Skip to content
openlaunch
Esc
↑↓navigate↵open⌘Jpreview

List access policies

Lists the workspace’s delegation policies. The owner sees all; a delegated administrator sees the policies its live role permits. Legacy per-device grants are not listed here (see /v1/grants).

GET/v1/access-policies
Authorization
AuthorizationBearer token (Clerk owner session) · headerrequired

Owner identity required.

Responses
200

Successful response

dataAccessPolicy[]required
Show properties
Array of AccessPolicy
principalstringrequired
modestringrequired

selected keeps the legacy per-device grant list; all covers every workspace device with opt-out exclusions.

Allowed:allselected
excludedDevicesstring[]required
excludedFunctionsobject[]required
Show properties
Array of object
deviceIdstring | nullrequired
capabilitystringrequired
rolestringrequired
Allowed:operatoradministrator
expiresAtinteger | nullrequired
delegatedFromstring

Parent policy principal this policy was delegated from; a child is always intersected with the live parent chain, so delegated credentials can never escape parent exclusions, expiry or role changes.

400

Invalid request or validation failure

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
401

Missing or invalid credential

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
403

Insufficient access or grant

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
404

Resource not found

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
413

Request body exceeds the 16 KiB limit

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
429

Rate limit or workspace capacity limit

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
500

Internal error

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
503

Service or required integration is not configured

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
Try it
Server
Authorization
Request
curl -X GET 'https://www.openlaunch.dev/v1/access-policies' \
  -H 'Authorization: Bearer YOUR_TOKEN'
Response
{
  "data": [
    {
      "principal": "string",
      "mode": "all",
      "excludedDevices": [
        "string"
      ],
      "excludedFunctions": [
        {
          "deviceId": "string",
          "capability": "string"
        }
      ],
      "role": "operator",
      "expiresAt": 0,
      "delegatedFrom": "string"
    }
  ]
}