Retrieve the permission catalog
/credentials/permission-catalogReturns every permission supported by the API, with its code, resource type, description, whether it can be delegated to other credentials, and the API version in which it was introduced.
Available to any authenticated credential. Reading the catalog does not grant any permission.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Header Parameters
Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.
length <= 64Response Body
application/json
application/json
application/json
curl -X GET "https://example.com/credentials/permission-catalog"{ "data": { "catalog_version": "string", "object": "permission_catalog", "permissions": [ { "code": "string", "delegable": true, "description": "string", "introduced_in": "string", "resource_type": "string" } ], "selector_types": [ "instance" ] }}Retrieve the current credential's policies GET
Returns the active policy revision of the credential used to authenticate the request. Use this operation to inspect what the calling credential is allowed to do; it cannot be used to read other credentials.
List policy templates GET
Returns the predefined policy templates that can be used when creating a credential, each with the list of permissions it grants. No template includes `administrators.*` or `credentials.*` permissions. Available to any authenticated credential. Reading the templates does not grant any permission.