> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-leet-slack-mcp-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Bindings

> CreateBindings binds one or more scopes (xaa_scope_ids) to an access
 profile. Every scope must belong to the profile's resource server.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/apps/{app_id}/xaa/access_profiles/{access_profile_id}/scope_bindings
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/apps/{app_id}/xaa/access_profiles/{access_profile_id}/scope_bindings:
    post:
      tags:
        - Cross-App Access
      summary: Create Bindings
      description: |-
        CreateBindings binds one or more scopes (xaa_scope_ids) to an access
         profile. Every scope must belong to the profile's resource server.
      operationId: >-
        c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingService.CreateBindings
      parameters:
        - in: path
          name: app_id
          required: true
          schema:
            description: The application that owns the resource server.
            type: string
        - in: path
          name: access_profile_id
          required: true
          schema:
            description: The access profile to bind scopes to.
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceCreateRequestInput
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceCreateResponse
          description: >-
            XAAAccessProfileScopeBindingServiceCreateResponse returns created
            bindings.
      x-codeSamples:
        - lang: go
          label: CreateBindings
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/operations\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.XAAAccessProfileScopeBinding.CreateBindings(ctx, operations.C1APICrossAppAccessV1XAAAccessProfileScopeBindingServiceCreateBindingsRequest{\n        AccessProfileID: \"<id>\",\n        AppID: \"<id>\",\n    })\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.XAAAccessProfileScopeBindingServiceCreateResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceCreateRequestInput:
      description: >-
        XAAAccessProfileScopeBindingServiceCreateRequest binds scopes to a
        profile.
      properties:
        xaaScopeIds:
          description: Scope IDs to bind to the access profile.
          items:
            type: string
          type:
            - array
            - 'null'
      title: Xaa Access Profile Scope Binding Service Create Request
      type: object
      x-speakeasy-name-override: XAAAccessProfileScopeBindingServiceCreateRequest
    c1.api.cross_app_access.v1.XAAAccessProfileScopeBindingServiceCreateResponse:
      description: >-
        XAAAccessProfileScopeBindingServiceCreateResponse returns created
        bindings.
      properties:
        bindings:
          description: The created scope bindings.
          items:
            $ref: >-
              #/components/schemas/c1.api.cross_app_access.v1.XAAAccessProfileScopeBinding
          type:
            - array
            - 'null'
      title: Xaa Access Profile Scope Binding Service Create Response
      type: object
      x-speakeasy-name-override: XAAAccessProfileScopeBindingServiceCreateResponse
    c1.api.cross_app_access.v1.XAAAccessProfileScopeBinding:
      description: >-
        XAAAccessProfileScopeBinding is a binding between an access profile and
        a
         scope. Both ends belong to one resource server.
      properties:
        accessProfileId:
          description: The access profile end of the binding.
          type: string
        appId:
          description: The application that owns the resource server.
          type: string
        createdAt:
          format: date-time
          type:
            - string
            - 'null'
        deletedAt:
          format: date-time
          type:
            - string
            - 'null'
        updatedAt:
          format: date-time
          type:
            - string
            - 'null'
        xaaResourceServerId:
          description: The resource server both ends belong to.
          type: string
        xaaScopeId:
          description: The scope end of the binding.
          type: string
      title: Xaa Access Profile Scope Binding
      type: object
      x-speakeasy-name-override: XAAAccessProfileScopeBinding
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````