Skip to content

Get a user's permissions​

GET
/users/{id}/permissions

Role assignments and effective permissions for the user named in the path. Requires a bearer session. Callers may read their own; reading another user's requires the view_all_users permission, and any other caller gets 403. Answers can be several minutes old; for the caller's own, current permissions use GET /me/capabilities.

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Parameters​

Path Parameters

id*
Type
string
Required
Format
"uuid"

Responses​

User permissions — a bare object.

application/json
JSON
{
"roles": [
{
"role_name": "string",
"context_type": "string",
"context_id": "string",
"hierarchy_level": 0
}
],
"permissions": [
"string"
],
"roleDefinitions": [
{
"name": "string",
"hierarchy_level": 0,
"context_type": "string"
}
]
}

Playground​

Server
Authorization
Variables
Key
Value

Samples​

Powered by VitePress OpenAPI

Built with VitePress