List roles

The roles this organization has, and exactly what each one allows. Every organization starts with three: `member` for everyday use, `admin` for running the place, and `owner` for the person who owns it. Add your own for anything in between — a role for read-only reporting, or one for a ticket scanner that may only redeem. Requires the `organizations.roles.read` permission.

GET
/organizations/{organizationId}/roles
AuthorizationBearer <token>

The access token returned after a successful sign-in, sent as Authorization: Bearer <access_token>.

It identifies the person and the organization they are working in, and it lasts about fifteen minutes. When it runs out, use their refresh token at POST /auth/refresh-token instead of asking them to sign in again.

In: header

Path Parameters

organizationId*string

Identifier of the organization. Each endpoint states whether it must be the caller's active organization or may be used without authentication.

Query Parameters

id?string

Return only the resource with this identifier. Equivalent to fetching it by path, but usable together with the other list filters.

name?string

Return only resources whose name matches this value exactly.

Lengthlength <= 255
autocomplete?string

Search the endpoint's supported text and identifier fields. Matching may be an exact identifier lookup or a case-insensitive prefix search, depending on the resource. Alphanumeric characters only.

limit?integer

How many items to return in one page. The default and the maximum are both 25; a larger value is rejected with 400.

Default25
Formatint64
Range1 <= value <= 25
next?string

Cursor for the next page, taken verbatim from the next field of the previous response. Keep every other query parameter the same between pages: sortBy and order are part of what the cursor means. An absent or empty next in a response means there are no more pages.

The value is opaque. Do not parse it or build one yourself.

order?string

Sort direction. Defaults to desc, newest first.

Default"desc"
Value in"asc" | "desc"
sortBy?string

Field used to sort the result. Supported fields depend on the endpoint; use when_created for chronological ordering where it is available. The default is the resource identifier, and identifiers break ties so cursor paging stays stable.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X GET "https://api.dual.network/organizations/665f1c2d4b1a2c3d4e5f6aa0/roles"
{
  "roles": [
    {
      "id": "665f1c2d4b1a2c3d4e5f6ab0",
      "name": "member",
      "permissions": [
        {
          "resource": "objects",
          "crud": {
            "read": true,
            "create": false,
            "update": false,
            "delete": false
          }
        }
      ],
      "when_created": "2026-02-01T09:00:00Z",
      "when_modified": "2026-02-01T09:00:00Z"
    },
    {
      "id": "665f1c2d4b1a2c3d4e5f6ab1",
      "name": "admin",
      "permissions": [
        {
          "resource": "organizations.members",
          "crud": {
            "read": true,
            "create": true,
            "update": true,
            "delete": true
          }
        }
      ],
      "when_created": "2026-02-01T09:00:00Z",
      "when_modified": "2026-02-01T09:00:00Z"
    },
    {
      "id": "665f1c2d4b1a2c3d4e5f6ab2",
      "name": "owner",
      "permissions": [
        {
          "resource": "organizations",
          "crud": {
            "read": true,
            "create": true,
            "update": true,
            "delete": true
          }
        }
      ],
      "when_created": "2026-02-01T09:00:00Z",
      "when_modified": "2026-02-01T09:00:00Z"
    }
  ]
}
{
  "code": 3,
  "message": "Key: 'limit' Error:Field validation for 'limit' failed on the 'lte' tag"
}

{
  "code": 16,
  "message": "no auth provided"
}

{
  "code": 5,
  "message": "object not found"
}
{
  "code": 13,
  "message": "internal error"
}