Returns permission identifiers. Requires usermanagement.read, secret.read, or permissions:read.
Feature permissions (dot notation) are filtered to modules booked on the instance unless showAll is true. API permissions (colon notation) are not filtered by feature flags.
Request
GET /permissions
Headers
| Header | Value |
|---|---|
Authorization | Bearer <token> (or HMAC headers, see Authentication) |
Query Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
showAll | boolean | No | When true, skip feature-flag filtering. The string false is treated as false. Default false. |
type | string | No | all (default), api (colon permissions), feature or features (dot permissions). |
Example Request
GET /permissions?type=feature
Response
JSON array of permission strings. Count is in X-Total-Count.
[
"usermanagement.read",
"usermanagement.write",
"pageeditor.read"
]Error Responses
| Status | Description |
|---|---|
400 | Unknown type value. |
403 | Missing permission. |

