Resource
Manage resource clients and the consents your end users grant against them
Use scalekit_client.resources to manage resource clients and to read and revoke the consents your end users grant against one. A consent records that one end user allowed a specific resource client to act on their behalf.
The same audit and revoke actions are available in the dashboard under Managing MCP clients.
get_resource
Section titled “get_resource”#asyncget_resource
Retrieves a single resource by id.
The resource to fetch (format: res_...).
Resource object.
response = scalekit_client.resources.get_resource('res_xxx')print(response[0].resource)list_resources
Section titled “list_resources”#asynclist_resources
Lists resources of a given type in the environment, with pagination.
The resource type to filter by. Supported value: ResourceType.MCP_SERVER.
Page size for pagination (max 30).
Page token for pagination.
Paginated resources.
from scalekit.v1.clients.clients_pb2 import ResourceType
response = scalekit_client.resources.list_resources( resource_type=ResourceType.MCP_SERVER, page_size=20,)
for resource in response[0].resources: print(resource.id, resource.scopes)create_resource_client
Section titled “create_resource_client”#asynccreate_resource_client
Creates a resource client. Returns the created client and a plain_secret - the plaintext client secret, only available at creation time.
The resource to create the client for (format: res_...).
The client properties. scopes should be the same or a subset of the scopes available for the resource. custom_claims is a flat key/value structure only. expiry (access token lifetime in seconds) defaults to the resource’s configured expiry. redirect_uris are the allowed redirect URIs for a pre-registered client. There is no audience field - audience is always server-determined.
The created client and its plaintext secret.
from scalekit.v1.clients.clients_pb2 import ResourceClient as ResourceClientProto
res_resource = scalekit_client.resources.get_resource('res_xxx')allowed_scopes = [s.name for s in res_resource[0].resource.scopes if s.enabled]
response = scalekit_client.resources.create_resource_client( 'res_xxx', ResourceClientProto(name='My Resource Client', scopes=allowed_scopes),)
print(response[0].client.client_id)# Store response[0].plain_secret in your secret manager now - it is never# returned again. It grants full access as this client, so if it leaks,# replace it right away: create a new secret and delete the compromised one# (delete first if you're already at your secret limit; if it's your only# secret, raise the limit before rotating).get_resource_client
Section titled “get_resource_client”#asyncget_resource_client
Fetches a single resource client, along with the end-users who have granted it consent.
The resource the client must belong to (format: res_...).
The client ID (format: m2m_...).
The resource client.
response = scalekit_client.resources.get_resource_client('res_xxx', 'm2m_xxx')print(response[0].client.name)list_resource_clients
Section titled “list_resource_clients”#asynclist_resource_clients
Lists resource clients.
The resource whose clients to list (format: res_...).
The resource’s clients, plus total_dcr_clients and total_static_clients counts.
response = scalekit_client.resources.list_resource_clients('res_xxx')
print(response[0].total_dcr_clients, response[0].total_static_clients)for c in response[0].clients: print(c.client_id, c.name)update_resource_client
Section titled “update_resource_client”#asyncupdate_resource_client
Updates a resource client.
The resource the client must belong to (format: res_...).
The client ID to update (format: m2m_...).
Updated name, if changing it. A no-op server-side when passed as an empty string, not a clear.
Updated description, if changing it. Same empty-string behavior as name.
Updated scopes, if changing them. Pass [] (not None) to clear.
Updated custom claims, if changing them. Pass [] to clear.
Updated access token lifetime in seconds, if changing it.
Updated redirect URIs, if changing them. Pass [] to clear.
The updated client.
Only the parameters you pass (non-None) are changed. There’s no audience parameter - audience is always server-determined.
res_resource = scalekit_client.resources.get_resource('res_xxx')allowed_scopes = [s.name for s in res_resource[0].resource.scopes if s.enabled]
response = scalekit_client.resources.update_resource_client( 'res_xxx', 'm2m_xxx', name='Updated Name', scopes=allowed_scopes,)
print(response[0].client.name, list(response[0].client.scopes))delete_resource_client
Section titled “delete_resource_client”#asyncdelete_resource_client
Deletes resource clients. Raises if the client is missing or scoped to a different resource.
The resource the client must belong to (format: res_...).
The client ID to delete (format: m2m_...).
Empty response on success.
scalekit_client.resources.delete_resource_client('res_xxx', 'm2m_xxx')create_resource_client_secret
Section titled “create_resource_client_secret”#asynccreate_resource_client_secret
Creates a new secret for a resource client. Only 2 client secrets are recommended to exist at a given point in time - use delete_resource_client_secret to remove an existing one first if you need more.
The plaintext client secret is only ever returned here, at creation time.
The resource the client must belong to (format: res_...).
The client ID to create a secret for (format: m2m_...).
The new secret, including its plaintext value.
response = scalekit_client.resources.create_resource_client_secret('res_xxx', 'm2m_xxx')# Store response[0].plain_secret in your secret manager now - it is never# returned again. It grants full access as this client, so if it leaks,# replace it right away: create a new secret and delete the compromised one# (delete first if you're already at your secret limit; if it's your only# secret, raise the limit before rotating).delete_resource_client_secret
Section titled “delete_resource_client_secret”#asyncdelete_resource_client_secret
Permanently deletes a secret from a resource client. A client must always keep at least 1 secret - calling this on a client’s last remaining secret raises an error.
The resource the client must belong to (format: res_...).
The client ID the secret belongs to (format: m2m_...).
The secret ID to delete (format: sks_...).
Empty response on success.
scalekit_client.resources.delete_resource_client_secret('res_xxx', 'm2m_xxx', 'sks_xxx')list_user_consents
Section titled “list_user_consents”#asynclist_user_consents
Lists the end-user consents granted against a resource, with pagination. Use this to audit who authorized a client, and to find the consent_id you need before revoking.
Filter by user in one of two ways. Pass user_ids to match external user IDs exactly and case-sensitively. Pass search for a case-insensitive substring match. When you give both, user_ids wins and search is ignored.
The resource whose consents to list (format: res_...).
Case-insensitive substring match on external user IDs.
Page size for pagination (max 30).
Page token for pagination.
Exact match on external user IDs (max 25). Takes precedence over search.
Consents with id, external_user_id, client_id, client_name, scopes, and granted_at, plus total_size and the next_page_token / prev_page_token cursors.
response = scalekit_client.resources.list_user_consents( 'res_xxx', page_size=20, user_ids=['user_456'], # optional; takes precedence over search)
print(response[0].total_size, response[0].next_page_token)for consent in response[0].consents: print(consent.id, consent.external_user_id, consent.client_id, consent.scopes)revoke_user_consent
Section titled “revoke_user_consent”#asyncrevoke_user_consent
Revokes a single end-user consent held by a resource client. The client is prompted for consent again on its next authorization attempt, and every active refresh token issued to that client for the same user is revoked.
Access tokens that Scalekit already issued stay valid until they expire. See How revocation affects active access tokens for ways to shorten that window.
The resource client that holds the consent (format: m2m_...), not the resource ID.
The consent to revoke (format: usrcnst_...), taken from list_user_consents.
Empty response on success. The call raises on failure.
scalekit_client.resources.revoke_user_consent('m2m_xxx', 'usrcnst_789')