> ## Documentation Index
> Fetch the complete documentation index at: https://ara-90a60a07.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# List projects

> Lists all unarchived projects accessible to the authenticated principal in this workspace. Requires sessions:read. Pass an item's id as project_id when creating a session. Projects are managed in the Ara app.

<sub>Scope: `sessions:read`</sub>



## OpenAPI

````yaml /openapi.json get /v3/organizations/{orgId}/projects
openapi: 3.1.0
info:
  title: Ara API
  version: 3.0.0
  description: >-
    The Ara HTTP API. Drive cloud software-engineering agents: open sessions
    against your repositories, stream their work, and manage the secrets,
    knowledge, skills, and automations they run with.


    All requests authenticate with an `ara_` API key sent as a bearer token.
    Every resource is scoped to an organization; resolve your `org_id` once with
    `GET /v3/self`.
servers:
  - url: https://api.reasonmachines.ai
security:
  - araApiKey: []
tags:
  - name: Devices
    description: >-
      Owned Mac and headless Device identity, bounded enrollment and root
      grants.
  - name: Account
    description: Verify a key and resolve the organization it belongs to.
  - name: Projects
    description: >-
      Discover existing workspace projects to target when creating and listing
      sessions.
  - name: Sessions
    description: >-
      A session is one run of an agent against a repository: it reproduces the
      task, writes the code, verifies it, and opens a pull request or merge
      request.
  - name: Secrets
    description: >-
      Encrypted credentials injected into the agent's sandbox. Write-only:
      values can be set but never read back.
  - name: Knowledge
    description: Durable notes the agent consults while it works.
  - name: Memory
    description: >-
      Editable repository notes that are projected into native memory; generated
      memory remains read-only.
  - name: Skills
    description: >-
      Reusable instruction bundles Ara selects semantically from their
      descriptions for matching agent tasks.
  - name: Automations
    description: Recurring or one-time triggers that open sessions on a timetable.
  - name: Change Request Reviews
    description: >-
      Automated senior-engineer reviews posted on pull requests and merge
      requests.
  - name: Repositories
    description: Connected repositories, their indexing state, and generated wikis.
  - name: Git Connections
    description: Linked source-control accounts and the repositories they expose.
  - name: Consumption
    description: 'Billing-aligned usage: daily consumption and billing cycles.'
  - name: Metrics
    description: Aggregate analytics over sessions, change requests, and usage.
  - name: Audit Logs
    description: An append-only record of changes made within the organization.
  - name: Organizations
    description: The top-level tenant. Create, read, update, and delete organizations.
  - name: Members
    description: People in an organization and their pending invites.
  - name: Service Users
    description: Machine principals that own API keys for headless access.
  - name: Roles
    description: Role assignments that govern what each member can do.
  - name: Attachments
    description: >-
      Files uploaded to the organization and shared with sessions, downloaded
      via short-lived signed URLs.
  - name: Guardrails
    description: >-
      Per-repository automation limits and the violations recorded when a limit
      is hit.
  - name: MCP Servers
    description: >-
      Org-level Model Context Protocol servers exposed to the agent. Secret
      values are write-only.
  - name: Settings
    description: 'Organization configuration: namespaced settings and the run tag policy.'
  - name: Blueprints
    description: >-
      Read-only declarative manifests of an organization's agents (identity, run
      config, triggers, suite), with credentials redacted.
  - name: IP Access List
    description: >-
      Source-network allow-list that, when enabled, restricts the organization's
      API surface to a set of CIDR ranges.
  - name: Groups
    description: Manually-curated member groups carrying optional per-day resource limits.
paths:
  /v3/organizations/{orgId}/projects:
    parameters:
      - $ref: '#/components/parameters/orgId'
    get:
      tags:
        - Projects
      summary: List projects
      description: >-
        Lists all unarchived projects accessible to the authenticated principal
        in this workspace. Requires sessions:read. Pass an item's id as
        project_id when creating a session. Projects are managed in the Ara app.


        <sub>Scope: `sessions:read`</sub>
      operationId: listProjects
      responses:
        '200':
          description: Accessible projects.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProjectList'
        '403':
          $ref: '#/components/responses/Forbidden'
      security:
        - araApiKey:
            - sessions:read
components:
  parameters:
    orgId:
      name: orgId
      in: path
      required: true
      description: Organization id or slug. Resolve it with `GET /v3/self`.
      schema:
        type: string
  schemas:
    ProjectList:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/Project'
        total:
          type: integer
        end_cursor:
          type: 'null'
        has_next_page:
          type: boolean
          const: false
      required:
        - items
        - total
        - end_cursor
        - has_next_page
    Project:
      type: object
      properties:
        id:
          type: string
          format: uuid
          description: Pass this id as project_id when creating or listing sessions.
        name:
          type: string
        slug:
          type: string
        description:
          type:
            - string
            - 'null'
        kind:
          type: string
          enum:
            - local
            - remote
        cloud_enabled:
          type: boolean
          description: >-
            Whether this Project permits the default cloud session target. When
            false, select a compatible Device target explicitly.
        visibility:
          type: string
          enum:
            - workspace
            - private
        resources:
          type: array
          items:
            $ref: '#/components/schemas/ProjectResource'
      required:
        - id
        - name
        - slug
        - description
        - kind
        - cloud_enabled
        - visibility
        - resources
      description: An existing, accessible project and its session resources.
    Error:
      type: object
      properties:
        error:
          type: string
        message:
          type: string
        required_scope:
          type: string
          description: >-
            The capability required when the request was denied for a missing
            scope.
    ProjectResource:
      oneOf:
        - type: object
          properties:
            id:
              type: string
            role:
              type: string
              enum:
                - primary
                - context
            access_mode:
              type: string
              enum:
                - read_only
                - read_write
            display_name:
              type: string
            status:
              type: string
              enum:
                - active
                - unavailable
                - retired
            write_allowed:
              type: boolean
            kind:
              type: string
              const: repository
            scm_repository_id:
              type: string
            provider:
              type: string
            full_path:
              type: string
          required:
            - id
            - role
            - access_mode
            - display_name
            - status
            - write_allowed
            - kind
            - scm_repository_id
            - provider
            - full_path
        - type: object
          properties:
            id:
              type: string
            role:
              type: string
              enum:
                - primary
                - context
            access_mode:
              type: string
              enum:
                - read_only
                - read_write
            display_name:
              type: string
            status:
              type: string
              enum:
                - active
                - unavailable
                - retired
            write_allowed:
              type: boolean
            kind:
              type: string
              const: remote_machine_folder
            local_execution_root_id:
              type: string
            device_id:
              type: string
            label:
              type: string
          required:
            - id
            - role
            - access_mode
            - display_name
            - status
            - write_allowed
            - kind
            - local_execution_root_id
            - device_id
            - label
  responses:
    Forbidden:
      description: The key lacks the required scope or role.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: missing_scope
            required_scope: sessions:read
  securitySchemes:
    araApiKey:
      type: http
      scheme: bearer
      bearerFormat: ara_<hex>
      description: >-
        Your `ara_` API key from Settings > Ara API. Keys are capability-scoped:
        run, mcp:read, mcp:write, secrets:read, secrets:write, sessions:read,
        sessions:debug, knowledge:read, memory:read, memory:write, skills:read,
        skills:write, repos:read, repos:write, reviews:read, reviews:write,
        deployment:read, analytics:read, org:read, org:write, attachments:read,
        attachments:write, guardrails:read, guardrails:write, automations:read,
        automations:write, agent_auth:read. mcp:write manages MCP server
        configuration only; it does not authorize remote MCP-tool execution.
        sessions:debug is privileged: it expands diagnostic session events only
        for organization owners/admins.

````