Skip to main content

GetEffectivePermissions returns every permission slug a user holds, through their roles and through direct grants.

GET 

/api/v1/auth/permissions/effective

Not on the authorization path. Enforcement checks the projected capability model in SpiceDB, which needs no database round trip; this reads the database because the answer it gives is a list to render, not a decision to make.

Serves the frontend: "what can I do", used to decide which menus and controls to render. Defaults to the caller, so a browser does not have to name itself — and naming itself would be the only thing stopping it naming somebody else.

Parameters​

  • user_id: Optional. Defaults to the caller. Reading another user requires users:read, because knowing exactly what a colleague can do is reconnaissance rather than menu rendering.

Response​

Deduplicated slugs. May contain group slugs (e.g. "engagements:agent"); callers expand them.

Errors​

  • PERMISSION_DENIED: Reading another user without users:read
  • NOT_FOUND: the user does not exist, or belongs to another organization

Request​

Responses​

A successful response.