Skip to content

Get permission audit trail

GET
/v3/authorization/permissions/audit
curl --request GET \
--url 'https://api.hopper.west.prod.govcloud.legion.picogrid.com/v3/authorization/permissions/audit?action=grant&end_date=2024-02-16T21%3A45%3A33Z&limit=50&offset=0&resource_id=123e4567-e89b-12d3-a456-426614174000&resource_type=entity&start_date=2024-01-16T21%3A45%3A33Z&subject_id=f47ac10b-58cc-4372-a567-0e02b2c3d479&subject_type=user'

Get the permission audit trail with optional filtering. Requires organization context.

action
string
Example
grant
end_date
string
Example
2024-02-16T21:45:33Z
limit
integer
>= 1 <= 100
Example
50
offset
integer
Example
0
resource_id
string format: uuid
Example
123e4567-e89b-12d3-a456-426614174000
resource_type
string
Example
entity
start_date
string
Example
2024-01-16T21:45:33Z
subject_id
string format: uuid
Example
f47ac10b-58cc-4372-a567-0e02b2c3d479
subject_type
string
Example
user

Successful response

Media typeapplication/json
object
entries
required
Array<object>
object
action
required
string
id
required
integer
performed_at
string
performed_by
string format: uuid
reason
string
>= 1 characters <= 500 characters
relation
string
resource
string
subject
string
total_count
required
integer
Example
{
"entries": [
{}
],
"total_count": 1
}

Bad Request

Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{
"code": 400,
"details": [
{
"Field": "organization_id",
"Issue": "must be a valid UUID format"
}
],
"message": "Request cannot be processed due to invalid input",
"status": "error",
"timestamp": "2026-01-15T14:32:45Z",
"trace_id": "req_2J9K8L7M6N5P4Q3R"
}

Unauthorized

Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{
"code": 401,
"details": [
{
"Field": "authorization_header",
"Issue": "Bearer token is expired or malformed"
}
],
"message": "Authentication credentials are missing or invalid",
"status": "error",
"timestamp": "2026-01-15T14:32:45Z",
"trace_id": "req_2J9K8L7M6N5P4Q3R"
}

Forbidden

Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{
"code": 403,
"details": [
{
"Field": "required_scope",
"Issue": "requires 'orion:settings:write' scope, but token only has 'orion:settings:read'"
}
],
"message": "Access denied: insufficient permissions for this resource",
"status": "error",
"timestamp": "2026-01-15T14:32:45Z",
"trace_id": "req_2J9K8L7M6N5P4Q3R"
}

Not Found

Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{
"code": 404,
"details": [
{
"Field": "organization_id",
"Issue": "organization with ID 'a1b2c3d4-e5f6-7890-abcd-ef1234567890' not found"
}
],
"message": "The requested resource could not be found",
"status": "error",
"timestamp": "2026-01-15T14:32:45Z",
"trace_id": "req_2J9K8L7M6N5P4Q3R"
}

Internal Server Error

Media typeapplication/json
object
category
required

The category of the error

string
code
required

The HTTP status code

number
details

Additional details about the error

Array<object>
object
field

The field that caused the error

string
issue

The specific issue with the field

string
message
required

A human-readable error message

string
status
required

The status of the response, always ‘error’ for error responses

string
timestamp
required

The timestamp when the error occurred

string format: date-time
trace_id
required

A unique identifier for tracing the error

string format: uuid
Example
{
"category": "server_error",
"code": 500,
"details": [
{
"field": "field_name",
"issue": "Field validation issue"
}
],
"message": "Internal Server Error",
"status": "error",
"timestamp": "2024-03-15T10:30:00Z",
"trace_id": "b7c5e4d3-a2b1-4f0e-8d9c-1a2b3c4d5e6f"
}

Version 3.14.0 · commit 0771262