API
List your connected apps
Every app the person connected with OAuth, as Account, Connected apps lists them.
GET/account/connected-apps
Runs the real call on your workspace.
GET /account/connected-apps
Every app the person connected with OAuth, as Account, Connected apps lists them.
Example
Needs account:read. grant is what the person gave the app: one workspace, its permissions, the addresses and domains it may reach and until when. current marks the app making the call.
curl "$OE/account/connected-apps" -H "$AUTH"{ "object": "list", "data": [ { "object": "connected_app", "clientId": "kZ3mQ9vT2xR7pL4wN8bY1cF6hJ5sD0aE", "name": "Claude", "kind": "app", "cliDevice": null, "current": true, "registeredByAccount": false, "redirectUris": ["https://claude.ai/api/mcp/auth_callback"], "connectedAt": "2026-09-30T14:02:11.000Z", "accessUntil": "2026-10-30T14:02:11.000Z", "tokenCount": 1, "status": "active", "usablePermissions": 6, "elevatedUntil": null, "grant": { "workspaceId": "10417196-e324-4283-af98-66ec62167c47", "workspaceName": "Acme", "permissions": ["emails:read", "threads:read", "account:read", "account:write"], "addressAllowlist": null, "domainAllowlist": null, "expiresAt": null, "updatedAt": "2026-09-30T14:02:11.000Z" } } ]}elevatedUntil says until when the app may make changes that ask for a verification code without one. Starting that window, and changing what an app may reach, are done in the app only, because an app must never widen its own access.
A sign-in of the command line tool is listed with kind set to cli and its device in cliDevice.