Permissions
api/admin/rbac_roles/permissions
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/admin/rbac_roles/permissions Changed · +42 / -45 lines
### Path parameters ### Query parameters ### Headers #### Response (200) ## Domain types ### Path Parameters ### Query Parameters ### Header Parameters #### Response ## Domain Types
---- -title: Permissions -url: https://platform.claude.com/docs/en/api/admin/rbac_roles/permissions ---- - # Permissions ## List RBAC Role Permissions -**get** `/v1/organizations/rbac_roles/{role_id}/permissions` +**GET** `/v1/organizations/rbac_roles/{role_id}/permissions` List the permissions an RBAC Role grants. The RBAC Roles API is in beta and available to Claude Enterprise organizations only. Requests must send the `ce-user-management-2026-07-13` value in the `anthropic-beta` header. -### Path Parameters +### Path parameters - `role_id: string` ID of the RBAC Role. -### Query Parameters +### Query parameters - `limit: optional number`
Defaults to `20`. Ranges from `1` to `1000`. + default: 20, maximum: 1000, minimum: 1 + - `page: optional string` Optionally set to the `next_page` token from the previous response. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
`all_connectors` grants carry a tool-access action, the scope action, or an authentication-method action (`interactive` or `managed`). - - `resource: object { organization_id, type } or object { connector_id, tool_name, type } or object { connector_id, scope, type } or 2 more` + - `resource: object or object or object or 2 more` What the permission applies to.
A tagged union: `type` names the kind of resource and determines which identifier fields are present. - - `Organization object { organization_id, type }` + - `Organization object` - `organization_id: string`
Kind of resource the permission applies to. - - `"organization"` + default: organization - - `ConnectorTool object { connector_id, tool_name, type }` + - `ConnectorTool object` - `connector_id: string`
Kind of resource the permission applies to. - - `"connector_tool"` + default: connector_tool - - `ConnectorScope object { connector_id, scope, type }` + - `ConnectorScope object` - `connector_id: string`
Kind of resource the permission applies to. - - `"connector_scope"` + default: connector_scope - - `Connector object { connector_id, type }` + - `Connector object` - `connector_id: string`
Kind of resource the permission applies to. - - `"connector"` + default: connector - - `AllConnectors object { type }` + - `AllConnectors object` - `type: "all_connectors"` Kind of resource the permission applies to. - - `"all_connectors"` + default: all_connectors - `type: "rbac_role_permission"`
For RBAC Role Permissions, this is always `"rbac_role_permission"`. - - `"rbac_role_permission"` + default: rbac_role_permission - `has_more: boolean`
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/rbac_roles/$ROLE_ID/permissions \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
} ``` -## Domain Types +## Domain types ### Rbac Role Permission -- `RbacRolePermission object { action, resource, type }` +- `RbacRolePermission object` - `action: string`
`all_connectors` grants carry a tool-access action, the scope action, or an authentication-method action (`interactive` or `managed`). - - `resource: object { organization_id, type } or object { connector_id, tool_name, type } or object { connector_id, scope, type } or 2 more` + - `resource: object or object or object or 2 more` What the permission applies to.
A tagged union: `type` names the kind of resource and determines which identifier fields are present. - - `Organization object { organization_id, type }` + - `Organization object` - `organization_id: string`
Kind of resource the permission applies to. - - `"organization"` + default: organization - - `ConnectorTool object { connector_id, tool_name, type }` + - `ConnectorTool object` - `connector_id: string`
Kind of resource the permission applies to. - - `"connector_tool"` + default: connector_tool - - `ConnectorScope object { connector_id, scope, type }` + - `ConnectorScope object` - `connector_id: string`
Kind of resource the permission applies to. - - `"connector_scope"` + default: connector_scope - - `Connector object { connector_id, type }` + - `Connector object` - `connector_id: string`
Kind of resource the permission applies to. - - `"connector"` + default: connector - - `AllConnectors object { type }` + - `AllConnectors object` - `type: "all_connectors"` Kind of resource the permission applies to. - - `"all_connectors"` + default: all_connectors - `type: "rbac_role_permission"`
For RBAC Role Permissions, this is always `"rbac_role_permission"`. - - `"rbac_role_permission"` + default: rbac_role_permission