List access policies
Lists the workspace’s delegation policies. The owner sees all; a delegated administrator sees the policies its live role permits. Legacy per-device grants are not listed here (see /v1/grants).
/v1/access-policiesAuthorizationBearer token (Clerk owner session) · headerrequiredOwner identity required.
Successful response
dataAccessPolicy[]requiredShow propertiesHide properties
AccessPolicyprincipalstringrequiredmodestringrequiredselected keeps the legacy per-device grant list; all covers every workspace device with opt-out exclusions.
allselectedexcludedDevicesstring[]requiredexcludedFunctionsobject[]requiredShow propertiesHide properties
objectdeviceIdstring | nullrequiredcapabilitystringrequiredrolestringrequiredoperatoradministratorexpiresAtinteger | nullrequireddelegatedFromstringParent policy principal this policy was delegated from; a child is always intersected with the live parent chain, so delegated credentials can never escape parent exclusions, expiry or role changes.
Invalid request or validation failure
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringMissing or invalid credential
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringInsufficient access or grant
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringResource not found
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringRequest body exceeds the 16 KiB limit
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringRate limit or workspace capacity limit
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringInternal error
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringService or required integration is not configured
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestring