List document permissions
Retrieves all permission assignments for the specified document, including user and group permissions with their roles and access levels.
Authorization: Requires document editor or workspace manager permissions. Response: Returns array of permission objects with user/group identifiers and roles.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
The unique identifier of the organization Standard identifier pattern for resource names
^[a-zA-Z0-9_ -]+$The unique identifier of the workspace
Workspace name pattern. Allows any character except / (would split the FGA resource path — see ResourceIdentifier.parseFromFga) and * (FGA wildcard). 1-63 chars.
^(?!.*\*)(?!.*[/]).{1,63}$The path to the document within the workspace Document path. Permits alphanumerics, spaces, ASCII hyphen, Unicode en-dash/em-dash (U+2013/U+2014), and common title punctuation (& : , ' + ? ! ( ) $ ^). Bans path traversal (..). Length capped at 255 to match the underlying varchar(255) storage column. % is deliberately excluded because @InitBinder decodes %2F → / in path variables to fix encoded-slash routing, which would collide with any path that legitimately contained '%2F'.
255^(?!.*\.\.)[a-zA-Z0-9_/. \-&:,'+?!()$^–—]+$Response
List of document permissions retrieved successfully
A resource identifier that uniquely identifies either a user or a group within the system. This identifier is used throughout the API for permission management and access control.
Format:
- For users:
user:{email}oruser:{userId} - For groups:
group:{groupName}
^(user:[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}|group:[a-zA-Z0-9._-]+)$The role/permission level granted to the user or group
editor, viewer The permission level inherited from parent workspace
manager, viewer Optional message or note about the permission assignment
ISO 8601 timestamp indicating when the permission was created
ISO 8601 timestamp indicating when the permission was last modified