FruxonDocs
AgentsCore

Returns the calling user's effective role on the agent.

The role resolves through the agent's owning Application, unioned with any legacy per-agent grant and with tenant-admin status. `role` is null when the caller has no access; the `canView` / `canEdit` / `canManage` flags project that role onto the permission ladder so clients do not reimplement it. Deliberately **not** 403 on denial — "you have no access" is an answer this endpoint has to be able to give, so an agent the caller cannot reach is a 200 with a null role. Only an agent that does not exist is a 404. Soft-deleted agents still resolve during their grace period.

GET
/v1/tenants/{tenant}/agents/{agent}/access
AuthorizationBearer <token>

JWT Authorization header using the Bearer scheme. Enter 'Bearer' [space] and then your token.

In: header

Path Parameters

agent*string

The agent ID.

tenant*string

The tenant identifier

Response Body

curl -X GET "https://api.fruxon.com/v1/tenants/string/agents/string/access"
{
  "role": "VIEWER",
  "canView": false,
  "canEdit": false,
  "canManage": false,
  "applicationId": "00000000-0000-0000-0000-000000000000",
  "requestPending": false
}
Empty
Empty
{
  "type": "string",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "property1": null,
  "property2": null
}