## Retrieve

`client.Zones.Roles.Get(ctx, roleID, query) (*Role, error)`

**get** `/zones/{zoneId}/roles/{roleId}`

Returns details of a specific role by ID

### Parameters

- `roleID string`

- `query ZoneRoleGetParams`

  - `ZoneID param.Field[string]`

    Zone ID

### Returns

- `type Role struct{…}`

  A role that can be assigned to users within a zone.

  - `ID string`

    Unique identifier of the role

  - `CreatedAt Time`

    Entity creation timestamp

  - `Identifier string`

    Role identifier: a lowercase slug (letters and digits separated by single hyphens or underscores), unique per owner type within a zone. Role identifiers surface in policy evaluation, so the slug restriction keeps them unambiguous in policy text.

  - `OwnerType RoleOwnerType`

    Who owns this role. Platform-owned roles are managed by Keycard and cannot be modified or deleted via the API; customer-owned roles are user-created.

    - `const RoleOwnerTypePlatform RoleOwnerType = "platform"`

    - `const RoleOwnerTypeCustomer RoleOwnerType = "customer"`

  - `UpdatedAt Time`

    Entity update timestamp

  - `ZoneID string`

    Zone this role belongs to

  - `Description string`

    Human-readable description

### Example

```go
package main

import (
  "context"
  "fmt"

  "github.com/keycardai/keycard-go"
  "github.com/keycardai/keycard-go/option"
)

func main() {
  client := keycard.NewClient(
    option.WithAPIKey("My API Key"),
  )
  role, err := client.Zones.Roles.Get(
    context.TODO(),
    "roleId",
    keycard.ZoneRoleGetParams{
      ZoneID: "zoneId",
    },
  )
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", role.ID)
}
```
