# Search for access groups.

Endpoint: POST /access-groups/search
Version: 3.30.0
Security: ApiKeyAuth

## Security:

  - `ApiKeyAuth` (unknown)
    apiKey in header Authorization

## Query parameters:

  - `limit` (integer)
    Maximum number of objects to return per query. The value must be between 1 and 1000. Default is 100.

  - `cursor` (string)
    Cursor to fetch the next or previous page of results. The value of this property must be extracted from the 'prev_cursor' or 'next_cursor' property of a PaginatedResponseMetadata which is contained in the response of list and search API endpoints.

  - `sort` (string)
    The field to sort results by. A property name with a prepended '-' signifies descending order.

## Request body:

  - `application/json` (unknown)
    A request body containing a filter expression. This enables searching
for items matching arbitrarily complex conditions. The list of
attributes which can be used in filter expressions is available
in the x-filterable vendor extension.
# Filter Expression Overview
**Note: All keywords are case-insensitive**
## Comparison Operators
| Operator | Description | Example |
|  --- | --- | --- |
| CONTAINS | Substring or membership testing for string and list attributes respectively. | field3 CONTAINS 'foobar', field4 CONTAINS TRUE |
| IN | Tests if field is a member of a list literal. List can contain a maximum of 100 values | field2 IN ['Goku', 'Vegeta'] |
| GE | Tests if a field is greater than or equal to a literal value | field1 GE 1.2e-2 |
| GT | Tests if a field is greater than a literal value | field1 GT 1.2e-2 |
| LE | Tests if a field is less than or equal to a literal value | field1 LE 9000 |
| LT | Tests if a field is less than a literal value | field1 LT 9.02 |
| NE | Tests if a field is not equal to a literal value | field1 NE 42 |
| EQ | Tests if a field is equal to a literal value | field1 EQ 42 |

## Search Operator
The SEARCH operator filters for items which have any filterable
attribute that contains the input string as a substring, comparison
is done case-insensitively. This is not restricted to attributes with
string values. Specifically `SEARCH '12'` would match an item with an
attribute with an integer value of `123`.
## Logical Operators
Ordered by precedence.
| Operator | Description | Example |
|  --- | --- | --- |
| NOT | Logical NOT (Right associative) | NOT field1 LE 9000 |
| AND | Logical AND (Left Associative) | field1 GT 9000 AND field2 EQ 'Goku' |
| OR | Logical OR (Left Associative) | field1 GT 9000 OR field2 EQ 'Goku' |

## Grouping
Parenthesis `()` can be used to override operator precedence.
For example:
NOT (field1 LT 1234 AND field2 CONTAINS 'foo')
## Literal Values
| Literal | Description | Examples |
|  --- | --- | --- |
| Nil | Represents the absence of a value | nil, Nil, nIl, NIL |
| Boolean | true/false boolean | true, false, True, False, TRUE, FALSE |
| Number | Signed integer and floating point numbers. Also supports scientific notation. | 0, 1, -1, 1.2, 0.35, 1.2e-2, -1.2e+2 |
| String | Single or double quoted | "foo", "bar", "foo bar", 'foo', 'bar', 'foo bar' |
| Datetime | Formatted according to [RFC3339](https://datatracker.ietf.org/doc/html/rfc3339) | 2018-04-27T18:39:26.397237+00:00 |
| List | Comma-separated literals wrapped in square brackets | [0], [0, 1], ['foo', "bar"] |

## Limitations
- A maximum of 8 unique identifiers may be used inside a filter expression.

## Request fields (application/json):

  - `filter_expression` (string)
    Example: string_field CONTAINS "over" AND numberic_field GT 9000 OR string_field2 EQ "Goku"

## Request examples:

  - `Nested Object Comparison` (unknown)
    An example of a nested Object comparison testing that at least one repository has a
version which is equal to 19.0.0.

  - `Relative comparison` (unknown)
    An example of a relative comparison testing that field1 has a
value which is less than 123.

  - `Absence of an attribute value` (unknown)
    An example of using nil to test for the absence of a value for field2.

  - `Existence of an attribute value` (unknown)
    An example of using nil to test for the existence of a value for field2.

  - `Use of the CONTAINS operator` (unknown)
    An example of using the 'CONTAINS' operator to check if
field2 contains the string 'foo'. If field2 is string valued
then this is checking if 'foo' is a substring of field2. If
field2 is a list of strings then this is checking if 'foo'
is a member of the list.

  - `Use of the IN operator` (unknown)
    An example of using the 'IN' operator to check if field1
is an element of a list literal.

  - `Use of the SEARCH operator` (unknown)
    An example of using the 'SEARCH' operator to retrieve all elements
for which 'foo' is a substring of a filterable attribute.

  - `Overriding operator precedence` (unknown)
    An example of parenthesis being used to group operators & override
operator precedence.

## Response 200:

  - `200` (unknown)
    OK

## Response 200 fields (application/json):

  - `items` (array)

  - `items.id` (string)
    The Access group ID.

  - `items.name` (string, required)
    The Access group name

  - `items.single_account` (boolean)
    Indicates that this Access group defines the permissions of a single account, and thus account and account tags cannot be modified. Instead create a new Access group to manage permissions of multiple accounts.

  - `items.account_ids` (array)
    List of accounts ids included individually (as opposed to added by tags) in the Access group.

  - `items.tagged_account_ids` (array)
    List of accounts ids included by tags in the Access group.

  - `items.account_tags` (array)
    List of account tags. Accounts matching any of these tags will be automatically added to the Access group.

  - `items.account_tags.key` (string, required)
    Key of the tag
    Example: key-1

  - `items.account_tags.value` (string, required)
    Value of the tag
    Example: value-1

  - `items.scopes` (array)
    The Access group scopes.

  - `items.scopes.id` (string)
    The Access group scope ID.

  - `items.scopes.name` (string)
    The Access group scope name.

  - `items.scopes.role_id` (string, required)
    The Access group role id.

  - `items.scopes.scope_type` (string)
    Specifies the type of the scope. Scope of type SIMPLE would grant access to all DCT objects. Scope of type SCOPED would grant access to all objects based on objects and object-tags and permissions defined in linked role. Scope of type ADVANCED would grant access to DCT objects based on objects and object-tags and the individual permissions.
    Enum: "SIMPLE", "SCOPED", "ADVANCED"

  - `items.scopes.object_tags` (array)
    The permissions in this access group scope will be granted to all DCT objects tagged with tags matching this property. This is cumulative with objects defined in the 'objects' property, and mutually exclusive with scope_type 'SIMPLE'.

  - `items.scopes.object_tags.key` (string, required)
    Key of the tag
    Example: key-1

  - `items.scopes.object_tags.value` (string, required)
    Value of the tag
    Example: value-1

  - `items.scopes.object_tags.object_type` (string)
    Type of the DCT object.
    Enum: "ALGORITHM", "ACCESS_GROUP", "ACCOUNT", "AI_SERVICE", "ROLE", "BOOKMARK", "CDB", "CLASSIFIER", "DATA_CLASS", "DATABASE_TEMPLATE", "DISCOVERY_EXPRESSION", "DISCOVERY_POLICY", "DSOURCE", "ENGINE", "ENVIRONMENT", "COMPLIANCE_JOB_COLLECTION", "MASKING_ENVIRONMENT", "MASKING_FILE_UPLOAD", "MASKING_JOB", "MASKING_JOB_SET", "REPORT_SCHEDULE", "RULE_SET", "SOURCE", "VCDB", "VDB", "VDB_GROUP", "CONNECTOR", "VIRTUALIZATION_POLICY", "DATASET_GROUP", "ENGINE_VAULT", "KERBEROS_CONFIG", "TIMEFLOW", "MASKING_PLUGIN", "HYPERSCALE_INSTANCE", "HYPERSCALE_CONNECTOR", "HYPERSCALE_DATASET", "TOOLKIT", "REPLICATION_PROFILE", "NAMESPACE", "STAGING_SOURCE", "DATA_LAYOUT", "SNAPSHOT", "VIRTUALIZATION_POLICY_TARGET", "DATA_CONNECTION", "HOOK_TEMPLATE", "JOB_ORCHESTRATOR", "STAGING_CDB", "SYNTHETIC_APPLICATION", "SYNTHETIC_DATASET", "SYNTHETIC_GENERATOR_FRAMEWORK", "SYNTHETIC_CONNECTOR", "SYNTHETIC_JOB", "SYNTHETIC_FILE", "SYNTHETIC_EXECUTION", "SYNTHETIC_EXECUTION_COMPONENT", "SYNTHETIC_SEED_LIST_FILE", "SYNTHETIC_GENERATOR_INSTANCE", "CLOUD_ACCOUNT", "PAAS_DATABASE", "CDB_DSOURCE", "PAAS_INSTANCE", "PAAS_SNAPSHOT", "SYNTHETIC_JDBC_DRIVER", "MOUNT_INFORMATION", "LLM_PROVIDER", "SSH_KEY", "COMPLIANCE_JDBC_DRIVER", "COMPLIANCE_PASSWORD_VAULT", "COMPLIANCE_CREDENTIAL_PATH", "FILE_FORMAT", "MAINFRAME_DATASET_FORMAT", "FEATURE_ASSIGNMENT", "STANDALONE_SERVICE"

  - `items.scopes.object_tags.permission` (string)
    Type of the permission on DCT object.
    Enum: "READ", "UPDATE", "DELETE", "EXECUTE", "CANCEL", "MIGRATE", "REFRESH", "DISABLE", "ENABLE", "ABANDON", "VALIDATE", "START", "STOP", "SNAPSHOT", "COPY", "REMOVE_JOB", "PASSWORD_RESET", "UNDO_IMPORT", "IMPORT", "PROVISION_FROM_BOOKMARK", "PROVISION", "REFRESH_FROM_BOOKMARK", "REFRESH_FROM_SNAPSHOT", "REFRESH_FROM_TIMESTAMP", "REFRESH_FROM_LOCATION", "CREATE_ENVIRONMENT", "CREATE_BOOKMARK", "CREATE_VDBGROUP", "MANAGE_TAGS", "LINK", "REPLICATE", "REPLICATE_TO", "CONVERT_AND_DROP", "IMPORT_BOOKMARKS", "FAILOVER", "COMMIT_FAILOVER", "FAILBACK", "DISCARD", "LOCK", "UNLOCK", "FORCE_UNLOCK", "LOCK_FOR_OTHER_ACCOUNT", "UPDATE_TIMEFLOW", "SNAPSHOT_DELETE", "SWITCH_TIMEFLOW", "DELETE_TIMEFLOW", "SNAPSHOT_UPDATE", "IMPORT_ACCOUNTS", "DETACH_SOURCE", "ATTACH_SOURCE", "RESOLVE", "RESOLVE_ALL", "RESOLVE_OR_IGNORE", "API_KEY_RESET", "API_KEY_DELETE", "READ_STORAGE_CAPACITY_DATA", "READ_DATASET_PERF_ANALYTICS", "CREATE_TOOLKIT", "REALIGN", "DELETE_BOOKMARK", "UPDATE_BOOKMARK", "READ_BOOKMARK", "CONVERT_AND_DROP_BOOKMARKS", "GLOBAL_SYNC_ENGINES", "ADD_ENGINE_TO_HYPERSCALE", "CONFIGURE_CUSTOM_AUTO_TAGGING", "CONFIGURE_PREDEFINED_AUTO_TAGGING", "APPLY", "UNAPPLY", "UNDO_REFRESH", "CONVERT", "DELETE_HELDSPACE", "REPAIR_TIMEFLOW", "EXPORT", "EXECUTE_NETWORK_TEST", "READ_NETWORK_TEST", "READ_HOOKS", "MANAGE_HOOKS", "REFRESH_LOGS", "VIEW_LOGS", "GENERATE_SUPPORT_BUNDLE", "RESTORE_FROM_RECYCLE_BIN", "DOWNLOAD_SUPPORT_BUNDLE", "SYNC", "EMPTY_RECYCLE_BIN", "PURGE_LOGS", "REPAVE_PREPARE", "REPAVE_APPLY", "IMPORT_SYNTHETIC_GENERATORS_PACK", "MIGRATE_COMPLIANCE_JOBS"

  - `items.scopes.objects` (array)
    The permissions in this access group scope will be granted to all DCT objects with matching object id and object type, mutually exclusive with  scope_type 'SIMPLE'.

  - `items.scopes.objects.object_id` (string, required)
    ID of the object
    Example: 1-VDB-OBJECT-ID

  - `items.scopes.always_allowed_permissions` (array)
    An array of always allowed permissions which can be used to specify object type and permission. An object with same object type and permission can not be added in 'objects' array.

  - `response_metadata` (object)

  - `response_metadata.prev_cursor` (string)
    Pointer to the previous page of results. Use this value as a cursor query parameter in a subsequent request, along with limit, to navigate through the collection by virtual page.

  - `response_metadata.next_cursor` (string)
    Pointer to the next page of results. Use this value as a cursor query parameter in a subsequent request, along with limit, to navigate through the collection by virtual page.

  - `response_metadata.total` (integer)
    The total number of results. This value may not be provided.

