/api/v1/permissions The permission catalogue
Operation permissions_list
· bearer token
Every fine-grained permission key the portal honours, <feature>-<level>-<scope>. grantable says whether it may be granted to a person; mintable whether an API token may carry it (v1 tokens carry -global keys only, never admin, founder, ssh-console or a key of the api-tokens feature). The roles catalogue also holds role names that are not permission keys (user, admin, …); those can be granted too.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
feature | query | string | null | Only this feature's keys. |
limit | query | integer | Page size. min 1 · max 200 · default 50 |
cursor | query | string | null |
|
Responses
- 200
- 401
Not authenticated: no
Authorization: Bearerheader (not_authenticated), or the credential is refused (token_invalid,token_expired,token_revoked,principal_disabled,token_ip_not_allowed).Headers:WWW-Authenticate,X-Request-ID - 403
The caller lacks a permission the operation needs (
forbidden;requiredlists the keys, any one of which would do), or the licence refuses a change (licence_locked,licence_restricted,licence_required, withstateandremedy; never retry alicence_*code).Headers:X-Request-ID - 429
More than 600 requests in a minute with this token (
rate_limited), or the first request with thisIdempotency-Keyis still running (idempotency_request_in_progress). Retry afterRetry-After.Headers:Retry-After,X-Request-ID - 503
The platform cannot answer right now (
unavailable; retry afterRetry-After), or API tokens are not configured on it (api_tokens_unconfigured; an operator must act).Headers:Retry-After,X-Request-ID - default