List identities at a node
/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/nodes/{id}/identitiesReturns a paginated list of identity role assignments effective at a node, gated by hierarchy.view on that node. The result spans the node's full lineage so inherited assignments (granted at ancestor nodes) appear alongside direct ones, with each row flagged accordingly. Supports filtering by q, role_id, access_type, status, and source_node_id, plus sorting and paging. Returns 404 when the node is not found in this Environment.
Authentication
AuthorizationJWT access token. Never send alongside X-API-Key: a request carrying both is refused.
env_identities.viewDeveloper ConsoleView identities, invitations, and role assignments in an Environment. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.
production_identities.accessDeveloper ConsoleAccess identities in production Environments. Applies to users only, and only in an Environment marked production: its identities are real end users. API keys and identity principals are exempt.
Path Parameters
idstring Required Query Parameters
pagenumber Optional Page number (1-based)
takenumber Optional Items per page (1-100, default 20)
qstring Optional Search term
sort_byenum Optional Sort field
orderenum Optional Sort order
role_idstring Optional Filter by role ID
access_typeenum Optional Filter by access type
statusenum Optional Filter by assignment status
source_node_idstring Optional Filter by source node ID
Responses
application/json
items *IdentityAssignmentRowDto[]pagination *PageMetaDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
Errors
When the request can't be completed, the response body includes a stable error code you can branch on.
account.capability_requiredForbiddenThe signed-in user's administrator roles do not grant the capability this endpoint requires.
Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.
environment.production_identities_forbiddenForbiddenThe Environment is marked production and the caller is a user without production identity access.
Manage these people in the Admin Workspace, or ask an administrator to grant the Production Support role, then retry.
Pagination
This endpoint returns a paginated collection. Use the query parameters below to page through results.
pagenumberPage number (1-indexed). Defaults to 1.
takenumberItems per page (1–100). Defaults to 20.
Each response includes an items array alongside a pagination object with item_count, page_count, has_previous_page, and has_next_page fields.
Returned object
curl -X GET "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/nodes/value/identities?page=0&take=0&q=value&sort_by=name&order=asc&role_id=value&access_type=direct&status=active&source_node_id=value" \ -H "Authorization: Bearer $CANOPY_TOKEN"
{ "items": [ { "identity": { "id": "string", "first_name": "string", "last_name": "string", "name": "string", "email": "string", "avatar_url": "string" }, "role": { "id": "string", "name": "string" }, "assignment": { "id": "string", "source_node_id": "string", "source_node_name": "string", "access_type": "direct", "effective_from": "2026-04-20T12:00:00.000Z", "effective_to": "2026-04-20T12:00:00.000Z", "status": "active", "created_at": "2026-04-20T12:00:00.000Z" } } ], "pagination": { "page": 0, "take": 0, "item_count": 0, "page_count": 0, "has_previous_page": false, "has_next_page": false } }
Tell us how we can improve this guide.