Merges permissions from a list of role IDs. Authenticated users can call this endpoint (no extra permission annotation).
Request
POST /permissions/preview
Headers
| Header | Value |
|---|---|
Authorization | Bearer <token> (or HMAC headers, see Authentication) |
Content-Type | application/json |
Request Body
A JSON array of Auth0 role IDs.
["rol_abc123", "rol_def456"]Response
Deduplicated permission strings. Count is in X-Total-Count.
[
"usermanagement.read",
"pageeditor.read",
"search.read"
]
