---
title: "Retrieve the access rights of a user"
url: "https://dev.developer-internal.sanofi.com/apis/plta-permissions-api-cbz/versions/88cdfef8-3b56-44ca-883d-5b15378e5a3a/operations/retrieveUserAccessRights"
---

> Full API specification: https://dev.developer-internal.sanofi.com/apis/plta-permissions-api-cbz/versions/88cdfef8-3b56-44ca-883d-5b15378e5a3a.md

# Retrieve the access rights of a user

`GET` `/users/{userId}/accessRights`

Operation ID: `retrieveUserAccessRights`

Retrieve the access rights of a user, held either directly or through role membership. An access right is a combination of an Action (with its hierarchy) and a Resource.

## Path parameters

- `userId` (string, required) - The id of the user, as stored in IDP. For Sanofi internal user, it would be the oid (Unique identifier of the user in Azure AD)

## Responses

- `200` - Success
- `204` - Empty
- `401` - Unauthorized
- `403` - Forbidden
- `404` - Not Found
- `500` - Internal Server Error

## OpenAPI definition

```yaml
openapi: 3.1.0
info:
  title: Permission Administration API
  version: 1.5.0
servers:
  - url: https://dev.api.sanofi.com/permissions
paths:
  /users/{userId}/accessRights:
    parameters:
      - description: The id of the user, as stored in IDP. For Sanofi internal user, it
          would be the oid (Unique identifier of the user in Azure AD)
        in: path
        name: userId
        required: true
        schema:
          type: string
    get:
      description: Retrieve the access rights of a user, held either directly or
        through role membership. An access right is a combination of an Action
        (with its hierarchy) and a Resource.
      operationId: retrieveUserAccessRights
      responses:
        "200":
          content:
            application/json:
              schema:
                items:
                  $ref: "#/components/schemas/SourcedAccessRight"
                type: array
          description: Success
        "204":
          description: Empty
        "401":
          $ref: "#/components/responses/401"
        "403":
          $ref: "#/components/responses/403"
        "404":
          $ref: "#/components/responses/404"
        "500":
          $ref: "#/components/responses/500"
      summary: Retrieve the access rights of a user
      tags:
        - Access Rights
security:
  - oauth: []
components:
  schemas:
    SourcedAccessRight:
      description: An access right, tagged with where it comes from - held directly by
        the user, or inherited through membership of a role.
      properties:
        actionName:
          description: Name of the action.
          examples:
            - read_narrative
            - write_compound
          type: string
        resourceName:
          description: Name of the resource.
          examples:
            - compound_1245
          type: string
        source:
          description: Where this access right comes from. "DIRECT" if held directly by
            the user, or "ROLE#<roleName>" if inherited through membership of
            that role.
          examples:
            - DIRECT
            - ROLE#clintrials:study-reader
          readOnly: true
          type: string
        userId:
          description: The id of the user, as stored in IDP. For Sanofi internal user, it
            would be the oid (Unique identifier of the user in Azure AD). Always
            equal to the userId path parameter.
          readOnly: true
          type: string
      required:
        - actionName
        - resourceName
        - userId
        - source
      type: object
    UnauthorizedError:
      properties:
        debugId:
          description: A unique request identifier for correlation purposes.
          example: 00-0af7651916cd43dd8448eb211c80319c-00f067aa0ba902b7-01
          type: string
        detail:
          description: Error detail
          enum:
            - You are not authorized to access this resource
          type: string
        status:
          description: HTTP status code
          enum:
            - 401
          type: number
        title:
          description: Human-readable identifier
          enum:
            - Unauthorized
          type: string
        type:
          description: URI that identifies the type of error that occurred
          example: https://backstage.prod.accelerator.sanofi/docs/default/component/sanofi-accelerator-api-rules/errors-unauthorized
          type: string
      required:
        - type
        - title
        - status
        - debugId
        - detail
      type: object
    ForbiddenError:
      properties:
        debugId:
          description: A unique request identifier for correlation purposes.
          example: 00-0af7651916cd43dd8448eb211c80319c-00f067aa0ba902b7-01
          type: string
        detail:
          description: Error detail
          enum:
            - You don't have the permission to access this resource
          type: string
        status:
          description: HTTP status code
          enum:
            - 403
          type: number
        title:
          description: Human-readable identifier
          enum:
            - Forbidden
          type: string
        type:
          description: URI that identifies the type of error that occurred
          example: https://backstage.prod.accelerator.sanofi/docs/default/component/sanofi-accelerator-api-rules/errors-forbidden
          type: string
      required:
        - type
        - title
        - status
        - debugId
        - detail
      type: object
    NotFoundError:
      properties:
        debugId:
          description: A unique request identifier for correlation purposes.
          example: 00-0af7651916cd43dd8448eb211c80319c-00f067aa0ba902b7-01
          type: string
        detail:
          description: Error detail
          type: string
        status:
          description: HTTP status code
          enum:
            - 404
          type: number
        title:
          description: Human-readable identifier
          enum:
            - Not Found
          type: string
        type:
          description: URI that identifies the type of error that occurred
          example: https://backstage.prod.accelerator.sanofi/docs/default/component/sanofi-accelerator-api-rules/errors-not-found
          type: string
      required:
        - type
        - title
        - status
        - debugId
        - detail
      type: object
    InternalServerError:
      description: Object describing the error format expected in API responses. Based
        on [RFC 9457](https://datatracker.ietf.org/doc/html/rfc9457)
      properties:
        debugId:
          description: A unique request identifier for correlation purposes. [Trace
            Context RFC](https://www.w3.org/TR/trace-context/)
          example: 00-0af7651916cd43dd8448eb211c80319c-00f067aa0ba902b7-01
          type: string
        detail:
          description: More information about the specific problem, and if it's
            appropriate also steps to correct it. For example information about
            a form validation problem
          example: The service is currently unavailable due to an unexpected error
          type: string
        status:
          description: HTTP status code
          example: 500
          type: number
        title:
          description: Human-readable identifier, usually the same type field should have
            the same title field
          example: Internal Server Error
          type: string
        type:
          description: URI that identifies the type of error that occured
          example: https://backstage.prod.accelerator.sanofi/docs/default/component/sanofi-accelerator-api-rules/errors-internal/
          type: string
      required:
        - type
        - title
        - status
        - debugId
        - detail
      type: object
  responses:
    "401":
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/UnauthorizedError"
      description: Unauthorized
    "403":
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/ForbiddenError"
      description: Forbidden
    "404":
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/NotFoundError"
      description: Not Found
    "500":
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/InternalServerError"
      description: Internal Server Error
  securitySchemes:
    oauth:
      bearerFormat: JWT
      scheme: bearer
      type: http
```
