Skip to main content
GET
List workspaces

Authorizations

Authorization
string
header
required

An agent key (rpk_...) created in Settings → API & MCP, sent as Authorization: Bearer rpk_.... Bearer only: a cookie session can never drive this API. An OAuth 2.1 access token obtained from the same host works identically and lands on the same ceiling.

Headers

X-Workspace-Id
string

Which workspace to read. Omit it and you get the account’s home workspace, which on an agency account is often not where the live businesses are. A workspace this credential cannot read is refused with 403 rather than quietly answered from the default.

Query Parameters

q
string

JSON filter object, for example {"needs_response":true}.

sort_by
string

Field to sort on.

limit
integer

Maximum rows to return.

skip
integer

Rows to skip, for paging.

Response

Matching workspaces.

id
string

Unique id.

agency_id
string

FK to Agency.id. The agency-of-1 signup flow (PR-2) creates exactly one workspace per agency by default; the agency console (PR-3) lets owners create more.

name
string
slug
string
owner_user_id
string
is_active
boolean
is_prospects
boolean

True on the agency's single auto-provisioned 'Prospects' workspace (see server/lib/prospectsWorkspace.js). Prospect-audit data (inactive is_prospect BusinessLocations, their reviews and visibility snapshots) lives here instead of a client workspace. Created lazily on the first audit.