> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cognee.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Principal Datasets

> List the datasets a principal holds a permission on.

A principal is a user, a role or a tenant. What the caller may ask about
depends on which: themselves or any user if they can manage users; a role
of this tenant they belong to, or any of its roles if they can manage
users; and only the tenant they are currently in. Results are always
narrowed to the caller's current tenant.

## Path Parameters
- **principal_id** (UUID): The principal UUID — a user, role or tenant.

## Request Parameters
- **permission_name** (str): Permission to list. Defaults to "read".

## Response
Returns a JSON list of dataset objects the principal has that permission on.

## Error Codes
- **403 Forbidden**: Caller may not ask about this principal
- **404 Not Found**: Principal does not exist in the caller's tenant



## OpenAPI

````yaml /cognee_openapi_spec.json get /api/v1/permissions/principals/{principal_id}/datasets
openapi: 3.1.0
info:
  title: Cognee API
  description: Cognee API with Bearer token and Cookie auth
  version: 1.0.0
servers:
  - url: https://api.cognee.ai
    description: Production server (full functionality)
  - url: http://localhost:8000
    description: Local development server (requires local setup)
security:
  - BearerAuth: []
  - ApiKeyAuth: []
tags:
  - name: activity
    description: ''
  - name: add
    description: Data ingestion endpoints for adding text, files, and structured data.
  - name: agent connections
    description: ''
  - name: agent management
    description: ''
  - name: auth
    description: >-
      Authentication endpoints for user registration, login, and token
      management.
  - name: checks
    description: ''
  - name: cognify
    description: >-
      Knowledge processing endpoints to transform raw data into knowledge
      graphs.
  - name: configuration
    description: ''
  - name: datasets
    description: Dataset management endpoints for listing, creating, and deleting datasets.
  - name: delete
    description: Data deletion endpoints (deprecated — use datasets endpoints instead).
  - name: forget
    description: ''
  - name: health
    description: ''
  - name: improve
    description: ''
  - name: integrations
    description: ''
  - name: llm
    description: ''
  - name: memify
    description: ''
  - name: ontologies
    description: ''
  - name: permissions
    description: Permission management for multi-user access control.
  - name: recall
    description: ''
  - name: remember
    description: ''
  - name: responses
    description: Response generation endpoints using the knowledge graph.
  - name: schema
    description: ''
  - name: search
    description: Search endpoints for querying the knowledge graph.
  - name: sessions
    description: ''
  - name: settings
    description: Configuration endpoints for managing Cognee settings.
  - name: skills
    description: ''
  - name: slack
    description: ''
  - name: sync
    description: ''
  - name: update
    description: ''
  - name: users
    description: User management endpoints.
  - name: validate
    description: ''
  - name: visualize
    description: Graph visualization endpoints.
paths:
  /api/v1/permissions/principals/{principal_id}/datasets:
    get:
      tags:
        - permissions
      summary: Get Principal Datasets
      description: >-
        List the datasets a principal holds a permission on.


        A principal is a user, a role or a tenant. What the caller may ask about

        depends on which: themselves or any user if they can manage users; a
        role

        of this tenant they belong to, or any of its roles if they can manage

        users; and only the tenant they are currently in. Results are always

        narrowed to the caller's current tenant.


        ## Path Parameters

        - **principal_id** (UUID): The principal UUID — a user, role or tenant.


        ## Request Parameters

        - **permission_name** (str): Permission to list. Defaults to "read".


        ## Response

        Returns a JSON list of dataset objects the principal has that permission
        on.


        ## Error Codes

        - **403 Forbidden**: Caller may not ask about this principal

        - **404 Not Found**: Principal does not exist in the caller's tenant
      operationId: >-
        get_principal_datasets_api_v1_permissions_principals__principal_id__datasets_get
      parameters:
        - name: principal_id
          in: path
          required: true
          schema:
            type: string
            format: uuid
            title: Principal Id
        - name: permission_name
          in: query
          required: false
          schema:
            type: string
            description: >-
              Permission to read back. One of 'read', 'write', 'delete',
              'share'.
            examples:
              - read
            default: read
            title: Permission Name
          description: Permission to read back. One of 'read', 'write', 'delete', 'share'.
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema: {}
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  schemas:
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-Api-Key

````