List all assignments across the Application
/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/assignments/app-wideReturns a paginated list of every direct role assignment across the active Application, scoped to the current Environment. Each row joins the assigned identity, the role, and the source hierarchy node, and carries a computed status of active, scheduled, or expired derived from the assignment's effective_from/effective_to window. Requires the rbac.view_assignments permission; supports q search plus filtering by role_id, status, and source_node_id, and sorting by name, role, or created_at.
Authentication
AuthorizationJWT access token. Never send alongside X-API-Key: a request carrying both is refused.
env_identities.viewDeveloper ConsoleView identities, invitations, and role assignments in an Environment. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.
production_identities.accessDeveloper ConsoleAccess identities in production Environments. Applies to users only, and only in an Environment marked production: its identities are real end users. API keys and identity principals are exempt.
Query Parameters
pagenumber Optional Page number (1-based)
takenumber Optional Items per page (1-100, default 20)
qstring Optional Search term
sort_byenum Optional Sort field
orderenum Optional Sort order
role_idstring Optional Filter by role ID
statusenum Optional Filter by assignment status
source_node_idstring Optional Filter by source node ID
Responses
application/json
items *IdentityAssignmentRowDto[]pagination *PageMetaDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
Errors
When the request can't be completed, the response body includes a stable error code you can branch on.
account.capability_requiredForbiddenThe signed-in user's administrator roles do not grant the capability this endpoint requires.
Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.
environment.production_identities_forbiddenForbiddenThe Environment is marked production and the caller is a user without production identity access.
Manage these people in the Admin Workspace, or ask an administrator to grant the Production Support role, then retry.
Pagination
This endpoint returns a paginated collection. Use the query parameters below to page through results.
pagenumberPage number (1-indexed). Defaults to 1.
takenumberItems per page (1–100). Defaults to 20.
Each response includes an items array alongside a pagination object with item_count, page_count, has_previous_page, and has_next_page fields.
Returned object
curl -X GET "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/assignments/app-wide?page=0&take=0&q=value&sort_by=name&order=asc&role_id=value&status=active&source_node_id=value" \ -H "Authorization: Bearer $CANOPY_TOKEN"
{ "items": [ { "identity": { "id": "string", "first_name": "string", "last_name": "string", "name": "string", "email": "string", "avatar_url": "string" }, "role": { "id": "string", "name": "string" }, "assignment": { "id": "string", "source_node_id": "string", "source_node_name": "string", "access_type": "direct", "effective_from": "2026-04-20T12:00:00.000Z", "effective_to": "2026-04-20T12:00:00.000Z", "status": "active", "created_at": "2026-04-20T12:00:00.000Z" } } ], "pagination": { "page": 0, "take": 0, "item_count": 0, "page_count": 0, "has_previous_page": false, "has_next_page": false } }
Tell us how we can improve this guide.