Skip to content

List all roles

GET/roles

Common API · Tenant role management

List all tenant roles.

Required permissionrole:read

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
type query string (enum) No Role type.
Must be one of: predefined, custom.
principalType query string (enum) No Principal type of role.
Must be one of: user, service.
fields query array of string No The fields to return in a partial response.

Request samples

curl -X GET "https://api-<data-region>.central.sophos.com/common/v1/roles" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"

import requests

response = requests.get(
    "https://api-<data-region>.central.sophos.com/common/v1/roles",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
    },
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/common/v1/roles" -Headers $headers

package main

import (
    "fmt"
    "io"
    "net/http"
)

func main() {
    req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/common/v1/roles", nil)
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/common/v1/roles", {
  method: "GET",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
  },
});
const data = await response.json();
console.log(data);

Responses

200 — List of tenant roles.

Response fields

itemsarray of objectrequired
List of roles.
Tenant role.
Show child attributesHide child attributes
idstring (uuid)required
Role UUID.
namestringrequired
Role name.
descriptionstring
Role Description.
typestring (enum)required
Role type.
Must be one of: predefined, custom.
principalTypestring (enum)required
Principal type of role.
Must be one of: user, service.
permissionSetsarray of stringrequired
List of permission sets.
Must contain at least 1 item. Items must be unique.
createdAtstring (datetime)
Date and time tenant role was created.
updatedAtstring (datetime)
Date and time tenant role was last updated.

Errors

Status Meaning
500 Internal server error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "items": [
    {
      "id": "00000000-0000-0000-0000-000000000000",
      "name": "string",
      "description": "string",
      "type": "predefined",
      "principalType": "user",
      "permissionSets": [
        "string"
      ],
      "createdAt": "string",
      "updatedAt": "string"
    }
  ]
}