Read current effective API access
Returns the caller's live permission IDs for menu and action visibility. Does not expose other members, grant authority or replace server-side authorization. Own-profile, session and preference APIs remain independently self-scoped.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
OK
*/*- response
membershipId?stringuuidpermissions?array<string>roles?array<string>curl -X GET 'https://api.monetaryai.uz/api/v1/settings/access'{ "membershipId": "8072cc74-4782-4f2c-827c-699c48ce2092", "permissions": [ "string" ], "roles": [ "string" ]}Remove a user from this company DELETE
Soft deletion ends this membership and revokes its grants and sessions. The global identity, other companies and historical documents/audit remain intact. Ended memberships cannot be edited or reactivated by the settings API. Supply the last read lockVersion as a query parameter. Company permission: `deleteCompanyUser`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.
List configurable permissions GET
Stable permission IDs match Swagger operationId values. Each entry includes its API paths, HTTP methods, group and default roles. Public and self-only APIs cannot be delegated through this catalogue. Company permission: `listCompanyPermissions`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.