Get My Capabilities In Tenant
List the capabilities the authenticated user has in a tenant.
Capabilities are tenant-scoped actions (as opposed to dataset permissions) and are the union of what the tenant and the caller’s roles in it grant. The tenant owner holds all of them.
The caller must belong to the tenant. A tenant they are not a member of and one that does not exist both answer 403, so the endpoint cannot be used to discover which tenant ids are real.
Intended for the client to decide which controls to show. It is not an authorization boundary on its own: every endpoint still enforces its own capability, since anyone who knows the URL can call it without the UI.
Path Parameters
- tenant_id (UUID): The UUID of the tenant (find yours via GET /api/v1/permissions/tenants/me)
Response
Returns a JSON object: {“capabilities”: [“manage_users”, …]}.
Error Codes
- 403 Forbidden: Caller is not a member of the tenant, or it does not exist