> ## Documentation Index
> Fetch the complete documentation index at: https://cantonfoundation-generated-reference-full-stack-preview.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# GET /v2/users/:user-id/rights

> List the set of all rights granted to a user.

<div class="x2mdx-ref-page x2mdx-ref-page--operation x2mdx-ref-page--manual-api" />

<div class="x2mdx-ref-hero">
  <p class="x2mdx-ref-summary">List the set of all rights granted to a user.</p>

  <div class="x2mdx-ref-badges">
    <span class="x2mdx-ref-badge x2mdx-ref-badge--protocol">OpenAPI</span>

    <a class="x2mdx-ref-badge x2mdx-ref-badge--changed" href="#history-updated-3-5">Updated 3.5</a>
  </div>
</div>

<RequestExample>
  ```bash cURL theme={"theme":{"light":"github-light","dark":"github-dark"}}
  curl --request GET \
    --url 'http://localhost:7575/v2/users/{user-id}/rights' \
    --header 'Authorization: Bearer $TOKEN'
  ```

  ```python Python theme={"theme":{"light":"github-light","dark":"github-dark"}}
  import json
  import requests

  url = "http://localhost:7575/v2/users/{user-id}/rights"
  headers = {'Authorization': 'Bearer <token>'}
  response = requests.request("GET", url, headers=headers)

  print(response.text)
  ```

  ```javascript JavaScript theme={"theme":{"light":"github-light","dark":"github-dark"}}
  const response = await fetch('http://localhost:7575/v2/users/{user-id}/rights', {
    method: 'GET',
    headers: {
    "Authorization": "Bearer <token>"
  },
  });

  console.log(await response.text());
  ```

  ```php PHP theme={"theme":{"light":"github-light","dark":"github-dark"}}
  <?php
  $curl = curl_init();

  curl_setopt_array($curl, [
      CURLOPT_URL => 'http://localhost:7575/v2/users/{user-id}/rights',
      CURLOPT_RETURNTRANSFER => true,
      CURLOPT_CUSTOMREQUEST => 'GET',
      CURLOPT_HTTPHEADER => [
          "Authorization: Bearer <token>"
      ],
  ]);

  $response = curl_exec($curl);
  echo $response;
  ```

  ```go Go theme={"theme":{"light":"github-light","dark":"github-dark"}}
  package main

  import (
    "fmt"
    "io"
    "net/http"
  )

  func main() {
    req, _ := http.NewRequest("GET", "http://localhost:7575/v2/users/{user-id}/rights", nil)
    req.Header.Set("Authorization", "Bearer <token>")
    response, _ := http.DefaultClient.Do(req)
    defer response.Body.Close()
    body, _ := io.ReadAll(response.Body)
    fmt.Println(string(body))
  }
  ```

  ```java Java theme={"theme":{"light":"github-light","dark":"github-dark"}}
  import java.net.URI;
  import java.net.http.HttpClient;
  import java.net.http.HttpRequest;
  import java.net.http.HttpResponse;

  var request = HttpRequest.newBuilder()
      .uri(URI.create("http://localhost:7575/v2/users/{user-id}/rights"))
      .header("Authorization", "Bearer <token>")
      .method("GET", HttpRequest.BodyPublishers.noBody())
      .build();
  var response = HttpClient.newHttpClient().send(
      request, HttpResponse.BodyHandlers.ofString());
  System.out.println(response.body());
  ```

  ```ruby Ruby theme={"theme":{"light":"github-light","dark":"github-dark"}}
  require 'net/http'
  require 'uri'

  uri = URI('http://localhost:7575/v2/users/{user-id}/rights')
  request = Net::HTTP::Get.new(uri)
  request['Authorization'] = 'Bearer <token>'
  response = Net::HTTP.start(uri.hostname, uri.port) do |http|
    http.request(request)
  end
  puts response.body
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={"theme":{"light":"github-light","dark":"github-dark"}}
  {
    "rights": [
      {
        "kind": {
          "CanActAs": {
            "value": {
              "party": "<string>"
            }
          }
        }
      }
    ]
  }
  ```

  ```text 400 theme={"theme":{"light":"github-light","dark":"github-dark"}}
  <string>
  ```

  ```json default theme={"theme":{"light":"github-light","dark":"github-dark"}}
  {
    "code": "<string>",
    "cause": "<string>",
    "correlationId": "<string>",
    "traceId": "<string>",
    "context": {},
    "resources": [
      [
        "<string>"
      ]
    ],
    "errorCategory": 123,
    "grpcCodeValue": 123,
    "retryInfo": "<string>",
    "definiteAnswer": false
  }
  ```
</ResponseExample>

## Authorizations

### httpAuth

<ParamField header="Authorization" type="string" required>
  HTTP bearer authentication. Send the token as `Authorization: Bearer &lt;token&gt;`. Ledger API standard JWT token
</ParamField>

### apiKeyAuth

<ParamField header="Sec-WebSocket-Protocol" type="string" required>
  API key authentication in the header. Ledger API standard JWT token (websocket)
</ParamField>

## Path parameters

<ParamField path="user-id" type="string" required />

## Responses

### 200

<div class="x2mdx-ref-badges">
  <span class="x2mdx-ref-badge x2mdx-ref-badge--neutral">application/json</span>
</div>

<ResponseField name="rights" type="Right[]">
  All rights of the user. Optional: can be empty

  <Expandable title="child attributes">
    <ResponseField name="kind" type="Kind">
      Required

      <Expandable title="child attributes">
        <ResponseField name="Variant 1" type="object">
          <Expandable title="child attributes">
            <ResponseField name="CanActAs" type="CanActAs" required>
              <Expandable title="child attributes">
                <ResponseField name="value" type="CanActAs1" required>
                  <Expandable title="child attributes">
                    <ResponseField name="party" type="string" required>
                      The right to authorize commands for this party. Required
                    </ResponseField>
                  </Expandable>
                </ResponseField>
              </Expandable>
            </ResponseField>
          </Expandable>
        </ResponseField>

        <ResponseField name="Variant 2" type="object">
          <Expandable title="child attributes">
            <ResponseField name="CanExecuteAs" type="CanExecuteAs" required>
              <Expandable title="child attributes">
                <ResponseField name="value" type="CanExecuteAs1" required>
                  <Expandable title="child attributes">
                    <ResponseField name="party" type="string" required>
                      The right to prepare and execute submissions as this party. This right does not entitle the user to perform any reads. If reading is required, a separate ReadAs right must be added. Right to execute as a party is also implicitly contained in the CanActAs right. Required
                    </ResponseField>
                  </Expandable>
                </ResponseField>
              </Expandable>
            </ResponseField>
          </Expandable>
        </ResponseField>

        <ResponseField name="Variant 3" type="object">
          <Expandable title="child attributes">
            <ResponseField name="CanExecuteAsAnyParty" type="CanExecuteAsAnyParty" required>
              The rights of a user to prepare and execute transactions as any party. Its utility is predominantly for users that perform interactive submissions on behalf of many parties.

              <Expandable title="child attributes">
                <ResponseField name="value" type="CanExecuteAsAnyParty1" required>
                  The rights of a user to prepare and execute transactions as any party. Its utility is predominantly for users that perform interactive submissions on behalf of many parties.
                </ResponseField>
              </Expandable>
            </ResponseField>
          </Expandable>
        </ResponseField>

        <ResponseField name="Variant 4" type="object">
          <Expandable title="child attributes">
            <ResponseField name="CanReadAs" type="CanReadAs" required>
              <Expandable title="child attributes">
                <ResponseField name="value" type="CanReadAs1" required>
                  <Expandable title="child attributes">
                    <ResponseField name="party" type="string" required>
                      The right to read ledger data visible to this party. Required
                    </ResponseField>
                  </Expandable>
                </ResponseField>
              </Expandable>
            </ResponseField>
          </Expandable>
        </ResponseField>

        <ResponseField name="Variant 5" type="object">
          <Expandable title="child attributes">
            <ResponseField name="CanReadAsAnyParty" type="CanReadAsAnyParty" required>
              The rights of a participant's super reader. Its utility is predominantly for feeding external tools, such as PQS, continually without the need to change subscriptions as new parties pop in and out of existence.

              <Expandable title="child attributes">
                <ResponseField name="value" type="CanReadAsAnyParty1" required>
                  The rights of a participant's super reader. Its utility is predominantly for feeding external tools, such as PQS, continually without the need to change subscriptions as new parties pop in and out of existence.
                </ResponseField>
              </Expandable>
            </ResponseField>
          </Expandable>
        </ResponseField>

        <ResponseField name="Variant 6" type="object">
          <Expandable title="child attributes">
            <ResponseField name="Empty" type="Empty8" required />
          </Expandable>
        </ResponseField>

        <ResponseField name="Variant 7" type="object">
          <Expandable title="child attributes">
            <ResponseField name="IdentityProviderAdmin" type="IdentityProviderAdmin" required>
              The right to administer the identity provider that the user is assigned to. It means, being able to manage users and parties that are also assigned to the same identity provider.

              <Expandable title="child attributes">
                <ResponseField name="value" type="IdentityProviderAdmin1" required>
                  The right to administer the identity provider that the user is assigned to. It means, being able to manage users and parties that are also assigned to the same identity provider.
                </ResponseField>
              </Expandable>
            </ResponseField>
          </Expandable>
        </ResponseField>

        <ResponseField name="Variant 8" type="object">
          <Expandable title="child attributes">
            <ResponseField name="ParticipantAdmin" type="ParticipantAdmin" required>
              The right to administer the participant node.

              <Expandable title="child attributes">
                <ResponseField name="value" type="ParticipantAdmin1" required>
                  The right to administer the participant node.
                </ResponseField>
              </Expandable>
            </ResponseField>
          </Expandable>
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

### 400

Invalid value

<div class="x2mdx-ref-badges">
  <span class="x2mdx-ref-badge x2mdx-ref-badge--neutral">text/plain</span>
</div>

<ResponseField name="value" type="string" required />

### default

<div class="x2mdx-ref-badges">
  <span class="x2mdx-ref-badge x2mdx-ref-badge--neutral">application/json</span>
</div>

<ResponseField name="code" type="string" required />

<ResponseField name="cause" type="string" required />

<ResponseField name="correlationId" type="string" />

<ResponseField name="traceId" type="string" />

<ResponseField name="context" type="Map_String" required />

<ResponseField name="resources" type="Tuple2_String_String[]" />

<ResponseField name="errorCategory" type="integer (int32)" required />

<ResponseField name="grpcCodeValue" type="integer (int32)" />

<ResponseField name="retryInfo" type="string" />

<ResponseField name="definiteAnswer" type="boolean" />

## History

<div class="x2mdx-ref-history" aria-label="Reference history">
  <div class="x2mdx-ref-history-event x2mdx-ref-history-event--changed" id="history-updated-3-5">
    <div class="x2mdx-ref-history-event-head">
      <span class="x2mdx-ref-history-event-label">Updated</span>
      <code class="x2mdx-ref-history-event-version">3.5</code>
    </div>

    <p class="x2mdx-ref-history-event-detail">The GET /v2/users/\{user-id}/rights operation changed in this snapshot.</p>
  </div>
</div>
