Get entity permissions
Use this request to retrieve direct permissions for a goal, project, or project portfolio.
GET
https://api.tracker.yandex.net/v3/entities/{entity_type}/{entity_ID}/permissions
Query format
Before making a request, get permission to access the API.
GET /v3/entities/{entity_type}/{entity_ID}/permissions
Host: api.tracker.yandex.net
Authorization: OAuth API_TOKEN
X-Org-ID or X-Cloud-Org-ID: ORGANIZATION_ID
Headers
-
Host: address of the node that provides the API. -
Authorization: Authorization token about these formats:-
OAuth OAUTH_TOKEN: For authorization using the OAuth 2.0 protocol. Learn more -
Bearer IAM_TOKEN: For authorization using an IAMÂ token, if a Yandex Identity Hub organization is linked to Tracker. Learn more
-
-
ID types
X-Org-IDorX-Cloud-Org-ID: Organization ID.-
Use the
X-Org-IDheader if a Tracker organization is linked to Yandex 360 for Business. -
Use the
X-Cloud-Org-IDheader if a Tracker organization is linked to Yandex Identity Hub.
Finding the ID
To get the organization ID, go to Administration → Organizations and copy the value from the ID field.
-
Resource
| Parameter | Description | Data type |
|---|---|---|
entity_type |
Entity type:
|
String |
entity_ID |
Entity ID. To get the ID, see the entity list. You can use the id or shortId parameter as the ID. |
String |
You can use the id or shortId value for the {entity_ID} parameter.
Response format
If the request is successful, the API returns a response with code 200 OK.
The API returns an object with access permissions. The READ, GRANT, and WRITE properties are at the top level. The response doesn't include acl, permissionSources, or parentEntities.
{
"READ": {
"users": [],
"groups": [],
"roles": []
},
"GRANT": {
"users": [],
"groups": [],
"roles": ["AUTHOR", "OWNER"]
},
"WRITE": {
"users": [],
"groups": [],
"roles": ["CLIENT", "AUTHOR", "FOLLOWER", "OWNER", "MEMBER"]
}
}
Response parameters
| Parameter | Description | Data type |
|---|---|---|
| READ | Object with the users, groups, and roles that can view the entity | Object |
| GRANT | Object with the users, groups, and roles that can manage the entity's access settings | Object |
| WRITE | Object with the users, groups, and roles that can edit the entity | Object |
READ, GRANT, and WRITE object fields
|
Parameter |
Description |
Data type |
|
users |
List of users with this access type |
Object array |
|
groups |
List of groups with this access type |
Object array |
|
roles |
List of entity roles with this access type:
|
String array |
Fields of objects in the users array
| Parameter | Description | Data type |
|---|---|---|
| self | Address of the API resource with information about the user | String |
| id | User ID. | String |
| display | Displayed user name | String |
| passportUid | Unique ID of the user account in the Yandex 360 for Business organization and Yandex ID. | Number |
| cloudUid | Unique user ID in Yandex Identity Hub | String |
Fields of objects in the groups array
| Parameter | Description | Data type |
|---|---|---|
| self | The address of the API resource that contains information about the user group | String |
| id | Group ID | String |
| display | Group display name | String |
If the request is processed incorrectly, the API returns a response with an error code:
- 401
- The user is not authorized. Make sure that actions described in the API access section are performed.
- 403
- You are not authorized to perform this action. You can check what rights you have in the Tracker interface. The same rights are required to perform an action via the API and interface.
- 404
- The requested object was not found. You may have specified an invalid object ID or key.
To retrieve extended access settings, including inherited permissions, use the Get extended entity access settings request.