> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-docs-google-workspace-action-examples.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Add Binding

> AddBinding associates a tenant-scoped subject with an existing service
 principal. Subjects support zero-to-many bindings; the same pair is
 idempotent and a soft-deleted pair is restored. Associations do not define
 runtime identity selection. Requires SERVICE_PRINCIPALS and the subject's
 feature flag, plus existing service-principal and subject permissions.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/service_principals/bindings
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/service_principals/bindings:
    post:
      tags:
        - Service Principal Binding
      summary: Add Binding
      description: |-
        AddBinding associates a tenant-scoped subject with an existing service
         principal. Subjects support zero-to-many bindings; the same pair is
         idempotent and a soft-deleted pair is restored. Associations do not define
         runtime identity selection. Requires SERVICE_PRINCIPALS and the subject's
         feature flag, plus existing service-principal and subject permissions.
      operationId: c1.api.service_principal.v1.ServicePrincipalService.AddBinding
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceAddBindingRequest
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.service_principal.v1.ServicePrincipalServiceAddBindingResponse
          description: Successful response
      x-codeSamples:
        - lang: typescript
          label: Typescript (SDK)
          source: >-
            import { ConductoroneSDKTypescript } from
            "conductorone-sdk-typescript";


            const conductoroneSDKTypescript = new ConductoroneSDKTypescript({
              security: {
                bearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
                oauth: "<YOUR_OAUTH_HERE>",
              },
            });


            async function run() {
              const result = await conductoroneSDKTypescript.principal.addBinding();

              console.log(result);
            }


            run();
        - lang: go
          label: AddBinding
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.Principal.AddBinding(ctx, nil)\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.ServicePrincipalServiceAddBindingResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    c1.api.service_principal.v1.ServicePrincipalServiceAddBindingRequest:
      description: The ServicePrincipalServiceAddBindingRequest message.
      properties:
        servicePrincipalId:
          description: The servicePrincipalId field.
          type: string
        subject:
          oneOf:
            - $ref: >-
                #/components/schemas/c1.api.service_principal.v1.ServicePrincipalBindingSubject
            - type: 'null'
      title: Service Principal Service Add Binding Request
      type: object
      x-speakeasy-name-override: ServicePrincipalServiceAddBindingRequest
    c1.api.service_principal.v1.ServicePrincipalServiceAddBindingResponse:
      description: The ServicePrincipalServiceAddBindingResponse message.
      title: Service Principal Service Add Binding Response
      type: object
      x-speakeasy-name-override: ServicePrincipalServiceAddBindingResponse
    c1.api.service_principal.v1.ServicePrincipalBindingSubject:
      description: >
        ServicePrincipalBindingSubject identifies the entity that is bound to a
         service principal. Open-ended oneof so future subject kinds (workflows,
         connectors, etc.) can be added without changing the RPC shape.

        This message contains a oneof named kind. Only a single field of the
        following list may be set at a time:
          - functionId
          - ssoApplication
          - authzenServer
          - edge
      properties:
        authzenServer:
          oneOf:
            - $ref: '#/components/schemas/c1.api.authzen.v1.AuthzenServerRef'
            - type: 'null'
        edge:
          oneOf:
            - $ref: '#/components/schemas/c1.api.edge.v1.EdgeRef'
            - type: 'null'
        functionId:
          description: >-
            Function ID. The function authenticates outbound c1-api calls as
             user:<service_principal_id> instead of function:<function_id>.
            This field is part of the `kind` oneof.

            See the documentation for
            `c1.api.service_principal.v1.ServicePrincipalBindingSubject` for
            more details.
          type:
            - string
            - 'null'
        ssoApplication:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sso.v1.SSOApplicationRef'
            - type: 'null'
      title: Service Principal Binding Subject
      type: object
      x-speakeasy-name-override: ServicePrincipalBindingSubject
    c1.api.authzen.v1.AuthzenServerRef:
      description: The AuthzenServerRef message.
      properties:
        appId:
          description: The appId field.
          type: string
        id:
          description: The id field.
          type: string
      title: Authzen Server Ref
      type: object
      x-speakeasy-name-override: AuthzenServerRef
    c1.api.edge.v1.EdgeRef:
      description: The EdgeRef message.
      properties:
        appId:
          description: The appId field.
          type: string
        id:
          description: The id field.
          type: string
      title: Edge Ref
      type: object
      x-speakeasy-name-override: EdgeRef
    c1.api.sso.v1.SSOApplicationRef:
      description: The SSOApplicationRef message.
      properties:
        appId:
          description: The appId field.
          type: string
        id:
          description: The id field.
          type: string
      title: Sso Application Ref
      type: object
      x-speakeasy-name-override: SSOApplicationRef
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````