> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://apidocs.polytomic.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://apidocs.polytomic.com/_mcp/server.

# Lookup Harbor Action

POST https://app.polytomic.com/api/harbors/{harbor_id}/actions/lookup
Content-Type: application/json

Look up exactly one record using a granted read-only Harbor action.

Use a scoped credential belonging to this Harbor, including a read-only
credential. An administrator must grant the Connection, read-only operation,
lookup field, and returned fields. Select an identity with
[List actions](../../../../../api-reference/harbors/actions/list), then inspect its effective
lookup and output fields with
[Describe action](../../../../../api-reference/harbors/actions/describe).

Polytomic checks current grants and provider capabilities on each lookup. The
response contains one record under `data`, limited to the selected fields.
Omitting `fields` returns all currently available granted outputs;
new provider fields remain excluded until an administrator grants them.
Salesforce uses `Id`; HubSpot uses `hs_object_id`. Preserve these IDs as strings.
Alternate keys, fuzzy matches, search, and batching are unsupported.

A definite absence returns `404 Not Found`. More than one exact match returns
`409 Conflict`. Invalid selections return `400 Bad Request`; unavailable
capabilities or provider failures return `503 Service Unavailable`. Errors do
not include lookup values or provider response bodies.

This request is synchronous and read-only. It requires no preparation, approval,
execution identifier, or status polling. It creates no write receipt or private
write evidence. Harbor Activity records `action.looked_up` with field names and
an outcome, never the lookup value or returned values. If Activity cannot be
recorded, Polytomic returns no record.

Unknown properties, duplicate keys, invalid Unicode, trailing JSON, and bodies
larger than 256 KiB are rejected. Lookup values must be JSON scalars. Numeric
values must use integer notation within +/-9007199254740991.

Send a new nonzero UUID in `X-Polytomic-Activity-Request-ID` for each request.
`X-Polytomic-Harbor-Session` is optional for direct REST requests. A supplied
session must be active and bound to your credential and Harbor.

Reference: https://apidocs.polytomic.com/api-reference/harbors/actions/lookup

## Authentication

- `Authorization` header (bearer token, required) — Bearer user API key
- `Authorization` header (basic auth, required) — Basic organization-scoped API key

## Request

### Path parameters

- `harbor_id` (string, required) — Unique identifier of the Harbor.

### Headers

- `X-Polytomic-Harbor-Session` (string, optional)
- `X-Polytomic-Activity-Request-ID` (string, optional)

### Body (application/json)

This endpoint expects a LookupHarborActionRequest.

- `connection_id` (string, required) — Connection ID from Harbor action discovery.
- `lookup` (ActionLookup, required)
- `operation_id` (string, required) — Exact read-only operation ID from action discovery.
- `schema_id` (string, required) — Exact schema ID from action discovery.
- `fields` (list of string, optional) — Unique, nonempty subset of granted output field IDs. Omit to return all currently available granted outputs. Null and empty arrays are invalid.

## Response

### 200

OK

- `data` (map from string to any, optional)

## Types

### ActionLookup

- `field_id` (string, optional)
- `value` (any, optional)

## Examples

**Request**

```json
{
  "connection_id": "248df4b7-aa70-47b8-a036-33ac447e668d",
  "operation_id": "string",
  "schema_id": "string"
}
```

**Response**

```json
{
  "data": {}
}
```

**SDK Code**

```python
import requests

url = "https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions/lookup"

payload = {
    "connection_id": "248df4b7-aa70-47b8-a036-33ac447e668d",
    "operation_id": "string",
    "schema_id": "string"
}
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions/lookup';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{"connection_id":"248df4b7-aa70-47b8-a036-33ac447e668d","operation_id":"string","schema_id":"string"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions/lookup"

	payload := strings.NewReader("{\n  \"connection_id\": \"248df4b7-aa70-47b8-a036-33ac447e668d\",\n  \"operation_id\": \"string\",\n  \"schema_id\": \"string\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions/lookup")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"connection_id\": \"248df4b7-aa70-47b8-a036-33ac447e668d\",\n  \"operation_id\": \"string\",\n  \"schema_id\": \"string\"\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions/lookup")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"connection_id\": \"248df4b7-aa70-47b8-a036-33ac447e668d\",\n  \"operation_id\": \"string\",\n  \"schema_id\": \"string\"\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions/lookup', [
  'body' => '{
  "connection_id": "248df4b7-aa70-47b8-a036-33ac447e668d",
  "operation_id": "string",
  "schema_id": "string"
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions/lookup");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"connection_id\": \"248df4b7-aa70-47b8-a036-33ac447e668d\",\n  \"operation_id\": \"string\",\n  \"schema_id\": \"string\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "connection_id": "248df4b7-aa70-47b8-a036-33ac447e668d",
  "operation_id": "string",
  "schema_id": "string"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions/lookup")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```