GetEffectivePermissions returns every permission slug a user holds, through their roles and through direct grants.
GET/api/v1/auth/permissions/effective
Not on the authorization path. Enforcement checks the projected capability model in SpiceDB, which needs no database round trip; this reads the database because the answer it gives is a list to render, not a decision to make.
Serves the frontend: "what can I do", used to decide which menus and controls to render. Defaults to the caller, so a browser does not have to name itself — and naming itself would be the only thing stopping it naming somebody else.
Parameters
- user_id: Optional. Defaults to the caller. Reading another user requires users:read, because knowing exactly what a colleague can do is reconnaissance rather than menu rendering.
Response
Deduplicated slugs. May contain group slugs (e.g. "engagements:agent"); callers expand them.
Errors
- PERMISSION_DENIED: Reading another user without users:read
- NOT_FOUND: the user does not exist, or belongs to another organization
Request
Responses
- 200
- default
A successful response.
An unexpected error response.