- Legion API
- Authorization
- Expand permissions
Expand permissions
POST
/v3/authorization/permissions/expand
const url = 'https://us-gov.legion.picogrid.com/v3/authorization/permissions/expand';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"limit":25,"offset":0,"relation":"viewer","resource":"entity:123e4567-e89b-12d3-a456-426614174000"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://us-gov.legion.picogrid.com/v3/authorization/permissions/expand \ --header 'Content-Type: application/json' \ --data '{ "limit": 25, "offset": 0, "relation": "viewer", "resource": "entity:123e4567-e89b-12d3-a456-426614174000" }'Find all subjects that have access to a resource. Requires organization context and organizations:users:read scope.
Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/json
object
inheritance_source
string
limit
number
offset
number
relation
string
resource
string
subject_type
string
Example
{ "limit": 25, "offset": 0, "relation": "viewer", "resource": "entity:123e4567-e89b-12d3-a456-426614174000"}Responses
Section titled “Responses”Successful response
Media typeapplication/json
object
count
required
number
direct_subjects
required
Array<object>
object
granted_at
string
granted_by
string format: uuid
relation
string
source
required
string
subject
string
has_more
required
boolean
offset
required
number
organization_id
string
relation
string
resource
string
total_count
required
number
Example
{ "direct_subjects": [ {} ], "organization_id": "123e4567-e89b-12d3-a456-426614174000", "relation": "viewer", "resource": "entity:123e4567-e89b-12d3-a456-426614174000", "total_count": 1}Bad Request
Media typeapplication/json
object
category
string
code
number
details
Array<object>
object
field
required
string
issue
required
string
message
string
status
string
timestamp
string
trace_id
string
Example
{ "code": "400", "details": "sample_value", "message": "Request cannot be processed due to invalid input", "status": "error", "timestamp": "2025-01-15T14:32:45Z", "trace_id": "req_2J9K8L7M6N5P4Q3R"}Unauthorized
Media typeapplication/json
object
category
string
code
number
details
Array<object>
object
field
required
string
issue
required
string
message
string
status
string
timestamp
string
trace_id
string
Example
{ "code": "401", "details": "sample_value", "message": "Authentication credentials are missing or invalid", "status": "error", "timestamp": "2025-01-15T14:32:45Z", "trace_id": "req_2J9K8L7M6N5P4Q3R"}Forbidden
Media typeapplication/json
object
category
string
code
number
details
Array<object>
object
field
required
string
issue
required
string
message
string
status
string
timestamp
string
trace_id
string
Example
{ "code": "403", "details": "sample_value", "message": "Access denied: insufficient permissions for this resource", "status": "error", "timestamp": "2025-01-15T14:32:45Z", "trace_id": "req_2J9K8L7M6N5P4Q3R"}Not Found
Media typeapplication/json
object
category
string
code
number
details
Array<object>
object
field
required
string
issue
required
string
message
string
status
string
timestamp
string
trace_id
string
Example
{ "code": "404", "details": "sample_value", "message": "The requested resource could not be found", "status": "error", "timestamp": "2025-01-15T14:32:45Z", "trace_id": "req_2J9K8L7M6N5P4Q3R"}Internal Server Error
Media typeapplication/json
object
category
required
The category of the error
string
code
required
The HTTP status code
number
details
required
Additional details about the error
Array<object>
object
field
The field that caused the error
string
issue
The specific issue with the field
string
message
required
A human-readable error message
string
status
required
The status of the response, always ‘error’ for error responses
string
timestamp
required
The timestamp when the error occurred
string format: date-time
trace_id
required
A unique identifier for tracing the error
string format: uuid
Example
{ "category": "server_error", "code": "500", "details": [ { "field": "field_name", "issue": "Field validation issue" } ], "message": "Internal Server Error", "status": "error", "timestamp": "2024-03-15T10:30:00Z", "trace_id": "b7c5e4d3-a2b1-4f0e-8d9c-1a2b3c4d5e6f"}Version 3.0.0 · commit 0771262
