> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hq.zone/llms.txt
> Use this file to discover all available pages before exploring further.

# List OAuth authorizations

> Lists the third-party OAuth applications the authenticated caller has authorized
(consented to). Each entry includes the client_id, app name, client_type, an active
flag indicating whether the app is still registered and enabled, the union of scopes
the user has granted it, and timestamps for when it was first authorized and last
updated. First-party apps such as the browser extension never appear here since they
skip consent.



## OpenAPI

````yaml GET /v1/api/oauth/authorizations
openapi: 3.1.0
info:
  title: HQ API
  description: >-
    Public HTTP API for HQ. Authenticate with a Personal Access Token
    (`Authorization: Bearer hq_pat_...`) for server-side integrations, or an
    OAuth 2.1 authorization-code + PKCE flow for browser apps acting on a user's
    behalf. Both grant from the same resource:action scope vocabulary; an
    endpoint's required scope is listed under its `security`.
  license:
    name: Apache-2.0
    identifier: Apache-2.0
  version: 1.0.0
servers:
  - url: https://api.hq.zone
    description: HQ API (production)
security: []
tags:
  - name: me
    description: The signed-in user's own account
  - name: conversations
    description: Conversations and their messages
  - name: documents
    description: The content-addressed documents library
  - name: schedules
    description: Scheduled prompts and recurring tasks
  - name: agents
    description: Agents, their skills and integrations
  - name: memory
    description: What the assistant remembers (L5 governance)
  - name: tokens
    description: Personal Access Token management
  - name: billing
    description: Usage and billing
  - name: notifications
    description: In-app notification center
  - name: admin
    description: Workspace administration
  - name: integrations
    description: Workspace integrations (Slack, MCP, skills)
  - name: onboarding
    description: New-workspace onboarding wizard
  - name: auth
    description: Sign-in, sessions, and OAuth
paths:
  /v1/api/oauth/authorizations:
    get:
      tags:
        - tokens
      summary: List OAuth authorizations
      description: >-
        Lists the third-party OAuth applications the authenticated caller has
        authorized

        (consented to). Each entry includes the client_id, app name,
        client_type, an active

        flag indicating whether the app is still registered and enabled, the
        union of scopes

        the user has granted it, and timestamps for when it was first authorized
        and last

        updated. First-party apps such as the browser extension never appear
        here since they

        skip consent.
      operationId: list_authorizations
      responses:
        '200':
          description: Third-party apps the caller has authorized
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/Authorization'
        '403':
          description: Not authenticated
      security:
        - bearer_pat: []
        - oauth2: []
components:
  schemas:
    Authorization:
      type: object
      required:
        - client_id
        - name
        - client_type
        - active
        - scopes
        - authorized_at
        - updated_at
      properties:
        active:
          type: boolean
          description: >-
            Whether the app is still registered and active. A disabled app keeps
            the

            consent row until revoked, but its tokens no longer refresh.
        authorized_at:
          type: string
          description: When the app was first authorized.
        client_id:
          type: string
        client_type:
          type: string
          description: '`public` (PKCE) or `confidential` (has a secret).'
        name:
          type: string
        scopes:
          type: array
          items:
            type: string
          description: >-
            The capability scopes this user has granted the app (the running
            UNION).
        updated_at:
          type: string
          description: When the grant last grew (a re-auth requesting new scopes).
  securitySchemes:
    bearer_pat:
      type: http
      scheme: bearer
      bearerFormat: hq_pat
      description: 'Personal Access Token. Send as `Authorization: Bearer hq_pat_...`.'
    oauth2:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://app.hq.zone/v1/oauth/authorize
          tokenUrl: https://api.hq.zone/v1/oauth/token
          refreshUrl: https://api.hq.zone/v1/oauth/token
          scopes:
            admin: Administer the workspace (users, settings, integrations)
            agents:read: View the agents in your workspace
            agents:write: Create and configure agents
            billing:read: View usage and billing information
            conversations:read: Read your conversations and their messages
            conversations:write: Start conversations and send messages on your behalf
            documents:read: Read your documents library
            documents:write: Upload and manage documents in your library
            memory:read: Read what the assistant remembers about you
            memory:write: Correct or delete what the assistant remembers
            schedules:read: View your scheduled tasks
            schedules:write: Create and manage scheduled tasks
            tables:read: Read your tables and their rows
            tables:write: Create tables and add, edit, or delete rows

````