Skip to main content
Pinecone Docs

Search documentation

Type to search this documentation.

List role bindings

GET/admin/role-bindingsList role bindings

List role bindings in the caller's organization, optionally filtered by principal, resource, and role.

Parameters

X-Pinecone-Api-Versionstringheaderrequired

Required date-based version header

default "2026-07"

principal_typestringquery

Filter by principal type. Required when `principal_id` is set.

principal_idstringquery

Filter by principal ID. Requires `principal_type`. The ID is a UUID for all principal types (user, service account, or invite).

resource_typestringquery

Filter by resource type. Required when `resource_id` is set.

resource_idstringquery

Filter by resource ID. Requires `resource_type`.

rolestringquery

Filter by role.

limitintegerquery

The number of results to return per page. When omitted, the server defaults to 100. Out-of-range values return `400 OUT_OF_RANGE`.

default 100 · maximum 100 · minimum 1

paginationTokenstringquery

Cursor from `pagination.next` of a prior response. Must be reused with the same query context (path parameters, filters, and `limit`).

Responses

200A paginated list of role bindings. When multiple filters are supplied, they are combined with AND.application/json
objectRoleBindingList

A paginated list of role bindings.

dataarray of objectrequired

The page of role bindings.

Show child attributes
Show array items

Grants a `role` to a `principal` at a `resource` scope.

created_atstring · date-timerequired

When the role binding was created.

idstring · uuidrequired

The unique ID of the role binding.

principal_idstringrequired

The principal's ID. A UUID for all principal types (`user`, `service_account`, `api_key`, `invite`).

principal_typestringrequired

The kind of principal that receives permissions from a role binding. Possible values: `user`, `service_account`, `api_key`, `invite`.

resource_idstringrequired

The organization or project that the binding is scoped to.

resource_typestringrequired

The kind of resource scope a role binding applies to. Possible values: `organization`, `project`.

rolestringrequired

A role assigned to a principal at a resource scope.

paginationvalue
Show child attributes
anyOf · 2 options
Option 1object

Cursor envelope for the next page. `null` (or absent) on the final page of results.

allOf · 1 option
Option 1object

Pagination metadata for list responses. When `next` is present, pass it as `paginationToken` on the following request.

nextstring

Opaque cursor for the next page. Do not parse or construct. Invalid or expired tokens return `400`.

Option 2nullnullable
Example response
{
  "data": [
    {
      "created_at": "2026-04-10T15:23:00Z",
      "id": "5a86ed21-daf1-448d-a9ca-f92a0fd839d3",
      "principal_id": "e2e92523-85dc-4142-b8c2-e681be8b78df",
      "principal_type": "user",
      "resource_id": "-ExampleOrgId0000000",
      "resource_type": "organization",
      "role": "OrgMember"
    }
  ],
  "pagination": {
    "next": "eyJsYXN0X2lkIjoiNWE4NmVkMjEifQ=="
  }
}
400Bad request. The request body included invalid request parameters.application/json
objectErrorResponse

The response shape used for all error responses.

errorobjectrequired

Detailed information about the error that occurred.

Show child attributes
codestringrequired

The error code. Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`, `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`, `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`, `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`, `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`, `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.

detailsobject

Additional information about the error. This field is not guaranteed to be present.

messagestringrequired
statusintegerrequired

The HTTP status code of the error.

Example response
{
  "error": {
    "code": "INVALID_ARGUMENT",
    "message": "Bad request. The request body included invalid request parameters."
  },
  "status": 400
}
401Unauthorized. Possible causes: Invalid API key.application/json
objectErrorResponse

The response shape used for all error responses.

errorobjectrequired

Detailed information about the error that occurred.

Show child attributes
codestringrequired

The error code. Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`, `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`, `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`, `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`, `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`, `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.

detailsobject

Additional information about the error. This field is not guaranteed to be present.

messagestringrequired
statusintegerrequired

The HTTP status code of the error.

Example response
{
  "error": {
    "code": "UNAUTHENTICATED",
    "message": "Invalid API key."
  },
  "status": 401
}
403Forbiddenapplication/json
objectErrorResponse

The response shape used for all error responses.

errorobjectrequired

Detailed information about the error that occurred.

Show child attributes
codestringrequired

The error code. Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`, `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`, `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`, `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`, `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`, `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.

detailsobject

Additional information about the error. This field is not guaranteed to be present.

messagestringrequired
statusintegerrequired

The HTTP status code of the error.

Example response
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
4XXUnexpected error on request.application/json
objectErrorResponse

The response shape used for all error responses.

errorobjectrequired

Detailed information about the error that occurred.

Show child attributes
codestringrequired

The error code. Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`, `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`, `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`, `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`, `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`, `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.

detailsobject

Additional information about the error. This field is not guaranteed to be present.

messagestringrequired
statusintegerrequired

The HTTP status code of the error.

Example response
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
500Internal server error.application/json
objectErrorResponse

The response shape used for all error responses.

errorobjectrequired

Detailed information about the error that occurred.

Show child attributes
codestringrequired

The error code. Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`, `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`, `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`, `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`, `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`, `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.

detailsobject

Additional information about the error. This field is not guaranteed to be present.

messagestringrequired
statusintegerrequired

The HTTP status code of the error.

Example response
{
  "error": {
    "code": "UNKNOWN",
    "message": "Internal server error"
  },
  "status": 500
}
Documentation menu