> ## Documentation Index
> Fetch the complete documentation index at: https://docs.basaltic.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# List internet gateway routes

> List routes targeting this internet gateway, newest first, with route-table identity. Requires read access to the gateway. Only routes in tables where the caller has network:ListRoutes permission are returned; pagination applies to those visible routes.

<Info>
  Primary IAM action: **`network:GetInternetGateway`**.
  Additionally checks network:ListRoutes on each owning route table, including resource-tag conditions. Routes in denied tables are omitted.
  See [NETWORK permissions](/networking/permissions) for policy examples.
</Info>


## OpenAPI

````yaml /api-reference/specs/network.yaml get /v1/internet-gateways/{internet_gateway_id}/routes
openapi: 3.0.3
info:
  title: Basaltic Network API
  version: 1.0.0
  description: |
    The VPC surface — networks and subnets, interfaces, route tables,
    security groups, internet, NAT and egress-only gateways, and floating
    IPs.

    Relationship inputs use one reference field: UUID, CRN, or an exact name
    when the request supplies its required parent scope. Subnets and route
    tables are VPC-scoped; interfaces are subnet-scoped. Nested CRNs use
    vpc/<vpc>/subnet/<subnet>, vpc/<vpc>/route-table/<table>, and
    vpc/<vpc>/subnet/<subnet>/interface/<interface>. Names are immutable.
    Unknown request fields and list parameters are rejected.
    Supplied empty references are invalid and failed lookups never fall back
    to another reference kind. Every list accepts exact name and crn filters.
  contact:
    name: Basaltic Support
    email: ping@basaltic.sh
  license:
    name: Proprietary
    url: https://basaltic.sh/terms
servers:
  - url: https://network.{region}.basaltic.sh
    description: Regional API endpoint
    variables:
      region:
        default: sa-saopaulo-1
        description: Region code
security:
  - BearerAuth: []
paths:
  /v1/internet-gateways/{internet_gateway_id}/routes:
    get:
      tags:
        - Networking
      summary: List internet gateway routes
      description: >-
        List routes targeting this internet gateway, newest first, with
        route-table identity. Requires read access to the gateway. Only routes
        in tables where the caller has network:ListRoutes permission are
        returned; pagination applies to those visible routes.
      operationId: listInternetGatewayRoutes
      parameters:
        - name: name
          in: query
          description: >-
            Exact resource name. This resource has no name, so a supplied name
            returns an empty result.
          schema:
            type: string
        - name: crn
          in: query
          description: >-
            Exact CRN, validated against the endpoint type, region and caller
            account. Valid foreign or mismatched CRNs return an empty result;
            malformed or flat child CRNs return 400. Filters are conjunctive.
          schema:
            type: string
        - $ref: '#/components/parameters/InternetGatewayId'
        - name: limit
          in: query
          schema:
            type: integer
            minimum: 1
            maximum: 500
            default: 50
            example: 50
        - name: marker
          in: query
          schema:
            type: string
            format: uuid
            example: a3c9e1f4-7b2d-4a6e-8c1f-9d3b5e7a2c4f
          description: Resume token — the last id from the previous page.
      responses:
        '200':
          description: List of routes
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GatewayRouteListResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
      security:
        - BearerAuth: []
components:
  parameters:
    InternetGatewayId:
      name: internet_gateway_id
      in: path
      description: Internet Gateway ID
      required: true
      schema:
        type: string
        format: uuid
      example: 550e8400-e29b-41d4-a716-446655440000
  schemas:
    GatewayRouteListResponse:
      type: object
      required:
        - routes
        - meta
      properties:
        routes:
          type: array
          items:
            $ref: '#/components/schemas/GatewayRoute'
        meta:
          $ref: '#/components/schemas/PaginationMeta'
    GatewayRoute:
      allOf:
        - $ref: '#/components/schemas/Route'
        - type: object
          required:
            - route_table
          properties:
            route_table:
              $ref: '#/components/schemas/RouteTableSummary'
    PaginationMeta:
      type: object
      properties:
        total:
          type: integer
          description: Total number of items
          example: 150
        limit:
          type: integer
          description: Number of items per page
          example: 20
        marker:
          type: string
          description: >-
            Opaque cursor for the next page. Pass it back as the `marker` query
            parameter; treat it as a token, not a value to parse.
          example: 550e8400-e29b-41d4-a716-446655440000
        has_more:
          type: boolean
          description: Whether there are more items
          example: true
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
            - request_id
          properties:
            code:
              type: string
              description: Error code identifying the type of error
              example: INVALID_INPUT
            message:
              type: string
              description: Human-readable error message
              example: Invalid request parameters
            request_id:
              type: string
              format: uuid
              description: Request ID for debugging
              example: 550e8400-e29b-41d4-a716-446655440000
    Route:
      type: object
      required:
        - id
        - crn
        - route_table_id
        - destination_cidr
        - target_type
        - tags
        - created_at
        - updated_at
      properties:
        id:
          type: string
          format: uuid
          readOnly: true
        crn:
          type: string
          readOnly: true
          example: crn:network:sa-saopaulo-1:my-account:route/<uuid>
        route_table_id:
          type: string
          format: uuid
          example: a3c9e1f4-7b2d-4a6e-8c1f-9d3b5e7a2c4f
        description:
          type: string
          example: Default route to the internet gateway
        destination_cidr:
          type: string
          example: 0.0.0.0/0
        target_type:
          $ref: '#/components/schemas/RouteTargetType'
        next_hop_ip:
          type: string
          nullable: true
          description: >-
            Set when target_type=ip. Mutex with the target_*_id fields. Must be
            a unicast address inside this VPC's CIDR (same IP family as
            destination_cidr); internet egress uses target_internet_gateway_id /
            target_nat_gateway_id.
          example: 10.0.1.1
        target_internet_gateway_id:
          type: string
          format: uuid
          nullable: true
          description: Set when target_type=internet_gateway.
          example: c4f7a2e9-8d1b-4e6c-9a3f-5b2d7c1e8a4f
        target_nat_gateway_id:
          type: string
          format: uuid
          nullable: true
          description: >-
            Set when target_type=nat_gateway. Supports IPv4 and IPv6; IPv6
            requires an IPv6-enabled hosting subnet.
          example: e2a8c5f1-3b9d-4c7e-8a1f-6d4b2e9c3a5f
        target_egress_only_gateway_id:
          type: string
          format: uuid
          nullable: true
          description: >-
            Set when target_type=egress_only_gateway (IPv6 only). Gives the
            subnet outbound v6 with the internet unable to initiate inbound.
          example: b7d3f1a9-2c8e-4b6d-9f1a-3e5c7d2b8a4f
        tags:
          type: object
          additionalProperties:
            type: string
        created_at:
          type: string
          format: date-time
          readOnly: true
        updated_at:
          type: string
          format: date-time
          readOnly: true
    RouteTableSummary:
      type: object
      nullable: true
      additionalProperties: false
      description: |
        Route table used by a subnet, without repeating its VPC. Null when the
        non-owning lookup no longer resolves, for example during concurrent
        reassociation and deletion of the former table. Deleting a table still
        associated with subnets is refused.
      required:
        - id
        - crn
        - name
      properties:
        id:
          type: string
          format: uuid
          readOnly: true
        crn:
          type: string
          readOnly: true
          example: >-
            crn:network:sa-saopaulo-1:my-account:vpc/prod/route-table/prod-private-rt
        name:
          type: string
          example: prod-private-rt
    RouteTargetType:
      type: string
      enum:
        - ip
        - internet_gateway
        - nat_gateway
        - egress_only_gateway
      description: |
        Discriminator for the route's target. New target types
        (interface, vpc_peering, …) extend this enum and add their own
        target_* field. Mirrors AWS one-field-per-target style —
        exactly one target_* property must be set on create.
  responses:
    BadRequest:
      description: Invalid request parameters
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: INVALID_INPUT
              message: Invalid request parameters
              request_id: 550e8400-e29b-41d4-a716-446655440000
    Unauthorized:
      description: Authentication required or token invalid
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: UNAUTHORIZED
              message: Authentication required
              request_id: 550e8400-e29b-41d4-a716-446655440000
    Forbidden:
      description: Insufficient permissions
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: ACCESS_DENIED
              message: You don't have permission to perform this action
              request_id: 550e8400-e29b-41d4-a716-446655440000
    NotFound:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: NOT_FOUND
              message: Resource not found
              request_id: 550e8400-e29b-41d4-a716-446655440000
    InternalServerError:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: INTERNAL_ERROR
              message: An internal error occurred
              request_id: 550e8400-e29b-41d4-a716-446655440000
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: |
        An OAuth 2.0 bearer token, sent as `Authorization: Bearer <token>`.
        This is the recommended way to authenticate.

        Get one by exchanging a service account's access key pair at
        `POST /v1/oauth/token` with `grant_type=client_credentials`. It is the
        standard client-credentials grant, so any OAuth-aware library will
        obtain and refresh it for you.

        ```
        curl -s -u "$KEY_ID:$SECRET" -d grant_type=client_credentials \
          https://iam.basaltic.sh/v1/oauth/token
        ```

        Tokens last an hour by default. The same access key pair is separately
        your AWS SigV4 credential for the S3-compatible object endpoint, which
        speaks nothing else.

````