type: object
      x-speakeasy-name-override: XAAScope
    c1.api.history.v1.HistoryActor:
      description: |-
        HistoryActor is a typed reference to whoever performed the change.
         kind mirrors the storage-model ActorKind enum; user_id is set when
         kind corresponds to a user principal (API / SUPPORT) so the frontend
         can resolve the user via its own avatar / lookup hooks. Protos
         reference objects by id; the frontend renders / caches itself.

         The raw passport fields (token_id / principal_id) intentionally do not
         leave the server. Non-user actors (workflow, connector, internal) are
         identified by `kind` alone; correlating IDs (workflow_run_id, etc.)
         flow through `HistoryAnnotation` instead of being plucked into the
         actor message.
      properties:
        kind:
          description: The kind field.
          enum:
            - ACTOR_KIND_UNSPECIFIED
            - ACTOR_KIND_API
            - ACTOR_KIND_SLACK
            - ACTOR_KIND_MSTEAMS
            - ACTOR_KIND_JIRA_CLOUD
            - ACTOR_KIND_INTERNAL
            - ACTOR_KIND_SUPPORT
            - ACTOR_KIND_WORKFLOW
          type: string
          x-speakeasy-unknown-values: allow
        userId:
          description: |-
            Bare KSUID. Set when kind = ACTOR_KIND_API or ACTOR_KIND_SUPPORT.
             Empty otherwise. The frontend resolves user_id → display name via
             the same lookup paths it uses elsewhere (avatars, mentions, ...).
          type: string
      title: History Actor
      type: object
      x-speakeasy-name-override: HistoryActor
    c1.api.history.v1.HistoryAnnotation:
      description: |-
        HistoryAnnotation is a single operator-provided key/value rendered with
         per-key display metadata. Annotations are minted from the
         Tx.*WithHistoryAnnotations / db.WithHistoryAnnotations call options.
      properties:
        displayLabel:
          description: Server-rendered label, e.g. "Ticket".
          type: string
        displayUrl:
          description: |-
            Resolved from tenant config; "" if none. Frontend applies its own
             scheme allowlist.
          type: string
        displayValue:
          description: UI-friendly rendering (truncated / reshaped from raw_value).
          type: string
        key:
          description: 'Storage-side key. Bounds: ^[a-z][a-z0-9_.-]{0,63}$.'
          type: string
        kind:
          description: The kind field.
          enum:
            - ANNOTATION_KIND_UNSPECIFIED
            - ANNOTATION_KIND_GENERIC
            - ANNOTATION_KIND_TICKET
            - ANNOTATION_KIND_REASON
            - ANNOTATION_KIND_WORKFLOW
            - ANNOTATION_KIND_BATCH
            - ANNOTATION_KIND_CORRELATION
            - ANNOTATION_KIND_AUTOMATION
          type: string
          x-speakeasy-unknown-values: allow
        rawValue:
          description: >-
            Raw value as stored in ObjectHistory.annotations; storage-side
            values
             are capped at 512 bytes.
          type: string
      title: History Annotation
      type: object
      x-speakeasy-name-override: HistoryAnnotation
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````