Skip to content
Scalekit Docs
Talk to an Engineer Dashboard

Resource

Manage resource clients and the consents your end users grant against them

Use scalekit_client.resources to manage resource clients and to read and revoke the consents your end users grant against one. A consent records that one end user allowed a specific resource client to act on their behalf.

The same audit and revoke actions are available in the dashboard under Managing MCP clients.

clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-python/blob/main/scalekit/resource.py
#asyncget_resource

Retrieves a single resource by id.

paramresource_idstr

The resource to fetch (format: res_...).

returnsGetResourceResponse

Resource object.

response = scalekit_client.resources.get_resource('res_xxx')
print(response[0].resource)
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-python/blob/main/scalekit/resource.py
#asynclist_resources

Lists resources of a given type in the environment, with pagination.

paramresource_typeResourceType

The resource type to filter by. Supported value: ResourceType.MCP_SERVER.

parampage_sizeOptional[int]

Page size for pagination (max 30).

parampage_tokenOptional[str]

Page token for pagination.

returnsListResourcesResponse

Paginated resources.

from scalekit.v1.clients.clients_pb2 import ResourceType
response = scalekit_client.resources.list_resources(
resource_type=ResourceType.MCP_SERVER,
page_size=20,
)
for resource in response[0].resources:
print(resource.id, resource.scopes)
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-python/blob/main/scalekit/resource.py
#asynccreate_resource_client

Creates a resource client. Returns the created client and a plain_secret - the plaintext client secret, only available at creation time.

paramresource_idstr

The resource to create the client for (format: res_...).

paramclientResourceClient

The client properties. scopes should be the same or a subset of the scopes available for the resource. custom_claims is a flat key/value structure only. expiry (access token lifetime in seconds) defaults to the resource’s configured expiry. redirect_uris are the allowed redirect URIs for a pre-registered client. There is no audience field - audience is always server-determined.

name, description, scopes, custom_claims, expiry, redirect_uris
returnsCreateResourceClientResponse

The created client and its plaintext secret.

from scalekit.v1.clients.clients_pb2 import ResourceClient as ResourceClientProto
res_resource = scalekit_client.resources.get_resource('res_xxx')
allowed_scopes = [s.name for s in res_resource[0].resource.scopes if s.enabled]
response = scalekit_client.resources.create_resource_client(
'res_xxx',
ResourceClientProto(name='My Resource Client', scopes=allowed_scopes),
)
print(response[0].client.client_id)
# Store response[0].plain_secret in your secret manager now - it is never
# returned again. It grants full access as this client, so if it leaks,
# replace it right away: create a new secret and delete the compromised one
# (delete first if you're already at your secret limit; if it's your only
# secret, raise the limit before rotating).
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-python/blob/main/scalekit/resource.py
#asyncget_resource_client

Fetches a single resource client, along with the end-users who have granted it consent.

paramresource_idstr

The resource the client must belong to (format: res_...).

paramclient_idstr

The client ID (format: m2m_...).

returnsGetResourceClientResponse

The resource client.

response = scalekit_client.resources.get_resource_client('res_xxx', 'm2m_xxx')
print(response[0].client.name)
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-python/blob/main/scalekit/resource.py
#asynclist_resource_clients

Lists resource clients.

paramresource_idstr

The resource whose clients to list (format: res_...).

returnsListResourceClientsResponse

The resource’s clients, plus total_dcr_clients and total_static_clients counts.

response = scalekit_client.resources.list_resource_clients('res_xxx')
print(response[0].total_dcr_clients, response[0].total_static_clients)
for c in response[0].clients:
print(c.client_id, c.name)
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-python/blob/main/scalekit/resource.py
#asyncupdate_resource_client

Updates a resource client.

paramresource_idstr

The resource the client must belong to (format: res_...).

paramclient_idstr

The client ID to update (format: m2m_...).

paramnameOptional[str]

Updated name, if changing it. A no-op server-side when passed as an empty string, not a clear.

paramdescriptionOptional[str]

Updated description, if changing it. Same empty-string behavior as name.

paramscopesOptional[List[str]]

Updated scopes, if changing them. Pass [] (not None) to clear.

paramcustom_claimsOptional[List[CustomClaim]]

Updated custom claims, if changing them. Pass [] to clear.

paramexpiryOptional[int]

Updated access token lifetime in seconds, if changing it.

paramredirect_urisOptional[List[str]]

Updated redirect URIs, if changing them. Pass [] to clear.

returnsUpdateResourceClientResponse

The updated client.

Only the parameters you pass (non-None) are changed. There’s no audience parameter - audience is always server-determined.

res_resource = scalekit_client.resources.get_resource('res_xxx')
allowed_scopes = [s.name for s in res_resource[0].resource.scopes if s.enabled]
response = scalekit_client.resources.update_resource_client(
'res_xxx', 'm2m_xxx',
name='Updated Name',
scopes=allowed_scopes,
)
print(response[0].client.name, list(response[0].client.scopes))
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-python/blob/main/scalekit/resource.py
#asyncdelete_resource_client

Deletes resource clients. Raises if the client is missing or scoped to a different resource.

paramresource_idstr

The resource the client must belong to (format: res_...).

paramclient_idstr

The client ID to delete (format: m2m_...).

returnsDeleteResourceClientResponse

Empty response on success.

scalekit_client.resources.delete_resource_client('res_xxx', 'm2m_xxx')
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-python/blob/main/scalekit/resource.py
#asynccreate_resource_client_secret

Creates a new secret for a resource client. Only 2 client secrets are recommended to exist at a given point in time - use delete_resource_client_secret to remove an existing one first if you need more.

The plaintext client secret is only ever returned here, at creation time.

paramresource_idstr

The resource the client must belong to (format: res_...).

paramclient_idstr

The client ID to create a secret for (format: m2m_...).

returnsCreateClientSecretResponse

The new secret, including its plaintext value.

response = scalekit_client.resources.create_resource_client_secret('res_xxx', 'm2m_xxx')
# Store response[0].plain_secret in your secret manager now - it is never
# returned again. It grants full access as this client, so if it leaks,
# replace it right away: create a new secret and delete the compromised one
# (delete first if you're already at your secret limit; if it's your only
# secret, raise the limit before rotating).
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-python/blob/main/scalekit/resource.py
#asyncdelete_resource_client_secret

Permanently deletes a secret from a resource client. A client must always keep at least 1 secret - calling this on a client’s last remaining secret raises an error.

paramresource_idstr

The resource the client must belong to (format: res_...).

paramclient_idstr

The client ID the secret belongs to (format: m2m_...).

paramsecret_idstr

The secret ID to delete (format: sks_...).

returnsTuple[Empty, grpc.Call]

Empty response on success.

scalekit_client.resources.delete_resource_client_secret('res_xxx', 'm2m_xxx', 'sks_xxx')
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-python/blob/main/scalekit/resource.py
#asynclist_user_consents

Lists the end-user consents granted against a resource, with pagination. Use this to audit who authorized a client, and to find the consent_id you need before revoking.

Filter by user in one of two ways. Pass user_ids to match external user IDs exactly and case-sensitively. Pass search for a case-insensitive substring match. When you give both, user_ids wins and search is ignored.

paramresource_idstr

The resource whose consents to list (format: res_...).

paramsearchOptional[str]

Case-insensitive substring match on external user IDs.

parampage_sizeOptional[int]

Page size for pagination (max 30).

parampage_tokenOptional[str]

Page token for pagination.

paramuser_idsOptional[List[str]]

Exact match on external user IDs (max 25). Takes precedence over search.

returnsListResourceUserConsentsResponse

Consents with id, external_user_id, client_id, client_name, scopes, and granted_at, plus total_size and the next_page_token / prev_page_token cursors.

response = scalekit_client.resources.list_user_consents(
'res_xxx',
page_size=20,
user_ids=['user_456'], # optional; takes precedence over search
)
print(response[0].total_size, response[0].next_page_token)
for consent in response[0].consents:
print(consent.id, consent.external_user_id, consent.client_id, consent.scopes)
clientResourceshttps://github.com/scalekit-inc/scalekit-sdk-python/blob/main/scalekit/resource.py