Skip to content
Scalekit Docs
Talk to an Engineer Dashboard

Resource

Manage resource clients and the consents your end users grant against them

Use scalekitClient.resources() to manage resource clients and to read and revoke the consents your end users grant against one. A consent records that one end user allowed a specific resource client to act on their behalf.

The same audit and revoke actions are available in the dashboard under Managing MCP clients.

clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-java/blob/main/src/main/java/com/scalekit/api/ResourceConsentClient.java
#asyncgetResource

Retrieves a single resource by id.

paramresourceIdString

The resource to fetch (format: res_...).

returnsGetResourceResponse

Resource object.

GetResourceResponse resource = scalekitClient.resources().getResource("res_xxx");
System.out.println(resource.getResource());
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-java/blob/main/src/main/java/com/scalekit/api/ResourceConsentClient.java
#asynclistResources

Lists resources of a given type in the environment, with pagination.

paramresourceTypeResourceType

The resource type to filter by. Supported value: ResourceType.MCP_SERVER.

parampageSizeint

Page size for pagination (max 30). 0 uses the server default.

parampageTokenString

Page token for pagination; empty for the first page.

returnsListResourcesResponse

Paginated resources.

ListResourcesResponse resources = scalekitClient.resources().listResources(ResourceType.MCP_SERVER, 20, "");
resources.getResourcesList().forEach(r -> System.out.println(r.getId() + " " + r.getScopesList()));
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-java/blob/main/src/main/java/com/scalekit/api/ResourceConsentClient.java
#asynccreateResourceClient

Creates a resource client. Returns the created client and a plainSecret - the plaintext client secret, only available at creation time.

paramresourceIdString

The resource to create the client for (format: res_...).

paramclientResourceClient

The client properties, built via ResourceClient.newBuilder(). scopes should be the same or a subset of the scopes available for the resource. customClaims is a flat key/value structure only. expiry (access token lifetime in seconds) defaults to the resource’s configured expiry. redirectUris are the allowed redirect URIs for a pre-registered client. There is no audience field - a non-empty audience list throws IllegalArgumentException, since audience is always server-determined.

name, description, scopes, customClaims, expiry, redirectUris
returnsCreateResourceClientResponse

The created client and its plaintext secret.

import com.scalekit.grpc.scalekit.v1.clients.CreateResourceClientResponse;
import com.scalekit.grpc.scalekit.v1.clients.GetResourceResponse;
import com.scalekit.grpc.scalekit.v1.clients.ResourceClient;
import com.scalekit.grpc.scalekit.v1.clients.Scope;
import java.util.List;
import java.util.stream.Collectors;
GetResourceResponse resource = scalekitClient.resources().getResource("res_xxx");
List<String> allowedScopes = resource.getResource().getScopesList().stream()
.filter(Scope::getEnabled)
.map(Scope::getName)
.collect(Collectors.toList());
CreateResourceClientResponse created = scalekitClient.resources().createResourceClient(
"res_xxx",
ResourceClient.newBuilder().setName("My Resource Client").addAllScopes(allowedScopes).build()
);
System.out.println(created.getClient().getClientId());
// Store created.getPlainSecret() in your secret manager now - it is never
// returned again. It grants full access as this client, so if it leaks,
// replace it right away: create a new secret and delete the compromised one
// (delete first if you're already at your secret limit; if it's your only
// secret, raise the limit before rotating).
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-java/blob/main/src/main/java/com/scalekit/api/ResourceConsentClient.java
#asyncgetResourceClient

Fetches a single resource client, along with the end-users who have granted it consent.

paramresourceIdString

The resource the client must belong to (format: res_...).

paramclientIdString

The client ID (format: m2m_...).

returnsGetResourceClientResponse

The resource client.

GetResourceClientResponse got = scalekitClient.resources().getResourceClient("res_xxx", "m2m_xxx");
System.out.println(got.getClient().getName());
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-java/blob/main/src/main/java/com/scalekit/api/ResourceConsentClient.java
#asynclistResourceClients

Lists resource clients.

paramresourceIdString

The resource whose clients to list (format: res_...).

returnsListResourceClientsResponse

The resource’s clients, plus totalDcrClients and totalStaticClients counts.

ListResourceClientsResponse list = scalekitClient.resources().listResourceClients("res_xxx");
System.out.println(list.getTotalDcrClients() + " " + list.getTotalStaticClients());
list.getClientsList().forEach(c -> System.out.println(c.getClientId() + " " + c.getName()));
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-java/blob/main/src/main/java/com/scalekit/api/ResourceConsentClient.java
#asyncupdateResourceClient

Updates a resource client.

paramresourceIdString

The resource the client must belong to (format: res_...).

paramclientIdString

The client ID to update (format: m2m_...).

paramoptionsUpdateResourceClientOptions

Built via UpdateResourceClientOptions.builder(). Only the fields set (non-null) are changed. name/description are a no-op server-side when set to an empty string, not a clear. scopes, customClaims, and redirectUris replace their existing values; set an empty list to clear one of them. There’s no audience field.

name, description, scopes, customClaims, expiry, redirectUris
returnsUpdateResourceClientResponse

The updated client.

GetResourceResponse resource = scalekitClient.resources().getResource("res_xxx");
List<String> allowedScopes = resource.getResource().getScopesList().stream()
.filter(Scope::getEnabled)
.map(Scope::getName)
.collect(Collectors.toList());
UpdateResourceClientResponse updated = scalekitClient.resources().updateResourceClient(
"res_xxx", "m2m_xxx",
UpdateResourceClientOptions.builder().name("Updated Name").scopes(allowedScopes).build()
);
System.out.println(updated.getClient().getName() + " " + updated.getClient().getScopesList());
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-java/blob/main/src/main/java/com/scalekit/api/ResourceConsentClient.java
#asyncdeleteResourceClient

Deletes resource clients. Throws if the client is missing or scoped to a different resource.

paramresourceIdString

The resource the client must belong to (format: res_...).

paramclientIdString

The client ID to delete (format: m2m_...).

returnsDeleteResourceClientResponse

Empty response on success.

scalekitClient.resources().deleteResourceClient("res_xxx", "m2m_xxx");
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-java/blob/main/src/main/java/com/scalekit/api/ResourceConsentClient.java
#asynccreateResourceClientSecret

Creates a new secret for a resource client. Only 2 client secrets are recommended to exist at a given point in time - use deleteResourceClientSecret to remove an existing one first if you need more.

The plaintext client secret is only ever returned here, at creation time.

paramresourceIdString

The resource the client must belong to (format: res_...).

paramclientIdString

The client ID to create a secret for (format: m2m_...).

returnsCreateClientSecretResponse

The new secret, including its plaintext value.

CreateClientSecretResponse secret = scalekitClient.resources().createResourceClientSecret("res_xxx", "m2m_xxx");
// Store secret.getPlainSecret() in your secret manager now - it is never
// returned again. It grants full access as this client, so if it leaks,
// replace it right away: create a new secret and delete the compromised one
// (delete first if you're already at your secret limit; if it's your only
// secret, raise the limit before rotating).
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-java/blob/main/src/main/java/com/scalekit/api/ResourceConsentClient.java
#asyncdeleteResourceClientSecret

Permanently deletes a secret from a resource client. A client must always keep at least 1 secret - calling this on a client’s last remaining secret throws an error.

paramresourceIdString

The resource the client must belong to (format: res_...).

paramclientIdString

The client ID the secret belongs to (format: m2m_...).

paramsecretIdString

The secret ID to delete (format: sks_...).

returnsvoid

Nothing on success.

scalekitClient.resources().deleteResourceClientSecret("res_xxx", "m2m_xxx", "sks_xxx");
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-java/blob/main/src/main/java/com/scalekit/api/ResourceConsentClient.java
#asynclistUserConsents

Lists the end-user consents granted against a resource, with pagination. Use this to audit who authorized a client, and to find the consentId you need before revoking.

Filter by user in one of two ways. Pass userIds to match external user IDs exactly and case-sensitively. Pass search for a case-insensitive substring match. When you give both, userIds wins and search is ignored.

paramresourceIdString

The resource whose consents to list (format: res_...).

paramoptionsListUserConsentsOptions

Built via ListUserConsentsOptions.builder(). Optional fields: search, pageSize (max 30), pageToken, userIds (max 25, takes precedence over search).

search, pageSize, pageToken, userIds
returnsListResourceUserConsentsResponse

Consents with id, externalUserId, clientId, clientName, scopes, and grantedAt, plus totalSize and the nextPageToken / prevPageToken cursors.

ListResourceUserConsentsResponse consents = scalekitClient.resources().listUserConsents(
"res_xxx",
ListUserConsentsOptions.builder().pageSize(20).userIds(List.of("user_456")).build() // userIds optional; takes precedence over search
);
System.out.println(consents.getTotalSize() + " " + consents.getNextPageToken());
consents.getConsentsList().forEach(c ->
System.out.println(c.getId() + " " + c.getExternalUserId() + " " + c.getClientId() + " " + c.getScopesList())
);
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-java/blob/main/src/main/java/com/scalekit/api/ResourceConsentClient.java
#asyncrevokeUserConsent

Revokes a single end-user consent held by a resource client. The client is prompted for consent again on its next authorization attempt, and every active refresh token issued to that client for the same user is revoked.

Access tokens that Scalekit already issued stay valid until they expire. See How revocation affects active access tokens for ways to shorten that window.

paramclientIdString

The resource client that holds the consent (format: m2m_...), not the resource ID.

paramconsentIdString

The consent to revoke (format: usrcnst_...), taken from listUserConsents.

returnsRevokeUserConsentResponse

Empty response on success. The call throws on failure.

scalekitClient.resources().revokeUserConsent("m2m_xxx", "usrcnst_789");