Skip to main content

AssetPrincipalPermissionsGet

One principal's permission entry on the asset domain, as listed by GET /twins/permissions and returned by the mutation endpoints.

The etag is customer-wide rather than per principal, so every entry in a listing carries the same value and a write by any administrator invalidates the one every other administrator is holding.

Index

Properties

optionaletag

etag?: string

Optimistic concurrency token, to send back on the next mutation. It is customer-wide rather than per principal, so any administrator's write invalidates the value every other one holds.

Because it belongs to the domain rather than to the principal, a revocation answers with one too, even though the revoked principal no longer has a listing entry — so a caller may chain another write straight after a deleteAssetPermissions without re-reading the listing.

Absent only before the domain has been provisioned for the customer.

id

id: string

Global id of the principal (a group; users are not grantable).

name

name: string

The principal's display name.

permissions

permissions: TwinCapabilityName[]

The capabilities this principal holds on the domain. Empty after a full revoke.

readOnly

readOnly: boolean

True exactly when a PUT or DELETE naming this principal would be refused with SystemPrincipalImmutable: the seeded default groups. Render the control as disabled rather than discovering the constraint by attempting a write. False for everything else, the all-authenticated principal included, whose capabilities are mutable.

Page Options