GET /v1/organizations/rbac_roles/{rbac_role_id}/permissions
List the permissions an RBAC Role grants.
The RBAC Roles API is available to Haijun Enterprise organizations only.
Path parameters
rbac_role_id: string
ID of the RBAC Role.
Query parameters
limit: optional number
Number of items to return per page.
Defaults to 20. Ranges from 1 to 1000.
default: 20, minimum: 1, maximum: 1000
page: optional string
Optionally set to the next_page token from the previous response.
Returns
data: array of BetaRBACRolePermission
type: "rbac_role_permission"
Object type.
For RBAC Role Permissions, this is always "rbac_role_permission".
default: rbac_role_permission
action: string
Action the permission grants on the resource.
The vocabulary follows the resource: an organization grant carries a product-feature entitlement (for example chat), an admin-panel permission entitlement (permission_*), or a blanket capability-access mode — capability_access_all grants every product-feature entitlement, and capability_access_all_ga grants the generally-available subset as it stands at permission-check time; neither mode grants model-access entitlements. A consumer enumerating a role's per-feature grants should treat a blanket row as granting every product-feature entitlement it covers, or it will under-report the role's effective access. A connector_tool grant carries a tool-access action (use or always_allow); a connector_scope grant carries the scope action grant (the role may receive the named OAuth scope when tokens are minted for the connector); connector and all_connectors grants carry a tool-access action, the scope action, or an authentication-method action (interactive or managed).
resource: Organization or ConnectorTool or ConnectorScope or 2 more
What the permission applies to.
A tagged union: type names the kind of resource and determines which identifier fields are present.
Organization object
type: "organization"
Kind of resource the permission applies to.
default: organization
organization_id: string
UUID of the organization the permission applies to.
ConnectorTool object
type: "connector_tool"
Kind of resource the permission applies to.
default: connector_tool
connector_id: string
ID of the connector the permission applies to.
tool_name: string
Published name of the connector tool the permission applies to.
When the published name contains characters outside [a-zA-Z0-9_-] (or collides with a reserved form), it is server-encoded into a stable {prefix}_{32-hex} form — a shortened readable prefix of the name plus a hash — from which the published name is not recoverable.
ConnectorScope object
type: "connector_scope"
Kind of resource the permission applies to.
default: connector_scope
connector_id: string
ID of the connector the permission applies to.
scope: string
OAuth scope the permission names — the role may receive this scope when tokens are minted for the connector.
Subject to the same encoding rule as tool_name: a scope containing characters outside [a-zA-Z0-9_-] (or colliding with a reserved form) appears server-encoded in a stable {prefix}_{32-hex} form. OAuth scopes routinely contain : and /, so most appear encoded.
Connector object
type: "connector"
Kind of resource the permission applies to.
default: connector
connector_id: string
ID of the connector the permission applies to.
AllConnectors object
type: "all_connectors"
Kind of resource the permission applies to.
default: all_connectors
has_more: boolean
Indicates whether there are more results beyond this page.
next_page: string or null
Opaque cursor for the next page. Pass as the page parameter on the next request.
Example
curl https://haijun.my.id/v1/organizations/rbac_roles/$RBAC_ROLE_ID/permissions \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"data": [
{
"action": "use",
"resource": {
"organization_id": "3c4f5e6d-7a8b-49c0-9d1e-2f3a4b5c6d7e",
"type": "organization"
},
"type": "rbac_role_permission"
}
],
"has_more": true,
"next_page": "eyJjdXJzb3IiOiAicmJhY19yb2xlXzAxIn0"
}