curl "https://api.scanova.io/multi-users/permission/" \
-H "Authorization: 401f7ac837da42b97f613d789819ff93537bee6a"
[
{
"name": "QR Codes",
"permissions": [
{ "id": 23, "code": "QR_CODE_CAN_VIEW", "name": "Can view QR Code", "description": "Allows viewing QR code details.", "is_boolean": true }
]
}
]
Shared Users & Roles
List permission categories
GET /multi-users/permission/
GET
/
multi-users
/
permission
/
curl "https://api.scanova.io/multi-users/permission/" \
-H "Authorization: 401f7ac837da42b97f613d789819ff93537bee6a"
[
{
"name": "QR Codes",
"permissions": [
{ "id": 23, "code": "QR_CODE_CAN_VIEW", "name": "Can view QR Code", "description": "Allows viewing QR code details.", "is_boolean": true }
]
}
]
Lists every active permission category and the shared permissions available within it, on the Management API host (
Not paginated. This is the bulk, category-grouped alternative to reading permission IDs off an existing role’s
api.scanova.io), authenticated with your raw Management API key.
GET https://api.scanova.io/multi-users/permission/
Authorization: 401f7ac837da42b97f613d789819ff93537bee6a
curl "https://api.scanova.io/multi-users/permission/" \
-H "Authorization: 401f7ac837da42b97f613d789819ff93537bee6a"
[
{
"name": "QR Codes",
"permissions": [
{ "id": 23, "code": "QR_CODE_CAN_VIEW", "name": "Can view QR Code", "description": "Allows viewing QR code details.", "is_boolean": true }
]
}
]
permissions array — use it to build a full role-editor UI (grouped checkboxes by category) without first fetching a role.
Related
- Create a custom role — use permission IDs from here to build
permissions. - List roles — see which permissions an existing role already grants.
- Roles & permissions — the human-facing explanation of what each permission grants.
- Management API overview — the auth scheme and quota rules that apply to this endpoint.
Authorizations
Send your Management API key as the raw value of the Authorization header — no "Bearer " or "Token " prefix, and no other characters. Example: Authorization: 401f7ac837da42b97f613d789819ff93537bee6a. A header containing more than one space-separated part is rejected outright. Requests also require the request's Host header to be the management API host (e.g. api.scanova.io) — the same key sent to the regular API host will not authenticate.
Response
200 - application/json
Permission categories with their permissions.
Was this page helpful?