> ## Documentation Index
> Fetch the complete documentation index at: https://developer.communicate.so/llms.txt
> Use this file to discover all available pages before exploring further.

# List owned notification devices without endpoint or key secrets

> Use an explicit notifications:read or notifications:write account grant, or an application session. Devices belong to the authenticated user; workspace settings retain live membership and agent access. Member summaries require the live owner/admin role. Cookie writes still require a trusted Origin. Provider acceptance alone does not establish device delivery.



## OpenAPI

````yaml https://app.communicate.so/api/v1/openapi/mintlify.json get /member-notifications/subscriptions
openapi: 3.1.0
info:
  title: Communicate Public REST API
  version: 1.1.0
  summary: >-
    Scoped agent chat, account credential lifecycle and workspace bootstrap
    operations.
  description: >-
    Canonical external schema for implemented REST operations. Account
    credentials and application sessions authorize the documented account and
    workspace operations separately from workspace keys. Exchange a workspace
    API-key client ID and secret for a short-lived OAuth access token, or use
    the `ck_` key directly for backward compatibility. `requestId` is optional
    but, when supplied, becomes the idempotency key for retries of the same chat
    input.
servers:
  - url: https://app.communicate.so/api/v1
    description: Canonical external base URL served through the Next.js /api/v1 rewrite.
security:
  - oauth2: []
  - bearerAuth: []
paths:
  /member-notifications/subscriptions:
    get:
      tags:
        - Notifications
      summary: List owned notification devices without endpoint or key secrets
      description: >-
        Use an explicit notifications:read or notifications:write account grant,
        or an application session. Devices belong to the authenticated user;
        workspace settings retain live membership and agent access. Member
        summaries require the live owner/admin role. Cookie writes still require
        a trusted Origin. Provider acceptance alone does not establish device
        delivery.
      operationId: listNotificationDevices
      parameters: []
      responses:
        '200':
          description: List owned notification devices without endpoint or key secrets
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/listNotificationDevicesResponse'
        '401':
          description: >-
            Missing, invalid, expired or revoked account credential or
            application session.
        '403':
          description: >-
            Required account scope, live verified identity, membership or role
            permission is missing.
        '404':
          description: Workspace or addressed resource is not visible to this member.
        '429':
          description: Notification mutation or test rate limit exceeded.
        '500':
          description: Unexpected server failure.
        '503':
          description: Push is not configured or the provider is temporarily unavailable.
      security:
        - accountBearer: []
        - accountSession: []
        - localAccountSession: []
components:
  schemas:
    listNotificationDevicesResponse:
      type: object
      properties:
        devices:
          type: array
          items:
            type: object
            properties:
              id:
                type: string
                minLength: 1
              label:
                type: string
              status:
                type: string
                enum:
                  - enabled
                  - expired
                  - attention
              lastActiveAt:
                type: string
                format: date-time
                pattern: >-
                  ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
              lastSuccessAt:
                anyOf:
                  - type: string
                    format: date-time
                    pattern: >-
                      ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z|([+-](?:[01]\d|2[0-3]):[0-5]\d)))$
                  - type: 'null'
              needsAttention:
                type: boolean
              failureClass:
                anyOf:
                  - type: string
                  - type: 'null'
            required:
              - id
              - label
              - status
              - lastActiveAt
              - lastSuccessAt
              - needsAttention
              - failureClass
            additionalProperties: false
      required:
        - devices
      additionalProperties: false
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        OAuth 2.0 client-credentials tokens bounded by the source API key scope
        ceiling.
      flows:
        clientCredentials:
          tokenUrl: https://app.communicate.so/api/v1/oauth/token
          scopes:
            agents:read: List agents in the authenticated workspace.
            chat:write: Create chat turns with an agent in the authenticated workspace.
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API key
      description: Workspace API key token with the `ck_` prefix.
    accountBearer:
      type: http
      scheme: bearer
      bearerFormat: Account credential
      description: >-
        Opaque user-bound `ca_` account credential. Each request checks live
        account scopes, verified email, expiry, revocation and the issuer
        session. Not a workspace `ck_` key or OAuth access token.
    accountSession:
      type: apiKey
      in: cookie
      name: __Secure-better-auth.session_token
      description: >-
        Signed Better Auth session cookie for an HTTPS application origin.
        Credential management additionally requires verified email and fresh
        password proof on writes.
    localAccountSession:
      type: apiKey
      in: cookie
      name: better-auth.session_token
      description: >-
        Signed session cookie used when the configured application auth origin
        is HTTP, such as local development.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.