List record types
Returns every record type a record permission can be granted on. The response is a bare array, not the paginated envelope.
Authorization
bearerAuth In: header
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/v1/rbac/record-types"[
{
"Schema": "string",
"name": "rbac",
"description": "string",
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"created_at": "2019-08-24T14:15:22Z",
"created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
"modified_at": "2019-08-24T14:15:22Z",
"modified_by": "e8d4374d-93a1-4e98-a6c6-fdcf00c5059f",
"active": true,
"metadata": {}
}
]{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 429,
"message": "Global rate limit exceeded",
"code": "Global rate limit exceeded",
"class": "temporary",
"retryable": true
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2026-08-27T15:04:05Z"
}Returns record permissions in the standard paginated envelope. Unrecognised query parameters are SILENTLY DROPPED. query.ParseQueryParameters switches on the parameter name and its default branch returns nil, so a typo such as ?lmit=50 or a parameter this endpoint does not support produces neither an error nor a warning — the request runs with the default paging and the caller sees a plausible but unfiltered page.
Replaces the permission mask and the active flag of an existing record permission. Only these two fields are read from the body; the actor, record type and record id cannot be changed. Both are a full replacement: an omitted field is written as its zero value, so send both — see RecordPermissionUpdateInput.