> ## Documentation Index
> Fetch the complete documentation index at: https://www.ravion.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Summarize what the caller may do

> For every action in the authorization catalog, whether the caller may perform it on all resources of the type, on some of them, or on none.



## OpenAPI

````yaml https://api.ravion.com/openapi.yaml get /authorization/me/permissions
openapi: 3.0.0
info:
  title: Ravion
  version: 0.0.0
servers:
  - url: https://api.ravion.com
security:
  - BearerAuth: []
tags:
  - name: Projects
  - name: Environments
  - name: FeatureFlags
  - name: Pipelines
  - name: PipelineRuns
  - name: TerraformResources
  - name: TerraformExecutionSummaries
  - name: PipelineStepExecutions
  - name: AwsCloudWatch
  - name: PipelineVersions
  - name: Organizations
  - name: Stacks
  - name: StackWorkspaces
  - name: Auth
  - name: OAuth
  - name: User
  - name: Health
  - name: Memberships
  - name: ServiceAccounts
  - name: AwsDefaultNetworks
  - name: AwsAccounts
  - name: ApiKeys
  - name: AwsAmp
  - name: EksPrometheus
  - name: EksLoki
  - name: ExecutionEnvironments
  - name: ModuleDefinitions
  - name: ModuleCategories
  - name: ModuleVersions
  - name: ModuleInstances
  - name: DefaultValueDefinitions
  - name: DefaultValues
  - name: CodeSources
  - name: Github
  - name: GitHub Actions
  - name: Gitlab
  - name: Git
  - name: Values
  - name: Deployments
  - name: DeploymentResources
  - name: InfrastructureEvents
  - name: WebSocket
  - name: Domains
  - name: AcmCertificates
  - name: Describe
  - name: Reports
  - name: BillingPlans
  - name: BillingAccounts
  - name: BillingCycles
  - name: BillingUsageSummaries
  - name: BillingAddOns
  - name: BillingInvoices
  - name: Authorization
paths:
  /authorization/me/permissions:
    get:
      tags:
        - Authorization
      summary: Summarize what the caller may do
      description: >-
        For every action in the authorization catalog, whether the caller may
        perform it on all resources of the type, on some of them, or on none.
        Needs no permission on policy and answers only about the caller. Ask
        `/authorization/check` about specific resources when the answer is
        `some`. In organizations that do not enforce authorization every answer
        is `all`.
      operationId: GetMyAuthorizationPermissions
      responses:
        '200':
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  data:
                    $ref: '#/components/schemas/AuthorizationPermissionSummary'
                required:
                  - data
                type: object
          description: The request has succeeded.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Errors.UserFacingErrorData'
          description: You are not authenticated
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Errors.UserFacingErrorData'
          description: Server error
        '503':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Errors.UserFacingErrorData'
          description: Service unavailable.
components:
  schemas:
    AuthorizationPermissionSummary:
      additionalProperties: false
      description: What the caller may do, for every action in the authorization catalog.
      properties:
        enforcing:
          description: >-
            False when the organization does not enforce authorization: every
            action is `all`.
          type: boolean
        permissions:
          items:
            $ref: '#/components/schemas/AuthorizationPermission'
          type: array
        revision:
          description: The policy revision the summary was computed at.
          format: int64
          type: integer
      required:
        - enforcing
        - revision
        - permissions
      type: object
    Errors.UserFacingErrorData:
      additionalProperties: false
      description: |-
        User-facing error presentation data.
        This is what the API returns to the frontend after formatting ErrorData
        using CEL templates from the error registry.

        Used for both:
        - Error fields on domain models (e.g., PipelineRun.error)
        - API error response bodies (HTTP 4xx/5xx responses)
      properties:
        action:
          allOf:
            - $ref: '#/components/schemas/Errors.Action'
          description: Optional action to help resolve the error
        code:
          description: Full error code, e.g., "Ravion:Pipeline:NOT_FOUND"
          type: string
        description:
          description: Additional description with more details
          type: string
        details:
          description: Structured details rendered as user-facing sections.
          items:
            $ref: '#/components/schemas/Errors.UserFacingErrorDetailSection'
          type: array
        isInternal:
          description: >-
            Indicates whether this error is internal (only set when
            ShowInternal=true).

            This allows SUPERADMINs to identify internal errors while viewing
            full details.
          type: boolean
        message:
          description: Main error message (required)
          type: string
        metadata:
          additionalProperties: {}
          description: >-
            Error params/metadata. Stripped for internal errors unless
            superadmin.
          type: object
        requestId:
          description: Request ID for correlating errors with server logs.
          type: string
      required:
        - code
        - message
      type: object
    AuthorizationPermission:
      additionalProperties: false
      description: The caller's access to one action on one resource type.
      properties:
        access:
          $ref: '#/components/schemas/AuthorizationPermissionAccess'
        action:
          description: Action from the authorization catalog.
          type: string
        type:
          description: Resource type from the authorization catalog.
          type: string
      required:
        - type
        - action
        - access
      type: object
    Errors.Action:
      additionalProperties: false
      description: Action to help user resolve the error
      properties:
        label:
          description: Button/link label text
          type: string
        url:
          description: URL to navigate to for resolution
          type: string
      required:
        - label
        - url
      type: object
    Errors.UserFacingErrorDetailSection:
      additionalProperties: false
      description: Structured user-facing error detail section.
      properties:
        items:
          description: List of detail values for this section.
          items:
            type: string
          type: array
        object:
          additionalProperties: {}
          description: Structured detail payload for object rendering.
          type: object
        render:
          description: Rendering hint for clients. Valid values are list or object.
          type: string
        title:
          description: Detail section title shown in the UI.
          type: string
      required:
        - title
        - render
      type: object
    AuthorizationPermissionAccess:
      description: >-
        How much of a resource type the caller may act on: `all` resources of
        the

        type, `some` (it depends on the resource, so ask
        `/authorization/check`), or

        `none`.
      enum:
        - all
        - some
        - none
      type: string
  securitySchemes:
    BearerAuth:
      scheme: Bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.