Skip to content
v0.3

read.internal.roles

The tenant’s role catalog (key, name, scopes, builtin). Internal face only.

  • Surface: GET /v1/read/internal/roles · MCP tool read.internal.roles
  • Auth:Internal read (operator) — a tenant credential is REQUIRED; requires the iam.roles.write scope. The tenant is resolved from the CALLER’s identity, never from store. Personal fields come back MASKED for an actor without pii.read (the shape is unchanged).
{
"properties": {},
"type": "object"
}

Open (unknown) — this capability does not declare an output schema.

validation_failed (400) · not_found (404) · unauthorized (401) · forbidden (403)