Get identity's effective permissions
/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/identities/{id}/permissionsReturns the identity's effective Application-wide permission keys for the current Environment as a flat items array of strings, resolved across all of its role assignments. Use this to answer "what can this identity do" without replaying individual assignments. Returns 404 when the identity has no membership in this Environment.
Authentication
AuthorizationJWT access token. Never send alongside X-API-Key: a request carrying both is refused.
env_identities.viewDeveloper ConsoleView identities, invitations, and role assignments in an Environment. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.
production_identities.accessDeveloper ConsoleAccess identities in production Environments. Applies to users only, and only in an Environment marked production: its identities are real end users. API keys and identity principals are exempt.
Path Parameters
idstring Required Responses
application/json
items *string[]
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
Errors
When the request can't be completed, the response body includes a stable error code you can branch on.
account.capability_requiredForbiddenThe signed-in user's administrator roles do not grant the capability this endpoint requires.
Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.
environment.production_identities_forbiddenForbiddenThe Environment is marked production and the caller is a user without production identity access.
Manage these people in the Admin Workspace, or ask an administrator to grant the Production Support role, then retry.
curl -X GET "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/identities/value/permissions" \ -H "Authorization: Bearer $CANOPY_TOKEN"
{ "items": [ "string" ] }
Tell us how we can improve this guide.