List permissions

Returns permission identifiers. Requires usermanagement.read, secret.read, or permissions:read.

Feature permissions (dot notation) are filtered to modules booked on the instance unless showAll is true. API permissions (colon notation) are not filtered by feature flags.

Request

GET /permissions

Headers

HeaderValue
AuthorizationBearer <token> (or HMAC headers, see Authentication)

Query Parameters

ParameterTypeRequiredDescription
showAllbooleanNoWhen true, skip feature-flag filtering. The string false is treated as false. Default false.
typestringNoall (default), api (colon permissions), feature or features (dot permissions).

Example Request

GET /permissions?type=feature

Response

JSON array of permission strings. Count is in X-Total-Count.

[
  "usermanagement.read",
  "usermanagement.write",
  "pageeditor.read"
]

Error Responses

StatusDescription
400Unknown type value.
403Missing permission.