> ## Documentation Index
> Fetch the complete documentation index at: https://pipedream.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# List effective access

> List resolved allow, enable, and effective access for workspace members

Requires the `policies:read` scope.



## OpenAPI

````yaml /conduit/openapi/api.yaml get /conduit.v1.ConduitService/ListEffectiveAccess
openapi: 3.1.0
info:
  title: Conduit API
  version: v1
  description: |
    Machine-to-machine API for Conduit workspaces. Authenticate a
    workspace API client with OAuth 2.0 client credentials at
    `/oauth/token`, then call these methods with the resulting bearer token.
    Read-only methods are documented as `GET`, with their JSON request encoded
    in the `message` query parameter. Mutating methods use `POST` with a JSON
    body. The server also accepts `POST` for reads. See the API guide for
    auth, scopes, and error handling.
servers:
  - url: https://conduit.example.com
    description: Your Conduit instance — replace with your CONDUIT_BASE_URL
security:
  - bearerAuth: []
tags:
  - name: connectors
    x-group: Connectors
    description: Create and manage connectors and the workspace's Pipedream configuration.
  - name: policies-and-groups
    x-group: Policies & groups
    description: Allow policies, groups, group membership, and effective-access debugging.
  - name: members
    x-group: Members
    description: Read the workspace's member roster.
  - name: single-sign-on
    x-group: Single sign-on
    description: Read sanitized workspace identity-provider configuration.
  - name: provisioning
    x-group: Provisioning
    description: Read sanitized SCIM metadata, provisioning rules, and resource mappings.
  - name: workspace-settings
    x-group: Workspace settings
    description: Change general workspace settings.
  - name: audit-log
    x-group: Audit log
    description: Read the workspace audit log.
paths:
  /conduit.v1.ConduitService/ListEffectiveAccess:
    get:
      tags:
        - policies-and-groups
      summary: List effective access
      description: |-
        List resolved allow, enable, and effective access for workspace members

        Requires the `policies:read` scope.
      operationId: ListEffectiveAccess
      parameters:
        - name: Connect-Protocol-Version
          in: header
          required: true
          schema:
            $ref: '#/components/schemas/connect-protocol-version'
        - name: Connect-Timeout-Ms
          in: header
          schema:
            $ref: '#/components/schemas/connect-timeout-header'
        - name: message
          in: query
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/conduit.v1.ListEffectiveAccessRequest'
        - name: encoding
          in: query
          required: true
          schema:
            $ref: '#/components/schemas/encoding'
        - name: base64
          in: query
          schema:
            $ref: '#/components/schemas/base64'
        - name: compression
          in: query
          schema:
            $ref: '#/components/schemas/compression'
        - name: connect
          in: query
          schema:
            $ref: '#/components/schemas/connect'
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/conduit.v1.ListEffectiveAccessResponse'
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
components:
  schemas:
    connect-protocol-version:
      type: number
      title: Connect-Protocol-Version
      enum:
        - 1
      description: Define the version of the Connect protocol
      const: 1
    connect-timeout-header:
      type: number
      title: Connect-Timeout-Ms
      description: Define the timeout, in ms
    conduit.v1.ListEffectiveAccessRequest:
      type: object
      properties:
        userIds:
          type: array
          items:
            type: string
          title: user_ids
          description: >-
            When non-empty, resolve exactly these current workspace members
            (maximum
             100; duplicates are ignored). When empty, page across all human members.
        limit:
          type: integer
          title: limit
          format: int32
          description: all-members mode only; clamped to 100, defaults to 50
        offset:
          type: integer
          title: offset
          format: int32
          description: all-members mode only
        organizationId:
          type: string
          title: organization_id
      title: ListEffectiveAccessRequest
      additionalProperties: false
    encoding:
      title: encoding
      enum:
        - proto
        - json
      description: Define which encoding or 'Message-Codec' to use
    base64:
      type: boolean
      title: base64
      description: >-
        Specifies if the message query param is base64 encoded, which may be
        required for binary data
    compression:
      title: compression
      enum:
        - identity
        - gzip
        - br
      description: Which compression algorithm to use for this request
    connect:
      title: connect
      enum:
        - v1
      description: Define the version of the Connect protocol
    conduit.v1.ListEffectiveAccessResponse:
      type: object
      properties:
        users:
          type: array
          items:
            $ref: '#/components/schemas/conduit.v1.UserEffectiveAccess'
          title: users
        total:
          type:
            - integer
            - string
          title: total
          format: int64
      title: ListEffectiveAccessResponse
      additionalProperties: false
    connect.error:
      type: object
      properties:
        code:
          type: string
          examples:
            - not_found
          enum:
            - canceled
            - unknown
            - invalid_argument
            - deadline_exceeded
            - not_found
            - already_exists
            - permission_denied
            - resource_exhausted
            - failed_precondition
            - aborted
            - out_of_range
            - unimplemented
            - internal
            - unavailable
            - data_loss
            - unauthenticated
          description: >-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
        message:
          type: string
          description: >-
            A developer-facing error message, which should be in English. Any
            user-facing error message should be localized and sent in the
            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized by the client.
        details:
          type: array
          items:
            $ref: '#/components/schemas/connect.error_details.Any'
          description: >-
            A list of messages that carry the error details. There is no limit
            on the number of messages.
      title: Connect Error
      additionalProperties: true
      description: >-
        Error type returned by Connect:
        https://connectrpc.com/docs/go/errors/#http-representation
    conduit.v1.UserEffectiveAccess:
      type: object
      properties:
        userId:
          type: string
          title: user_id
        access:
          $ref: '#/components/schemas/conduit.v1.GetEffectiveAccessResponse'
          title: access
      title: UserEffectiveAccess
      additionalProperties: false
    connect.error_details.Any:
      type: object
      properties:
        type:
          type: string
          description: >-
            A URL that acts as a globally unique identifier for the type of the
            serialized message. For example:
            `type.googleapis.com/google.rpc.ErrorInfo`. This is used to
            determine the schema of the data in the `value` field and is the
            discriminator for the `debug` field.
        value:
          type: string
          format: binary
          description: >-
            The Protobuf message, serialized as bytes and base64-encoded. The
            specific message type is identified by the `type` field.
        debug:
          oneOf:
            - type: object
              title: Any
              additionalProperties: true
              description: Detailed error information.
          discriminator:
            propertyName: type
          title: Debug
          description: >-
            Deserialized error detail payload. The 'type' field indicates the
            schema. This field is for easier debugging and should not be relied
            upon for application logic.
      additionalProperties: true
      description: >-
        Contains an arbitrary serialized message along with a @type that
        describes the type of the serialized message, with an additional debug
        field for ConnectRPC error details.
    conduit.v1.GetEffectiveAccessResponse:
      type: object
      properties:
        groupIds:
          type: array
          items:
            type: string
          title: group_ids
          description: transitively resolved groups
        policyIds:
          type: array
          items:
            type: string
          title: policy_ids
          description: contributing allow policies
        entries:
          type: array
          items:
            $ref: '#/components/schemas/conduit.v1.PolicyEntry'
          title: entries
          description: >-
            Deprecated compatibility alias of allowed_entries. New clients
            should use
             the three named views below.
          deprecated: true
        allowedEntries:
          type: array
          items:
            $ref: '#/components/schemas/conduit.v1.PolicyEntry'
          title: allowed_entries
          description: union of applicable allow policies
        enabledEntries:
          type: array
          items:
            $ref: '#/components/schemas/conduit.v1.PolicyEntry'
          title: enabled_entries
          description: the member's enable policy (or synthesized default)
        effectiveEntries:
          type: array
          items:
            $ref: '#/components/schemas/conduit.v1.PolicyEntry'
          title: effective_entries
          description: allowed_entries intersect enabled_entries
        enableDefaulted:
          type: boolean
          title: enable_defaulted
          description: true when no stored enable policy exists
      title: GetEffectiveAccessResponse
      additionalProperties: false
    conduit.v1.PolicyEntry:
      type: object
      properties:
        connectorId:
          type: string
          title: connector_id
        allTools:
          type: boolean
          title: all_tools
        tools:
          type: array
          items:
            type: string
          title: tools
      title: PolicyEntry
      additionalProperties: false
      description: >-
        One connector grant: all of the connector's tools, or an explicit
        allowlist.
         connector_id: 'app:<slug>' | 'mcp:<name>' | 'local:<name>' |
         'builtin:<name>', or the wildcards 'app:*' | 'mcp:*' | 'local:*' |
         'builtin:*' | '*'.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: opaque

````