> This page is for version 2025-09-18 (default).
> For other versions, use one of these documentation indexes:
> - 2025-09-18 (default): https://apidocs.polytomic.com/2025-09-18/llms.txt
> - 2024-02-08: https://apidocs.polytomic.com/2024-02-08/llms.txt
> - 2023-04-25: https://apidocs.polytomic.com/2023-04-25/llms.txt
> - 2022-12-12: https://apidocs.polytomic.com/2022-12-12/llms.txt
> - 2021-05-23: https://apidocs.polytomic.com/2021-05-23/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://apidocs.polytomic.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://apidocs.polytomic.com/_mcp/server.

# List Harbor Actions

GET https://app.polytomic.com/api/harbors/{harbor_id}/actions

List a page of configured action identities without loading provider capabilities or field metadata.

Use a scoped credential belonging to this Harbor. An administrator must first
select Connections and explicitly enable object operations and fields. These
grants apply to existing and future eligible Harbor credentials without changing
read access. Newly available objects and fields remain disabled until selected.

Each entry identifies a configured operation by `connection_id`, `schema_id`, and
`operation_id`. Search filters those identities. Follow
`pagination.next_page_token` with the same search to read additional pages.
Pages contain saved identities without field metadata or provider capability
checks. `unavailable: true` means the saved Connection is unavailable for actions;
its permissions remain saved and revocable. An available Connection does not
confirm that its operations or granted fields are currently available.

Use [Describe action](../../../../api-reference/harbors/actions/describe) for the selected
operation before looking up a record or
[preparing an action](../../../../api-reference/harbors/actions/prepare). Description checks
current provider capabilities and returns the operation's `effect` (`read_only`
or `mutating`) and effective granted fields.
Always submit the intended Connection explicitly when looking up or preparing,
even if only one is enabled. If several destinations match your intent, clarify
which one to use.

Read-only operations use [Lookup action](../../../../api-reference/harbors/actions/lookup)
without preparation or approval. Salesforce and HubSpot support exact lookups by
their canonical record ID. Listing does not grant additional permissions or
authorize mutations by a read-only credential.

Send a new nonzero UUID in `X-Polytomic-Activity-Request-ID`. For direct REST
requests, `X-Polytomic-Harbor-Session` is optional. If supplied, the session must
be active and bound to the credential and Harbor. Discovery is recorded as
`action.listed`; no response is returned if that event cannot be recorded.

Reference: https://apidocs.polytomic.com/api-reference/harbors/actions/list

## Authentication

- `Authorization` header (bearer token, required) — Bearer user API key
- `Authorization` header (basic auth, required) — Basic organization-scoped API key

## Request

### Path parameters

- `harbor_id` (string, required) — Unique identifier of the Harbor.

### Query parameters

- `search` (string, optional) — Filter configured schema or operation identities.
- `page_token` (string, optional) — Continuation token from the previous page; keep search unchanged.
- `limit` (integer, optional, default: 50)

### Headers

- `X-Polytomic-Harbor-Session` (string, optional)
- `X-Polytomic-Activity-Request-ID` (string, optional)

## Response

### 200

OK

- `data` (list of HarborActionSummary, optional, nullable)
- `pagination` (HarborActionListEnvelopePagination, optional)

## Types

### HarborActionSummary

- `connection_id` (string, optional)
- `connection_name` (string, optional)
- `operation_id` (string, optional)
- `schema_id` (string, optional)
- `unavailable` (boolean, optional)

### HarborActionListEnvelopePagination

- `next_page_token` (string, optional)

## Examples

**Response**

```json
{
  "data": [
    {
      "connection_id": "248df4b7-aa70-47b8-a036-33ac447e668d",
      "connection_name": "string",
      "operation_id": "string",
      "schema_id": "string",
      "unavailable": true
    }
  ],
  "pagination": {
    "next_page_token": "string"
  }
}
```

**SDK Code**

```python
import requests

url = "https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions"

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers)

print(response.json())
```

```javascript
const url = 'https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions");
var request = new RestRequest(Method.GET);
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = ["Authorization": "Bearer <token>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://app.polytomic.com/api/harbors/248df4b7-aa70-47b8-a036-33ac447e668d/actions")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```