List API permissions
Returns API permissions with their endpoint expanded, in the standard paginated envelope. Unrecognised query parameters are SILENTLY DROPPED. query.ParseQueryParameters switches on the parameter name and its default branch returns nil, so a typo such as ?lmit=50 or a parameter this endpoint does not support produces neither an error nor a warning — the request runs with the default paging and the caller sees a plausible but unfiltered page.
Authorization
bearerAuth In: header
Query Parameters
Maximum number of records to return. A value strconv.Atoi cannot parse is REJECTED with 400 common.invalid_input (parseLimitOffset), not defaulted — ?limit=abc is an error. An absent limit falls back to 10 (constants.DefaultLimit); a value above the documented maximum is silently clamped to 100 (constants.MaxLimit) rather than rejected, and a value of 0 or below falls back to 10. -1 is the one exception: it skips the data fetch entirely and returns only the counts, which is why no minimum is declared.
Number of records to skip. A value strconv.Atoi cannot parse is REJECTED with 400 common.invalid_input, not defaulted. A negative value is not rejected either — parseLimitOffset silently coerces it to 0, so the declared minimum describes the effective range, not a server-side check.
Sort expression, e.g. created_at:desc
JSON-encoded filter criteria. A value that is not valid JSON is rejected with 400.
Free-text search. query.ParseQueryParameters accepts it under two names, search and search_text, and additionally recognises the per-field family search. — e.g. search.endpoint. Those per-field keys cannot be enumerated here because the set is open.
Group results by this field; data then comes back as an object keyed by the field value instead of an array.
Return distinct values of this field
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/v1/rbac/api-permissions"{
"total": 0,
"total_unfiltered": 0,
"metadata": {},
"keys": [
"string"
],
"has_more": true,
"data": [
{
"type": "user",
"actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
"api_endpoint": {
"endpoint": "/v1/accounts/%",
"method": "GET",
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"created_at": "2019-08-24T14:15:22Z",
"created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
"modified_at": "2019-08-24T14:15:22Z",
"modified_by": "e8d4374d-93a1-4e98-a6c6-fdcf00c5059f",
"active": true,
"metadata": {}
},
"api_endpoint_id": "fb253d37-e680-42f3-827b-b3200c221269",
"rate_limit_per_minute": 0,
"rate_limit_per_hour": 0,
"rate_limit_per_day": 0,
"rate_limit_per_week": 0,
"rate_limit_per_month": 0,
"rate_limit_per_year": 0,
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"created_at": "2019-08-24T14:15:22Z",
"created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
"modified_at": "2019-08-24T14:15:22Z",
"modified_by": "e8d4374d-93a1-4e98-a6c6-fdcf00c5059f",
"active": true,
"metadata": {}
}
]
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 429,
"message": "Global rate limit exceeded",
"code": "Global rate limit exceeded",
"class": "temporary",
"retryable": true
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2026-08-27T15:04:05Z"
}