Skip to content
GET
/v1/organizations/{organizationId}/projects/{projectId}/environments/{environmentId}/service-principals/{principalId}/grants

List Grants for an Environment-scoped ServicePrincipal

Return bounded Grant metadata, including expired and revoked history.

Authentication

Send an API key as a Bearer token in the Authorization header.

Parameters

NameLocationRequiredDescription
organizationIdpathYes
The Organization to address.
stringA Cantora Organization identifier, prefixed with `org_`.
  • maximum length 64
  • pattern ^org_[\s\S]+$
projectIdpathYes
The Project to address.
stringA Cantora Project identifier, prefixed with `proj_`.
  • maximum length 64
  • pattern ^proj_[\s\S]+$
environmentIdpathYes
The Environment to address.
stringA Cantora Environment identifier, prefixed with `env_`.
  • maximum length 64
  • pattern ^env_[\s\S]+$
principalIdpathYes
The Principal to address.
stringA Cantora Principal identifier, prefixed with `principal_`.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
cursorqueryNo
The opaque continuation token returned by the preceding page.
string
  • maximum length 2048
  • minimum length 1
  • pattern ^[A-Za-z0-9_-]+$
limitqueryNo
The maximum number of resources to return, from 1 through 100.
string
  • pattern ^[+-]?\d*\.?\d+(?:[Ee][+-]?\d+)?$

Responses

200GrantPage
application/json
400The request path, headers, query, or JSON body did not satisfy the published schema
401Unauthorized
application/json
403Forbidden
application/json
404NotFound
application/json

Reusable schemas

GrantPageEncoded

object
  • unknown properties allowed false
itemsrequired
arrayThe resources in this page, in stable order.
nextCursorrequired
The opaque continuation token for the next page, or null after the final page.
Any of
string
  • maximum length 2048
  • minimum length 1
  • pattern ^[A-Za-z0-9_-]+$
null

UnauthorizedEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Unauthorized"
reasonrequired
stringA safe explanation of why the credential was rejected.

ForbiddenEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Forbidden"
permissionrequired
stringThe permission required by the refused operation.

NotFoundEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "NotFound"
resourcerequired
stringThe resource type relevant to the error.
idrequired
stringThe identifier supplied for the resource that was not found.

GrantMetadataEncoded

object
  • unknown properties allowed false
grantIdrequired
stringThe Grant identifier.
  • maximum length 64
  • pattern ^grant_[\s\S]+$
principalIdrequired
stringThe Principal identifier.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
rolerequired
MachineGrantRoleThe Organization role granted to the provisioned identity.
scoperequired
PrincipalScopeThe immutable structural scope of this machine identity.
grantedByPrincipalIdrequired
stringThe Principal that created this Grant.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
createdAtrequired
stringWhen the resource was created, in UTC.
  • format date-time
expiresAtrequired
When the resource expires, in UTC, or null when it does not expire.
  • format date-time
Any of
string
null
revokedAtrequired
When the resource was revoked, in UTC, or null while it remains active.
  • format date-time
Any of
string
null

MachineGrantRole

string
  • allowed values "admin", "developer", "viewer", "configurationDeployer"

PrincipalScope

OrganizationScope

object
  • unknown properties allowed false
levelrequired
stringThe tenancy level of this structural scope.
  • allowed values "organization"
organizationIdrequired
stringThe Organization identifier.
  • maximum length 64
  • pattern ^org_[\s\S]+$

ProjectScope

object
  • unknown properties allowed false
levelrequired
stringThe tenancy level of this structural scope.
  • allowed values "project"
organizationIdrequired
stringThe Organization identifier.
  • maximum length 64
  • pattern ^org_[\s\S]+$
projectIdrequired
stringThe Project identifier.
  • maximum length 64
  • pattern ^proj_[\s\S]+$

EnvironmentScope

object
  • unknown properties allowed false
levelrequired
stringThe tenancy level of this structural scope.
  • allowed values "environment"
organizationIdrequired
stringThe Organization identifier.
  • maximum length 64
  • pattern ^org_[\s\S]+$
projectIdrequired
stringThe Project identifier.
  • maximum length 64
  • pattern ^proj_[\s\S]+$
environmentIdrequired
stringThe Environment identifier.
  • maximum length 64
  • pattern ^env_[\s\S]+$

TenantScope

object
  • unknown properties allowed false
levelrequired
stringThe tenancy level of this structural scope.
  • allowed values "tenant"
organizationIdrequired
stringThe Organization identifier.
  • maximum length 64
  • pattern ^org_[\s\S]+$
projectIdrequired
stringThe Project identifier.
  • maximum length 64
  • pattern ^proj_[\s\S]+$
environmentIdrequired
stringThe Environment identifier.
  • maximum length 64
  • pattern ^env_[\s\S]+$
tenantIdrequired
stringThe Tenant identifier.
  • maximum length 64
  • pattern ^tenant_[\s\S]+$