Get a user's permissions
GET
/users/{id}/permissions
Role assignments and effective permissions for the user named in the path. Requires a bearer session. Callers may read their own; reading another user's requires the view_all_users permission, and any other caller gets 403. Answers can be several minutes old; for the caller's own, current permissions use GET /me/capabilities.
Authorizations
BearerAuth
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Type
HTTP (bearer)
Parameters
Path Parameters
id*
Type
Requiredstring
Format
"uuid"Responses
User permissions — a bare object.
application/json
JSON
{
"roles": [
{
"role_name": "string",
"context_type": "string",
"context_id": "string",
"hierarchy_level": 0
}
],
"permissions": [
"string"
],
"roleDefinitions": [
{
"name": "string",
"hierarchy_level": 0,
"context_type": "string"
}
]
}