Skip to main content
GET
List policies
Requires the IAM action workspace:ListPolicies. See WORKSPACE permissions for the full list, what each one covers, and an example policy.

Authorizations

Authorization
string
header
required

An OAuth 2.0 bearer token, sent as Authorization: Bearer <token>. This is the recommended way to authenticate.

Get one by exchanging a service account's access key pair at POST /v1/oauth/token with grant_type=client_credentials. It is the standard client-credentials grant, so any OAuth-aware library will obtain and refresh it for you.

Tokens last an hour by default. The same access key pair is separately your AWS SigV4 credential for the S3-compatible object endpoint, which speaks nothing else.

Query Parameters

name
string

Exact resource name, combined with crn using AND before pagination. Empty values are filters. Resources without a name never match.

crn
string

Exact returned CRN, combined with name using AND before pagination. Malformed or empty CRNs return 400; valid mismatched or foreign CRNs return an empty page. Resources without a CRN never match. Organization-scoped CRNs use the authenticated organization.

limit
integer
default:20

Maximum number of items to return. A value above the maximum is clamped to it rather than rejected, so a page shorter than the one you asked for is normal — page until meta.has_more is false, not until a page looks short.

Required range: 1 <= x <= 100
marker
string

Opaque pagination cursor. Echo back the meta.marker value from the previous page to fetch the next one; do not construct or parse it. The token's internal form varies by endpoint (a resource ID, a timestamp, …) and is not guaranteed stable across releases.

Response

List of policies

policies
object[]
meta
object