Skip to content
Docs
Roles

List user role assignments

List user role assignments

zones.users.roles.list(struser_id, RoleListParams**kwargs) -> RoleListResponse
GET/zones/{zoneId}/users/{userId}/roles

Returns the roles assigned to the specified user within the zone. The full result set is currently returned in a single page; the after/before/limit cursor parameters are reserved and not yet enforced, and pagination cursors are always null.

ParametersExpand Collapse
zone_id: str
user_id: str
after: Optional[str]

Cursor for forward pagination

minLength1
maxLength255
before: Optional[str]

Cursor for backward pagination

minLength1
maxLength255
expand: Optional[Union[Literal["total_count"], List[Literal["total_count"]]]]
Accepts one of the following:
Literal["total_count"]
List[Literal["total_count"]]
limit: Optional[int]

Maximum number of items to return

minimum1
maximum100
ReturnsExpand Collapse
class RoleListResponse:
items: List[RoleAssignment]
id: str

Unique identifier of the role assignment

created_at: datetime

Entity creation timestamp

formatdate-time
principal_id: str

ID of the principal the role is assigned to (a user, application, or group ID).

principal_type: str

The kind of principal the role is assigned to: user, application, or group. A role assigned to a group is inherited by that group's members.

role_id: str

ID of the assigned role

role_identifier: str

Role identifier: a lowercase slug (letters and digits separated by single hyphens or underscores), unique per owner type within a zone. Role identifiers surface in policy evaluation, so the slug restriction keeps them unambiguous in policy text.

minLength1
maxLength255
role_owner_type: Literal["platform", "customer"]

Owner type of the assigned role. Disambiguates roles that share an identifier across owner types.

Accepts one of the following:
"platform"
"customer"
updated_at: datetime

Entity update timestamp

formatdate-time
zone_id: str

Zone this assignment belongs to

scope_id: Optional[str]

The ID of the scoped resource. Null when the assignment is unscoped.

scope_type: Optional[str]

The kind of resource this grant is scoped to (e.g. zone). Null when the assignment is unscoped (applies to the owning zone itself).

List user role assignments

import os
from keycardai_api import KeycardAPI

client = KeycardAPI(
    api_key=os.environ.get("KEYCARD_API_API_KEY"),  # This is the default and can be omitted
)
roles = client.zones.users.roles.list(
    user_id="userId",
    zone_id="zoneId",
)
print(roles.items)
{
  "items": [
    {
      "id": "id",
      "created_at": "2019-12-27T18:11:19.117Z",
      "principal_id": "principal_id",
      "principal_type": "principal_type",
      "role_id": "role_id",
      "role_identifier": "role_identifier",
      "role_owner_type": "platform",
      "updated_at": "2019-12-27T18:11:19.117Z",
      "zone_id": "zone_id",
      "scope_id": "scope_id",
      "scope_type": "scope_type"
    }
  ],
  "pagination": {
    "after_cursor": "x",
    "before_cursor": "x",
    "total_count": 0
  }
}
Returns Examples
{
  "items": [
    {
      "id": "id",
      "created_at": "2019-12-27T18:11:19.117Z",
      "principal_id": "principal_id",
      "principal_type": "principal_type",
      "role_id": "role_id",
      "role_identifier": "role_identifier",
      "role_owner_type": "platform",
      "updated_at": "2019-12-27T18:11:19.117Z",
      "zone_id": "zone_id",
      "scope_id": "scope_id",
      "scope_type": "scope_type"
    }
  ],
  "pagination": {
    "after_cursor": "x",
    "before_cursor": "x",
    "total_count": 0
  }
}