List configurable permissions
Stable permission IDs match Swagger operationId values. Each entry includes its API paths, HTTP methods, group and default roles. Public and self-only APIs cannot be delegated through this catalogue. Company permission: `listCompanyPermissions`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
OK
*/*- response
[index: integer]?curl -X GET 'https://api.monetaryai.uz/api/v1/settings/permissions'[ { "defaultRoles": [ "string" ], "documented": true, "group": "string", "id": "string", "methods": [ "string" ], "name": "string", "paths": [ "string" ] }]Read current effective API access GET
Returns the caller's live permission IDs for menu and action visibility. Does not expose other members, grant authority or replace server-side authorization. Own-profile, session and preference APIs remain independently self-scoped.
List the four company default roles GET
Always returns ADMIN, ACCOUNTANT, MANAGER and EMPLOYEE with effective permission IDs and optimistic lock versions. Permission customization is isolated to the signed tenant. Company permission: `listCompanyRoles`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.