> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List workspace groups

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Returns every group in a workspace, oldest first, with how many members each has. The list isn't paginated.

Every member of a group gets the group's `role`, and a member of several groups gets the highest of their roles. A group whose `role` is `no_access` blocks members who get their role only from it. An `idp` group grants its role only while the workspace uses identity-provider groups. Otherwise its role is stored but grants nothing.

This is limited to 120 requests per minute, shared with [List group members](/api-reference/list-group-members). A signed-in session has its own limit, and every personal access token for the workspace shares one. Some workspaces have a different limit.

<Note>Call this as an owner, admin, or editor of the workspace, with a personal access token for that workspace sent as a Bearer token, or from a signed-in session. A read-only token is refused even though this endpoint only reads, and workspace API keys aren't accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json get /api/workspace/groups
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/workspace/groups:
    get:
      summary: List workspace groups
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Returns every group in a workspace, oldest first, with how many members
        each has. The list isn't paginated.


        Every member of a group gets the group's `role`, and a member of several
        groups gets the highest of their roles. A group whose `role` is
        `no_access` blocks members who get their role only from it. An `idp`
        group grants its role only while the workspace uses identity-provider
        groups. Otherwise its role is stored but grants nothing.


        This is limited to 120 requests per minute, shared with [List group
        members](/api-reference/list-group-members). A signed-in session has its
        own limit, and every personal access token for the workspace shares one.
        Some workspaces have a different limit.


        <Note>Call this as an owner, admin, or editor of the workspace, with a
        personal access token for that workspace sent as a Bearer token, or from
        a signed-in session. A read-only token is refused even though this
        endpoint only reads, and workspace API keys aren't accepted.</Note>
      operationId: list_groups_api_workspace_groups_get
      parameters:
        - name: workspaceId
          in: query
          required: true
          schema:
            type: string
            minLength: 1
            description: >-
              ID of the workspace. With a personal access token, use the token's
              workspace. Get it from `organization_id` in [Get
              app](/api-reference/get-app).
            title: Workspaceid
          description: >-
            ID of the workspace. With a personal access token, use the token's
            workspace. Get it from `organization_id` in [Get
            app](/api-reference/get-app).
          example: 67e0b12c4d8a3f005b21c9e4
      responses:
        '200':
          description: The workspace's groups.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WorkspaceGroupListResponse'
        '401':
          description: Missing or invalid credentials.
        '403':
          description: >-
            You aren't an owner, admin, or editor of the workspace, your token
            is for a different workspace or is read-only, or your credential
            can't be used on this endpoint.
        '409':
          description: Your workspace requires an unlocked SSO session.
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
        '429':
          description: Rate limit exceeded.
components:
  schemas:
    WorkspaceGroupListResponse:
      properties:
        groups:
          items:
            $ref: '#/components/schemas/WorkspaceGroupSummary'
          type: array
          title: Groups
          description: Every group in the workspace, oldest first.
          example:
            - description: Product designers
              id: 68b4e1d2c9a7f3001e2d4b61
              member_count: 12
              name: Design team
              role: editor
              source: custom
              unresolved_count: 0
      type: object
      required:
        - groups
      title: WorkspaceGroupListResponse
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    WorkspaceGroupSummary:
      properties:
        id:
          type: string
          title: Id
          description: ID of the group.
          example: 68b4e1d2c9a7f3001e2d4b61
        name:
          type: string
          title: Name
          description: Name of the group.
          example: Design team
        description:
          anyOf:
            - type: string
            - type: 'null'
          title: Description
          description: Short description of the group, or `null` when it has none.
          example: Product designers
        source:
          type: string
          title: Source
          description: >-
            `custom` for a group created in Base44, or `idp` for one your
            identity provider sends through SCIM. An `idp` group's name and
            members come from the identity provider.
          example: custom
        role:
          anyOf:
            - type: string
            - type: 'null'
          title: Role
          description: >-
            Role every member gets from the group: `admin`, `editor`, `viewer`,
            or `no_access`. `null` when the group grants no role.
          example: editor
        member_count:
          type: integer
          title: Member Count
          description: Number of members.
          example: 12
        unresolved_count:
          type: integer
          title: Unresolved Count
          description: >-
            Members your identity provider sent who don't have a Base44 account
            in the workspace yet. Always `0` for a `custom` group.
          default: 0
          example: 0
      type: object
      required:
        - id
        - name
        - source
        - member_count
      title: WorkspaceGroupSummary
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.