Skip to content
qibdo qibdo
v1
API version
  • v1
Theme
Book a demo

List Roles

GET
/iam/v1/roles
curl --request GET \
--url https://example.com/iam/v1/roles

Returns a paginated list of roles

page_size
integer format: int32

The maximum number of roles to return. The service may return fewer than this value. If unspecified, at most 20 roles will be returned. The maximum value is 100; values above 100 will be coerced to 100.

page_token
string

A page token, received from a previous ListRoles call. Provide this to retrieve the subsequent page. When paginating, all other parameters provided to ListRoles must match the call that provided the page token.

filter
string

AIP-160 filter expression. Filterable fields: create_time, display_name, id, name, role_type, scope_id, scope_type, stage, update_time.

order_by
string

AIP-132 order_by expression. Sortable fields: create_time, display_name, name, role_type, stage, update_time.

skip
string

AIP-158 offset mode: number of resources to skip from the start of the filtered, sorted set. Use EITHER skip (offset paging) OR page_token (cursor paging) — never both in the same request. Supplying both is an invalid request. Default 0 (no skip).

OK

Media type application/json

ListRolesResponse

Response message for ListRoles.

object
roles

The list of roles

Array<object>

Role resource: a named collection of permissions assignable to principals

object
id

The unique identifier of the role

stringOutput only
name
required

The handle of the role, e.g. “billing-viewer”. Lowercase letters, digits and hyphens; letter-initial; no adjacent hyphens. Parent-scoped-unique. Used to address the role by name or id.

string
display_name

A human-readable label for the role, e.g. “Billing Viewer”. Free text in any script. Never used to address the role. Optional; defaults to the handle (name) when omitted.

string
description

An optional description of the role

string
role_type

The type of role (system or custom)

string format: enum Output only
Allowed values: ROLE_TYPE_UNSPECIFIED ROLE_TYPE_SYSTEM ROLE_TYPE_CUSTOM
stage

The lifecycle stage of the role

string format: enum Output only
Allowed values: ROLE_STAGE_UNSPECIFIED ROLE_STAGE_ACTIVE ROLE_STAGE_DEPRECATED ROLE_STAGE_DISABLED
scope_type

The type of scope this role is defined in (only for custom roles)

string format: enum
Allowed values: SCOPE_TYPE_UNSPECIFIED SCOPE_TYPE_WORKSPACE SCOPE_TYPE_GROUP SCOPE_TYPE_ORGANISATION SCOPE_TYPE_PLATFORM
scope_id

The ID of the scoped resource (only for custom roles)

string
create_time

Created Timestamp

The timestamp when the role was created

string format: date-time Output only
update_time

Updated Timestamp

Timestamp when the Role was last updated

string format: date-time Output only
next_page_token

A token, which can be sent as page_token to retrieve the next page. If this field is empty, there are no subsequent pages.

string
total_size

Exact count of resources matching the request’s filter and scope (both pagination modes).

string
Example
{
"roles": [
{
"role_type": "ROLE_TYPE_UNSPECIFIED",
"stage": "ROLE_STAGE_UNSPECIFIED",
"scope_type": "SCOPE_TYPE_UNSPECIFIED"
}
]
}

Default error response

Media type application/json

The Status type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by gRPC. Each Status message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the API Design Guide.

object
code

The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].

integer format: int32
message

A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.

string
details

A list of messages that carry the error details. There is a common set of message types for APIs to use.

Array<object>

Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.

object
@type

The type of the serialized message.

string
key
additional properties
any
Example generated
{
"code": 1,
"message": "example",
"details": [
{
"@type": "example"
}
]
}