> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tofunmiadewuyi.com/custos/llms.txt
> Use this file to discover all available pages before exploring further.

# Get a group

> Requires `group.read`. Includes the group's resources.



## OpenAPI

````yaml /custos/openapi.yaml get /groups/{id}
openapi: 3.1.0
info:
  title: Custos control-plane API
  version: 0.1.0
  description: >
    Seed specification. The auth, identity, key, host-list, and grant endpoints
    below are

    complete; the remaining control-plane endpoints are still being transcribed.
servers:
  - url: https://custos.example.com
    description: Your control plane
security:
  - bearerAuth: []
tags:
  - name: Auth
    description: Login, token refresh, and logout.
  - name: Identity
    description: The authenticated user.
  - name: Keys
    description: A user's SSH public keys.
  - name: Credentials
    description: Stored secrets, sealed at rest and audited on every read.
  - name: Permission requests
    description: Time-boxed access requests for gated credentials.
  - name: Sets
    description: >-
      Secret sets — an app's .env, either deployable (private) or team-shared
      (public).
  - name: Hosts
    description: Enrolled machines.
  - name: Health
    description: Liveness and readiness probes.
  - name: Notifications
    description: In-app notifications for the signed-in user.
  - name: Rotation reviews
    description: Credential rotation checklists raised when a user is suspended or removed.
  - name: Audit
    description: Install-wide trails.
  - name: Users
    description: Accounts and their lifecycle.
  - name: Invitations
    description: Onboarding new accounts.
  - name: Groups
    description: Resource groups — a grant on a group cascades to everything in it.
  - name: Grants
    description: Permission grants.
  - name: Enrollment
    description: Admitting a machine to the fleet. Daemon-facing.
  - name: Upgrades
    description: Rolling the daemon fleet forward.
paths:
  /groups/{id}:
    parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
          format: uuid
    get:
      tags:
        - Groups
      summary: Get a group
      description: Requires `group.read`. Includes the group's resources.
      responses:
        '200':
          description: The group and its contents
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/Group'
                  - type: object
                    properties:
                      resources:
                        type: array
                        items:
                          $ref: '#/components/schemas/GroupResource'
        '403':
          description: Missing `group.read`
        '404':
          description: Not found
components:
  schemas:
    Group:
      type: object
      properties:
        id:
          type: string
          format: uuid
        name:
          type: string
        description:
          type: string
        created_at:
          type: string
          format: date-time
        permissions:
          type: array
          items:
            type: string
          description: The caller's permissions on this group.
    GroupResource:
      type: object
      description: >
        One member resource. Exactly one of host, credential, set or backup is
        populated, matching resource_kind.
      properties:
        resource_kind:
          $ref: '#/components/schemas/ResourceKind'
        resource_id:
          type: string
          format: uuid
        display_name:
          type: string
        added_at:
          type: string
          format: date-time
          description: Absent on the available-resources listing.
        host:
          $ref: '#/components/schemas/Host'
        credential:
          $ref: '#/components/schemas/Credential'
        set:
          $ref: '#/components/schemas/SetSummary'
        backup:
          type: object
          properties:
            id:
              type: string
              format: uuid
            name:
              type: string
    ResourceKind:
      type: string
      enum:
        - host
        - credential
        - set
        - backup
    Host:
      type: object
      properties:
        id:
          type: string
          format: uuid
        name:
          type: string
        hostname:
          type: string
        ssh_endpoint:
          type: object
          properties:
            address:
              type: string
            source:
              type: string
        accounts:
          type: array
          items:
            type: string
          description: The Unix accounts this host manages.
        status:
          type: string
        connection_status:
          type: string
          description: Whether a daemon is currently connected.
        agent_version:
          type: string
        desired_version:
          type: string
        enrolled_at:
          type: string
          format: date-time
        last_seen_at:
          type: string
          format: date-time
          nullable: true
        permissions:
          type: array
          items:
            type: string
          description: The caller's permissions on this host.
    Credential:
      type: object
      properties:
        id:
          type: string
          format: uuid
        label:
          type: string
        username:
          type: string
        metadata:
          type: object
          additionalProperties:
            type: string
          description: >-
            Visible in list responses without a reveal, so it must not hold
            secrets.
        tags:
          type: array
          items:
            type: string
        created_by:
          $ref: '#/components/schemas/Actor'
        updated_by:
          $ref: '#/components/schemas/Actor'
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
        permissions:
          type: array
          items:
            type: string
          description: The caller's permissions on this credential.
        requires_permission:
          type: boolean
          description: Whether revealing the value needs an approved permission request.
        access_status:
          type: string
          enum:
            - not_required
            - approved
            - pending
            - requestable
          description: >
            `not_required` when the credential is ungated. Otherwise the
            caller's standing: `approved` (admins, or an unexpired approval),
            `pending`, or `requestable`.
        access_expires_at:
          type: string
          format: date-time
          description: >-
            When an approved access window ends. Absent for admins and ungated
            credentials.
    SetSummary:
      type: object
      properties:
        id:
          type: string
          format: uuid
        name:
          type: string
        public:
          type: boolean
        key_count:
          type: integer
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
        permissions:
          type: array
          items:
            type: string
    Actor:
      type: object
      nullable: true
      properties:
        id:
          type: string
          format: uuid
        name:
          type: string
        display_name:
          type: string
        email:
          type: string
          format: email
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >
        An opaque access token from /login or /refresh. Tokens are checked
        against the database on every request, so revocation is immediate.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.