# How to read all entitlements through REST API call from PowerShell Script (with pagination)

**URL:** <https://developer.sailpoint.com/discuss/t/how-to-read-all-entitlements-through-rest-api-call-from-powershell-script-with-pagination/20931>\
**Category:** SHF Discussion and Questions\
**Tags:** identity-security-cloud\
**Created:** [November 15, 2023, 10:31am UTC](https://developer.sailpoint.com/discuss/t/how-to-read-all-entitlements-through-rest-api-call-from-powershell-script-with-pagination/20931 "2023-11-15T10:31:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrahulbb](https://avatars.discourse-cdn.com/v4/letter/m/96bed5/32.png) [@mrahulbb](https://developer.sailpoint.com/discuss/u/mrahulbb)\
**Post date:** [November 15, 2023, 10:31am UTC](https://developer.sailpoint.com/discuss/t/how-to-read-all-entitlements-through-rest-api-call-from-powershell-script-with-pagination/20931/1 "2023-11-15T10:31:25Z")

</div>

Please share if you have any sample code references to read all entitlements through REST API call from PowerShell Script (with pagination). We are working on reading all entitlements for all sources and check an attribute condition and update through PowerShell script. (limit is just 250 records)

---

<div class="post-metadata">

**Author:** ![Kurt\_Ramsey](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/kurt_ramsey/32/517_2.png) [@Kurt\_Ramsey](https://developer.sailpoint.com/discuss/u/Kurt_Ramsey)\
**Post date:** [November 15, 2023, 12:02pm UTC](https://developer.sailpoint.com/discuss/t/how-to-read-all-entitlements-through-rest-api-call-from-powershell-script-with-pagination/20931/2 "2023-11-15T12:02:45Z")

</div>

Using [GitHub - sailpoint-oss/powershell-sdk: PowerShell Module for accessing SailPoint IdentityNow APIs](https://github.com/sailpoint-oss/powershell-sdk)

This is a bit more than just the entitlements, but is part of a script that I have that exports all objects, this is what I have for sources

```auto
$orgName = "YOUR ORG"
$runtime = ([System.DateTime]::Now).ToString("yyyy-MM-ddTHH-mm-ss")

function Remove-NoteProperty {
    param(
        [Parameter(ValueFromPipeline=$true)]
        [PSCustomObject]$InputObject,
        [Parameter(Position=0)]
        [string]$Name
    )

    process {
        $InputObject.PSObject.Properties.Remove($Name)
        return $InputObject
    }
}

######################################################################################################
# ___
# / __|___ _ _ _ _ _____ ___
# \__ \/ _ \ || | '_/ _/ -_|_-<
# | ___/\___ /\_,_|_| \ __\___ /__/
#
######################################################################################################
	$objectType = "Sources"
	$Parameters = @{
	}

	try {
		$results = Invoke-Paginate -Function "Get-Sources" -Increment 250 -Limit 10000 -InitialOffset 0 -Parameters $Parameters
	} catch {
		Write-Host $_
		Write-Host ("Exception occurred when calling {1}: {0}" -f ($_.ErrorDetails | ConvertFrom-Json), "Get-Sources")
		Write-Host ("Response headers: {0}" -f ($_.Exception.Response.Headers | ConvertTo-Json))
	}

	foreach ($object in $results) {
		$objectName = $object.name
		$objectName = $objectName -replace '[\\/:*?"<>|]', ''
		$objectId = $object.id

		$object.connectorAttributes | Remove-NoteProperty -Name 'accesstoken' > $null
		$object.connectorAttributes | Remove-NoteProperty -Name 'client_secret' > $null
		$object.connectorAttributes | Remove-NoteProperty -Name 'IQServicePassword' > $null
		$object.connectorAttributes | Remove-NoteProperty -Name 'clientKeySpec' > $null
		$object.connectorAttributes | Remove-NoteProperty -Name 'password' > $null
		$object.connectorAttributes | Remove-NoteProperty -Name 'oauthBearerToken' > $null
		$object.connectorAttributes | Remove-NoteProperty -Name 'clientSecret' > $null
		$object.connectorAttributes | Remove-NoteProperty -Name 'sourceSecret' > $null
		$object.connectorAttributes | Remove-NoteProperty -Name 'accesstoken' > $null
		$object.connectorAttributes.domainSettings | Remove-NoteProperty -Name 'password' > $null

		$json = $object | ConvertTo-Json -Depth 100

		if (!(Test-Path -Path "$scriptDirectory\$orgName\$objectType\$objectName")) { New-Item -ItemType Directory -Force -Path "$scriptDirectory\$orgName\$objectType\$objectName" | Out-Null }
		Add-Content -Path "$scriptDirectory\$orgName\$objectType\$objectName\$objectName.json" -value "# https://$orgName.identitynow.com/ui/admin#admin:connections:sources:$objectId"
		Add-Content -Path "$scriptDirectory\$orgName\$objectType\$objectName\$objectName.json" -value $json

		#Get-BetaEntitlements
			$subobjectType = "Entitlements"
			if (!(Test-Path -Path "$scriptDirectory\$orgName\$subobjectType")) { New-Item -ItemType Directory -Force -Path "$scriptDirectory\$orgName\$subobjectType" | Out-Null }

			$Parameters = @{
				"Filters" = "source.id eq ""$objectId"""
			}
			try {

				$subResults = Invoke-Paginate -Function "Get-BetaEntitlements" -Increment 250 -Limit 100000 -InitialOffset 0 -Parameters $Parameters
				Set-Content -Path "$scriptDirectory\$orgName\$subobjectType\$objectName.$subobjectType.csv" -Value """entitlements.id"",""entitlements.name"",""type"",""SourceName"",""SourceValue"""
				foreach ($subObject in $subResults) {
					$entType = "$($subObject.attribute)".Trim()
					$entName = "$($subObject.name)".Trim()
					$entSourceName = "$($subObject.attributes.name)".Trim()
					$sourceName = "$($subObject.source.name)".Trim()
					$entValue = "$($subObject.value)".Trim()
					$entIDNID = "$($subObject.id)".Trim()
					Add-Content -Path "$scriptDirectory\$orgName\$subobjectType\$objectName.$subobjectType.csv" -value """$entIDNID"",""$entName"",""$entType"",""$entSourceName"",""$entValue"""
				}
				Start-Sleep -Seconds 1

			} catch {
				Write-Host $_
				Write-Host ("Exception occurred when calling {1}: {0}" -f ($_.ErrorDetails | ConvertFrom-Json), "Get-BetaEntitlements")
				Write-Host ("Response headers: {0}" -f ($_.Exception.Response.Headers | ConvertTo-Json))
			}

		#Get-SourceSchemas
			$subobjectType = "SourceSchemas"
			try {

				#$results = Invoke-Paginate -Function "Get-SourceSchemas" -Increment 250 -Limit 10000 -InitialOffset 0 -Parameters $Parameters
				$subResults = Get-SourceSchemas -SourceId $objectId
				foreach ($subObject in $subResults) {

					$json = $subObject | ConvertTo-Json -Depth 100

					$subObjectName = $subObject.name
					$subObjectId = $subObject.id

					if (!(Test-Path -Path "$scriptDirectory\$orgName\$objectType\$objectName")) { New-Item -ItemType Directory -Force -Path "$scriptDirectory\$orgName\$objectType\$objectName" | Out-Null }
					Add-Content -Path "$scriptDirectory\$orgName\$objectType\$objectName\$objectName.$subobjectType.$subObjectName.json" -value "# $orgName $subObjectId"
					Add-Content -Path "$scriptDirectory\$orgName\$objectType\$objectName\$objectName.$subobjectType.$subObjectName.json" -value $json

				}
				Start-Sleep -Seconds 1

			} catch {
				Write-Host $_
				Write-Host ("Exception occurred when calling {1}: {0}" -f ($_.ErrorDetails | ConvertFrom-Json), "Get-SourceSchemas")
				Write-Host ("Response headers: {0}" -f ($_.Exception.Response.Headers | ConvertTo-Json))
			}

		#Get-ProvisioningPolicies
			$subobjectType = "ProvisioningPolicies"
			try {

				#$results = Invoke-Paginate -Function "Get-ProvisioningPolicies" -Increment 250 -Limit 10000 -InitialOffset 0 -Parameters $Parameters
				$subResults = Get-ProvisioningPolicies -SourceId $objectId
				foreach ($subObject in $subResults) {

					$json = $subObject | ConvertTo-Json -Depth 100

					$subObjectName = $subObject.name
					$subObjectId = $subObject.id

					if (!(Test-Path -Path "$scriptDirectory\$orgName\$objectType\$objectName")) { New-Item -ItemType Directory -Force -Path "$scriptDirectory\$orgName\$objectType\$objectName" | Out-Null }
					Add-Content -Path "$scriptDirectory\$orgName\$objectType\$objectName\$objectName.$subobjectType.$subObjectName.json" -value "# $orgName $subObjectId"
					Add-Content -Path "$scriptDirectory\$orgName\$objectType\$objectName\$objectName.$subobjectType.$subObjectName.json" -value $json

				}
				Start-Sleep -Seconds 1

			} catch {
				Write-Host $_
				Write-Host ("Exception occurred when calling {1}: {0}" -f ($_.ErrorDetails | ConvertFrom-Json), "Get-ProvisioningPolicies")
				Write-Host ("Response headers: {0}" -f ($_.Exception.Response.Headers | ConvertTo-Json))
			}

	}

```

---

<div class="post-metadata">

**Author:** ![mcheek](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/mcheek/32/23705_2.png) [@mcheek](https://developer.sailpoint.com/discuss/u/mcheek)\
**Post date:** [November 15, 2023, 2:00pm UTC](https://developer.sailpoint.com/discuss/t/how-to-read-all-entitlements-through-rest-api-call-from-powershell-script-with-pagination/20931/3 "2023-11-15T14:00:55Z")

</div>

I [posted a solution](https://developer.sailpoint.com/discuss/t/how-to-get-all-entitlements-for-all-the-idn-sources/20878/3) in the other topic you created yesterday on this exact same question.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [January 14, 2024, 2:01pm UTC](https://developer.sailpoint.com/discuss/t/how-to-read-all-entitlements-through-rest-api-call-from-powershell-script-with-pagination/20931/4 "2024-01-14T14:01:30Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
