Get entity permissions

Use this request to retrieve direct permissions for a goal, project, or project portfolio.

GET

https://api.tracker.yandex.net/v3/entities/{entity_type}/{entity_ID}/permissions

Query format

Before making a request, get permission to access the API.

GET /v3/entities/{entity_type}/{entity_ID}/permissions
Host: api.tracker.yandex.net
Authorization: OAuth API_TOKEN
X-Org-ID or X-Cloud-Org-ID: ORGANIZATION_ID
Headers
  • Host: address of the node that provides the API.

  • Authorization: Authorization token about these formats:

    • OAuth OAUTH_TOKEN: For authorization using the OAuth 2.0 protocol. Learn more

    • Bearer IAM_TOKEN: For authorization using an IAM token, if a Yandex Identity Hub organization is linked to Tracker. Learn more

  • ID types

    X-Org-ID or X-Cloud-Org-ID: Organization ID.

    • Use the X-Org-ID header if a Tracker organization is linked to Yandex 360 for Business.

    • Use the X-Cloud-Org-ID header if a Tracker organization is linked to Yandex Identity Hub.

    Finding the ID

    To get the organization ID, go to Administration → Organizations and copy the value from the ID field.

Resource
Parameter Description Data type
entity_type Entity type:
  • project
  • portfolio
  • goal
String
entity_ID Entity ID. To get the ID, see the entity list. You can use the id or shortId parameter as the ID. String

You can use the id or shortId value for the {entity_ID} parameter.

Response format

If the request is successful, the API returns a response with code 200 OK.

The API returns an object with access permissions. The READ, GRANT, and WRITE properties are at the top level. The response doesn't include acl, permissionSources, or parentEntities.

{
    "READ": {
        "users": [],
        "groups": [],
        "roles": []
    },
    "GRANT": {
        "users": [],
        "groups": [],
        "roles": ["AUTHOR", "OWNER"]
    },
    "WRITE": {
        "users": [],
        "groups": [],
        "roles": ["CLIENT", "AUTHOR", "FOLLOWER", "OWNER", "MEMBER"]
    }
}
Response parameters
Parameter Description Data type
READ Object with the users, groups, and roles that can view the entity Object
GRANT Object with the users, groups, and roles that can manage the entity's access settings Object
WRITE Object with the users, groups, and roles that can edit the entity Object

READ, GRANT, and WRITE object fields

Parameter

Description

Data type

users

List of users with this access type

Object array

groups

List of groups with this access type

Object array

roles

List of entity roles with this access type:

  • AUTHOR: Author;
  • OWNER: Lead;
  • CLIENT: Customer;
  • FOLLOWER: Follower;
  • MEMBER: Participant

String array

Fields of objects in the users array

Parameter Description Data type
self Address of the API resource with information about the user String
id User ID. String
display Displayed user name String
passportUid Unique ID of the user account in the Yandex 360 for Business organization and Yandex ID. Number
cloudUid Unique user ID in Yandex Identity Hub String

Fields of objects in the groups array

Parameter Description Data type
self The address of the API resource that contains information about the user group String
id Group ID String
display Group display name String

If the request is processed incorrectly, the API returns a response with an error code:

401
The user is not authorized. Make sure that actions described in the API access section are performed.
403
You are not authorized to perform this action. You can check what rights you have in the Tracker interface. The same rights are required to perform an action via the API and interface.
404
The requested object was not found. You may have specified an invalid object ID or key.

To retrieve extended access settings, including inherited permissions, use the Get extended entity access settings request.