curl --request GET \
--url https://conduit.example.com/conduit.v1.ConduitService/GetEffectiveAccess \
--header 'Authorization: Bearer <token>' \
--header 'Connect-Protocol-Version: <connect-protocol-version>'const options = {
method: 'GET',
headers: {
'Connect-Protocol-Version': '<connect-protocol-version>',
Authorization: 'Bearer <token>'
}
};
fetch('https://conduit.example.com/conduit.v1.ConduitService/GetEffectiveAccess', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://conduit.example.com/conduit.v1.ConduitService/GetEffectiveAccess"
headers = {
"Connect-Protocol-Version": "<connect-protocol-version>",
"Authorization": "Bearer <token>"
}
response = requests.get(url, headers=headers)
print(response.text)HttpResponse<String> response = Unirest.get("https://conduit.example.com/conduit.v1.ConduitService/GetEffectiveAccess")
.header("Connect-Protocol-Version", "<connect-protocol-version>")
.header("Authorization", "Bearer <token>")
.asString();package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://conduit.example.com/conduit.v1.ConduitService/GetEffectiveAccess"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Connect-Protocol-Version", "<connect-protocol-version>")
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"groupIds": [
"<string>"
],
"policyIds": [
"<string>"
],
"entries": [
{
"connectorId": "<string>",
"allTools": true,
"tools": [
"<string>"
]
}
],
"allowedEntries": [
{
"connectorId": "<string>",
"allTools": true,
"tools": [
"<string>"
]
}
],
"enabledEntries": [
{
"connectorId": "<string>",
"allTools": true,
"tools": [
"<string>"
]
}
],
"effectiveEntries": [
{
"connectorId": "<string>",
"allTools": true,
"tools": [
"<string>"
]
}
],
"enableDefaulted": true
}{
"code": "not_found",
"message": "<string>",
"details": [
{
"type": "<string>",
"value": "<string>",
"debug": {}
}
]
}Get effective access
Inspect a member’s resolved groups, contributing policies, and effective connector/tool access
Requires the policies:read scope.
curl --request GET \
--url https://conduit.example.com/conduit.v1.ConduitService/GetEffectiveAccess \
--header 'Authorization: Bearer <token>' \
--header 'Connect-Protocol-Version: <connect-protocol-version>'const options = {
method: 'GET',
headers: {
'Connect-Protocol-Version': '<connect-protocol-version>',
Authorization: 'Bearer <token>'
}
};
fetch('https://conduit.example.com/conduit.v1.ConduitService/GetEffectiveAccess', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://conduit.example.com/conduit.v1.ConduitService/GetEffectiveAccess"
headers = {
"Connect-Protocol-Version": "<connect-protocol-version>",
"Authorization": "Bearer <token>"
}
response = requests.get(url, headers=headers)
print(response.text)HttpResponse<String> response = Unirest.get("https://conduit.example.com/conduit.v1.ConduitService/GetEffectiveAccess")
.header("Connect-Protocol-Version", "<connect-protocol-version>")
.header("Authorization", "Bearer <token>")
.asString();package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://conduit.example.com/conduit.v1.ConduitService/GetEffectiveAccess"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Connect-Protocol-Version", "<connect-protocol-version>")
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"groupIds": [
"<string>"
],
"policyIds": [
"<string>"
],
"entries": [
{
"connectorId": "<string>",
"allTools": true,
"tools": [
"<string>"
]
}
],
"allowedEntries": [
{
"connectorId": "<string>",
"allTools": true,
"tools": [
"<string>"
]
}
],
"enabledEntries": [
{
"connectorId": "<string>",
"allTools": true,
"tools": [
"<string>"
]
}
],
"effectiveEntries": [
{
"connectorId": "<string>",
"allTools": true,
"tools": [
"<string>"
]
}
],
"enableDefaulted": true
}{
"code": "not_found",
"message": "<string>",
"details": [
{
"type": "<string>",
"value": "<string>",
"debug": {}
}
]
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
Define the version of the Connect protocol
1 Define the timeout, in ms
Query Parameters
Define which encoding or 'Message-Codec' to use
proto, json Specifies if the message query param is base64 encoded, which may be required for binary data
Which compression algorithm to use for this request
identity, gzip, br Define the version of the Connect protocol
v1 Response
Success
transitively resolved groups
contributing allow policies
Deprecated compatibility alias of allowed_entries. New clients should use the three named views below.
Show child attributes
Show child attributes
union of applicable allow policies
Show child attributes
Show child attributes
the member's enable policy (or synthesized default)
Show child attributes
Show child attributes
allowed_entries intersect enabled_entries
Show child attributes
Show child attributes
true when no stored enable policy exists
Was this page helpful?