curl --request GET \
--url https://api.onecli.sh/v1/policy/effective-app-permissions \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.onecli.sh/v1/policy/effective-app-permissions"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.onecli.sh/v1/policy/effective-app-permissions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.onecli.sh/v1/policy/effective-app-permissions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.onecli.sh/v1/policy/effective-app-permissions"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.onecli.sh/v1/policy/effective-app-permissions")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.onecli.sh/v1/policy/effective-app-permissions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"provider": "<string>",
"basis": {
"agentId": "<string>",
"credentialAttached": true,
"scope": "organization"
},
"variesByIdentity": 123,
"orgResources": {
"repositories": [
"<string>"
]
},
"effectiveResources": {
"repositories": [
"<string>"
]
},
"groups": [
{
"category": "read",
"verdict": "allow",
"tools": [
{
"toolId": "<string>",
"verdict": "allow",
"rateLimit": 123,
"rateLimitWindow": "<string>",
"decidedBy": {
"kind": "rule",
"scope": "organization",
"redacted": true,
"rule": {
"logicalId": "<string>",
"name": "<string>"
}
},
"orgCeiling": "allow"
}
]
}
]
}{
"error": "<string>"
}Effective app permissions (workspace)
What the enforced policy decides for every tool of one app, in this workspace: the agent’s grant composed with organization rules. Without agentId the answer is the all-agents baseline; variesByIdentity counts the identity-scoped rules it cannot show. Add connectionId to reflect one specific account as the injected connection and to get the resource boundary (orgResources, effectiveResources).
Organization rule names are visible to organization admins only; other viewers see redacted: true on the provenance.
curl --request GET \
--url https://api.onecli.sh/v1/policy/effective-app-permissions \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.onecli.sh/v1/policy/effective-app-permissions"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.onecli.sh/v1/policy/effective-app-permissions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.onecli.sh/v1/policy/effective-app-permissions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.onecli.sh/v1/policy/effective-app-permissions"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.onecli.sh/v1/policy/effective-app-permissions")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.onecli.sh/v1/policy/effective-app-permissions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"provider": "<string>",
"basis": {
"agentId": "<string>",
"credentialAttached": true,
"scope": "organization"
},
"variesByIdentity": 123,
"orgResources": {
"repositories": [
"<string>"
]
},
"effectiveResources": {
"repositories": [
"<string>"
]
},
"groups": [
{
"category": "read",
"verdict": "allow",
"tools": [
{
"toolId": "<string>",
"verdict": "allow",
"rateLimit": 123,
"rateLimitWindow": "<string>",
"decidedBy": {
"kind": "rule",
"scope": "organization",
"redacted": true,
"rule": {
"logicalId": "<string>",
"name": "<string>"
}
},
"orgCeiling": "allow"
}
]
}
]
}{
"error": "<string>"
}Authorizations
A workspace API key (oc_…) or organization API key (oc_org_…). Workspace-scoped endpoints called with an organization key also need X-Workspace-Id.
Response
The per-tool verdicts
Show child attributes
Show child attributes
Identity-scoped rules the baseline view cannot show.
The organization's resource boundary for this agent + connection. Null when the organization does not restrict, or when no agentId + connectionId basis was given.
- GitHub repositories
- Dropbox folders
- Google Drive folders
Show child attributes
Show child attributes
What the credential actually reaches — the organization boundary composed with the workspace grant's selection. An empty list means the two do not overlap.
- GitHub repositories
- Dropbox folders
- Google Drive folders
Show child attributes
Show child attributes
Show child attributes
Show child attributes