CloudTruth Grants API

The grants API from CloudTruth — 3 operation(s) for grants.

Operations 7

GET /api/v1/grants/ Grants list #
POST /api/v1/grants/ Grants create #
GET /api/v1/grants/{id}/ Grants retrieve #
PUT /api/v1/grants/{id}/ Grants update #
PATCH /api/v1/grants/{id}/ Grants partial update #
DELETE /api/v1/grants/{id}/ Grants destroy #
DELETE /api/v1/grants/multi/ Grants multi destroy #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cloudtruth:cloudtruth-grants-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cloudtruth-grants-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: CloudTruth Management Grants API
  version: v1
  description: CloudTruth centralizes your configuration parameters and secrets making them easier to manage and use as a team.
  contact:
    name: CloudTruth Support
    email: support@cloudtruth.com
tags:
- name: Grants
paths:
  /api/v1/grants/:
    get:
      operationId: grants_list
      description: 'Grants allow you to enable access control on Environments and Projects.


        Grants are part of the role-based access control feature set, so

        if your subscription does not have support for it, these paths

        will return a 403 Forbidden error.'
      parameters:
      - name: ordering
        required: false
        in: query
        description: Which field to use when ordering the results.
        schema:
          type: string
      - name: page
        required: false
        in: query
        description: A page number within the paginated result set.
        schema:
          type: integer
      - name: page_size
        required: false
        in: query
        description: Number of results to return per page.
        schema:
          type: integer
      - in: query
        name: principal
        schema:
          type: string
          format: uri
        description: Filter by principal (User, Group). Returns direct grant assignments, not indirect (user via group).
      - in: query
        name: role
        schema:
          type: string
          enum:
          - ADMIN
          - CONTRIB
          - NO_SECRETS
          - OWNER
          - VIEWER
        description: 'Filter by role.


          * `OWNER` - Owner

          * `ADMIN` - Administrator

          * `CONTRIB` - Contributor

          * `VIEWER` - Viewer

          * `NO_SECRETS` - NoSecretsViewer'
      - in: query
        name: scope
        schema:
          type: string
          format: uri
        description: Filter by grant scope (Environment, Project).
      tags:
      - Grants
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedGrantList'
          description: ''
        '403':
          description: 'Forbidden: see response for further details.'
      summary: Grants list
      x-summary-source: derived
    post:
      operationId: grants_create
      description: 'Grants allow you to enable access control on Environments and Projects.


        Grants are part of the role-based access control feature set, so

        if your subscription does not have support for it, these paths

        will return a 403 Forbidden error.'
      tags:
      - Grants
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Grant'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/Grant'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/Grant'
        required: true
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Grant'
          description: ''
        '403':
          description: 'Forbidden: see response for further details.'
      summary: Grants create
      x-summary-source: derived
  /api/v1/grants/{id}/:
    get:
      operationId: grants_retrieve
      description: 'Grants allow you to enable access control on Environments and Projects.


        Grants are part of the role-based access control feature set, so

        if your subscription does not have support for it, these paths

        will return a 403 Forbidden error.'
      parameters:
      - in: path
        name: id
        schema:
          type: string
          format: uuid
          description: A unique identifier for the grant.
        required: true
      tags:
      - Grants
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Grant'
          description: ''
        '403':
          description: 'Forbidden: see response for further details.'
      summary: Grants retrieve
      x-summary-source: derived
    put:
      operationId: grants_update
      description: 'Grants allow you to enable access control on Environments and Projects.


        Grants are part of the role-based access control feature set, so

        if your subscription does not have support for it, these paths

        will return a 403 Forbidden error.'
      parameters:
      - in: path
        name: id
        schema:
          type: string
          format: uuid
          description: A unique identifier for the grant.
        required: true
      tags:
      - Grants
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/GrantUpdate'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/GrantUpdate'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/GrantUpdate'
        required: true
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Grant'
          description: ''
        '403':
          description: 'Forbidden: see response for further details.'
      summary: Grants update
      x-summary-source: derived
    patch:
      operationId: grants_partial_update
      description: 'Grants allow you to enable access control on Environments and Projects.


        Grants are part of the role-based access control feature set, so

        if your subscription does not have support for it, these paths

        will return a 403 Forbidden error.'
      parameters:
      - in: path
        name: id
        schema:
          type: string
          format: uuid
          description: A unique identifier for the grant.
        required: true
      tags:
      - Grants
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PatchedGrantUpdate'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/PatchedGrantUpdate'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/PatchedGrantUpdate'
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Grant'
          description: ''
        '403':
          description: 'Forbidden: see response for further details.'
      summary: Grants partial update
      x-summary-source: derived
    delete:
      operationId: grants_destroy
      description: 'Grants allow you to enable access control on Environments and Projects.


        Grants are part of the role-based access control feature set, so

        if your subscription does not have support for it, these paths

        will return a 403 Forbidden error.'
      parameters:
      - in: path
        name: id
        schema:
          type: string
          format: uuid
          description: A unique identifier for the grant.
        required: true
      tags:
      - Grants
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '204':
          description: Deleted.
        '403':
          description: 'Forbidden: see response for further details.'
      summary: Grants destroy
      x-summary-source: derived
  /api/v1/grants/multi/:
    delete:
      operationId: grants_multi_destroy
      description: 'Removes grants matching the query parameters atomically.


        Use this technique to disable access control on a scope,

        or remove all grants for a user.'
      tags:
      - Grants
      security:
      - JWTAuth: []
      - ApiKeyAuth: []
      - tokenAuth: []
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Grant'
          description: ''
        '403':
          description: 'Forbidden: see response for further details.'
      summary: Grants multi destroy
      x-summary-source: derived
components:
  schemas:
    PatchedGrantUpdate:
      type: object
      properties:
        url:
          type: string
          format: uri
          readOnly: true
        id:
          type: string
          format: uuid
          readOnly: true
          description: A unique identifier for the grant.
        principal:
          type: string
          format: uri
          description: The URI of a principal for the grant; this must reference a user or group.
        scope:
          type: string
          format: uri
          description: The URI of a scope for the grant; this must reference a project or environment.
        role:
          allOf:
          - $ref: '#/components/schemas/RoleEnum'
          description: 'The role that the principal has in the given scope.


            * `OWNER` - Owner

            * `ADMIN` - Administrator

            * `CONTRIB` - Contributor

            * `VIEWER` - Viewer

            * `NO_SECRETS` - NoSecretsViewer'
        created_at:
          type: string
          format: date-time
          readOnly: true
        modified_at:
          type:
          - string
          - 'null'
          format: date-time
          readOnly: true
    RoleEnum:
      enum:
      - OWNER
      - ADMIN
      - CONTRIB
      - VIEWER
      - NO_SECRETS
      type: string
      description: '* `OWNER` - Owner

        * `ADMIN` - Administrator

        * `CONTRIB` - Contributor

        * `VIEWER` - Viewer

        * `NO_SECRETS` - NoSecretsViewer'
    GrantUpdate:
      type: object
      properties:
        url:
          type: string
          format: uri
          readOnly: true
        id:
          type: string
          format: uuid
          readOnly: true
          description: A unique identifier for the grant.
        principal:
          type: string
          format: uri
          description: The URI of a principal for the grant; this must reference a user or group.
        scope:
          type: string
          format: uri
          description: The URI of a scope for the grant; this must reference a project or environment.
        role:
          allOf:
          - $ref: '#/components/schemas/RoleEnum'
          description: 'The role that the principal has in the given scope.


            * `OWNER` - Owner

            * `ADMIN` - Administrator

            * `CONTRIB` - Contributor

            * `VIEWER` - Viewer

            * `NO_SECRETS` - NoSecretsViewer'
        created_at:
          type: string
          format: date-time
          readOnly: true
        modified_at:
          type:
          - string
          - 'null'
          format: date-time
          readOnly: true
      required:
      - created_at
      - id
      - modified_at
      - principal
      - role
      - scope
      - url
    Grant:
      type: object
      properties:
        url:
          type: string
          format: uri
          readOnly: true
        id:
          type: string
          format: uuid
          readOnly: true
          description: A unique identifier for the grant.
        principal:
          type: string
          format: uri
          description: The URI of a principal for the grant; this must reference a user or group.
        scope:
          type: string
          format: uri
          description: The URI of a scope for the grant; this must reference a project or environment.
        role:
          allOf:
          - $ref: '#/components/schemas/RoleEnum'
          description: 'The role that the principal has in the given scope.


            * `OWNER` - Owner

            * `ADMIN` - Administrator

            * `CONTRIB` - Contributor

            * `VIEWER` - Viewer

            * `NO_SECRETS` - NoSecretsViewer'
        created_at:
          type: string
          format: date-time
          readOnly: true
        modified_at:
          type:
          - string
          - 'null'
          format: date-time
          readOnly: true
      required:
      - created_at
      - id
      - modified_at
      - principal
      - role
      - scope
      - url
    PaginatedGrantList:
      type: object
      required:
      - count
      - results
      properties:
        count:
          type: integer
          example: 123
        next:
          type:
          - string
          - 'null'
          format: uri
          example: http://api.example.org/accounts/?page=4
        previous:
          type:
          - string
          - 'null'
          format: uri
          example: http://api.example.org/accounts/?page=2
        results:
          type: array
          items:
            $ref: '#/components/schemas/Grant'
  securitySchemes:
    ApiKeyAuth:
      in: header
      name: Authorization
      type: apiKey
      description: "\nUse your CloudTruth API Key to authenticate to the API.  You can get\nan API Key by creating a Service Account.  During setup of the Service\nAccount you will generate a long-lived API key intended for use by automation\nand API clients.  Access through the service account will be audited separately\nfrom any other user.\n\nIf you are just trying to use the API in a normal workflow, this is likely the\nauthentication mechanism you want to use.\n\nTo use the API Key, place your API Key in the Authorization header as 'Api-Key APIKEY', where\nAPIKEY is your CloudTruth API Key.  For example:\n\n    Authorization: Api-Key fskur.ghlsiudhrg84so938r5u\n        "
    JWTAuth:
      in: header
      name: Authorization
      type: apiKey
      description: "\nUse your JWT to authenticate to the API.  This is how the CloudTruth\nWeb UI authenticates to the backend.  It requires a user to have already logged in\nand gotten a JWT from the login process.  This is usually done by an Auth0 authentication\nflow from one of the Auth0 javascript libraries.  Alternatively, you can pull the\nJWT from your browser if you have a logged in session with the CloudTruth UI.\n\nThis authentication mechanism is intended for deeper integrations into the CloudTruth\nsystem, where you want to handle the user logins directly in your application.  For\nnormal API use, you likely want the Api-Key authentication header and not this one.\n\nTo use the JWT, place your JWT in the Authorization header as 'Bearer JWT', where\nJWT is your JWT.  For example:\n\n    Authorization: Bearer eyJhbGciOiJIkuydfy.eyJzdWIiOiIxMjM....\n        "
    tokenAuth:
      type: http
      scheme: bearer
externalDocs:
  url: https://docs.cloudtruth.com/