read.internal.roles
The tenant’s role catalog (key, name, scopes, builtin). Internal face only.
- Surface:
GET /v1/read/internal/roles· MCP toolread.internal.roles - Auth: ★ Internal read (operator) — a tenant credential is REQUIRED; requires the
iam.roles.writescope. The tenant is resolved from the CALLER’s identity, never fromstore. Personal fields come back MASKED for an actor withoutpii.read(the shape is unchanged).
Params (JSON Schema)
Section titled “Params (JSON Schema)”{ "properties": {}, "type": "object"}Result (200)
Section titled “Result (200)”Open (unknown) — this capability does not declare an output schema.
Errors
Section titled “Errors”validation_failed (400) · not_found (404) · unauthorized (401) · forbidden (403)