Get identity summary for a node
/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/nodes/{id}/identities/summaryReturns aggregate identity-assignment counts for a node, gated by hierarchy.view. Computed across the node's lineage so both direct and inherited assignments are reflected: direct_count, inherited_count, status breakdown (active_count, scheduled_count, expired_count, expiring_soon_count), distinct_role_count, a sample of the five most recent identities, and can_manage_assignments (whether the caller also holds hierarchy.manage here). Returns 404 when the node is not found in this Environment.
Authentication
AuthorizationJWT access token. Never send alongside X-API-Key: a request carrying both is refused.
env_identities.viewDeveloper ConsoleView identities, invitations, and role assignments in an Environment. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.
production_identities.accessDeveloper ConsoleAccess identities in production Environments. Applies to users only, and only in an Environment marked production: its identities are real end users. API keys and identity principals are exempt.
Path Parameters
idstring Required Responses
application/json
data *NodeIdentitiesSummaryDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
Errors
When the request can't be completed, the response body includes a stable error code you can branch on.
account.capability_requiredForbiddenThe signed-in user's administrator roles do not grant the capability this endpoint requires.
Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.
environment.production_identities_forbiddenForbiddenThe Environment is marked production and the caller is a user without production identity access.
Manage these people in the Admin Workspace, or ask an administrator to grant the Production Support role, then retry.
Returned object
curl -X GET "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/nodes/value/identities/summary" \ -H "Authorization: Bearer $CANOPY_TOKEN"
{ "data": { "direct_count": 0, "inherited_count": 0, "can_manage_assignments": false, "active_count": 0, "scheduled_count": 0, "expired_count": 0, "expiring_soon_count": 0, "distinct_role_count": 0, "recent_identities": [ { "id": "string", "first_name": "string", "last_name": "string", "name": "string", "avatar_url": "string" } ] } }
Tell us how we can improve this guide.