Get an authorization grant
GET /v1/access-policy/grants/{id}: Reads one live grant, or one revoked historical grant when includeRevoked is true, after requiring MANAGE_ACCESS on its policy target.
Reads one live grant, or one revoked historical grant when includeRevoked is true, after requiring MANAGE_ACCESS on its policy target.
In: header
Path Parameters
Grant UUID
Query Parameters
Include a revoked historical row
falseHeader Parameters
Optional waiting budget in milliseconds, measured from REST servlet ingress and shared across all internal gRPC calls. Supply one decimal integer from 1 to 86400000. Omission adds no deadline. Existing shorter deadlines still apply. Expiry returns HTTP 504 before streaming starts; after streaming starts, no successful completion event is sent. Use SSE or opt into GoodMem-Stream-Terminal for an explicit terminal outcome. Retrieval work is cooperatively cancelled. An accepted mutation may still commit after timeout or disconnect; a failed response does not imply rollback.
int641 <= value <= 86400000Response Body
curl -X GET "https://your-goodmem-server.example.com/v1/access-policy/grants/f276b9a4-73d6-4e04-95c5-87b974221f92?includeRevoked=true" \ -H "GoodMem-Timeout-Ms: 30000"{
"grantId": "f276b9a4-73d6-4e04-95c5-87b974221f92",
"audience": {
"principalId": "70e025f6-76ca-4cbe-b8fc-7dab8e84590a"
},
"rule": {
"operation": "CREATE_USER",
"selector": "ANY",
"assignedResource": {
"resourceId": "550e8400-e29b-41d4-a716-446655440000"
}
},
"createdAt": 0,
"createdById": "70e025f6-76ca-4cbe-b8fc-7dab8e84590a",
"revokedAt": 0,
"revokedById": "114ad558-323d-4b76-85b8-37af103b8650"
}Create an authorization grant
POST /v1/access-policy/grants: Creates one direct grant after resolving its typed policy target and requiring MANAGE_ACCESS.
Get a scoped role assignment
GET /v1/access-policy/role-assignments/{id}: Reads one live assignment, or one revoked historical assignment when includeRevoked is true, after requiring MANAGE_ACCESS on its policy target.