# List the permission catalog

`GET https://evohub.io/api/v1/permissions`

Part of the [Organization API](https://docs-dev.evohub.io/organization.md) reference · operationId `listPermissions`.

Every permission a role or a key can carry, split into service, resource and
action, with `grantable` saying whether the caller holds it.

`org_id` naming another organization is for a person signed in to the
console choosing which organization a new key is for; an API key answers
only for its own organization and gets **403** for any other.

**Permission:** none — any valid API key of the organization.

## Authorization

Any one of:

- `bearerAuth`
- `apiKeyHeader`

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Query parameters

- `org_id` (string): The key's own organization (`org_…`); any other is 403 for an API key.

## Responses

### 200 — The catalog.

Content type: `application/json`

Type: `object`

- `data` (array of Permission, required)
  - `permission` (string)
  - `service` (string)
  - `resource` (string)
  - `action` (string)
  - `deprecated` (boolean): An older name still accepted, no longer offered.
  - `grantable` (boolean): Whether the caller holds it, and so may put it in a role or on a key.
- `success` (boolean, required, value `true`)

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 403 — `org_id` is not the key's own organization (`FORBIDDEN`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

## Example request

```bash
curl -X GET 'https://evohub.io/api/v1/permissions' \
  -H 'Authorization: Bearer <TOKEN>'
```
