List role bindings
List role bindings in the caller's organization, optionally filtered by principal, resource, and role.
/admin/role-bindingsList role bindings
8 parameters
- X-Pinecone-Api-Versionstringheaderrequired
Required date-based version header
- principal_typestringquery
Filter by principal type. Required when `principal_id` is set.
- principal_idstringquery
Filter by principal ID. Requires `principal_type`. The ID is a UUID for all principal types (user, service account, or invite).
- resource_typestringquery
Filter by resource type. Required when `resource_id` is set.
- resource_idstringquery
Filter by resource ID. Requires `resource_type`.
- rolestringquery
Filter by role.
- limitintegerquery
The number of results to return per page. When omitted, the server defaults to 100. Out-of-range values return `400 OUT_OF_RANGE`.
- paginationTokenstringquery
Cursor from `pagination.next` of a prior response. Must be reused with the same query context (path parameters, filters, and `limit`).
curl --request GET \
--url https://api.pinecone.io/admin/role-bindings \
--header 'Authorization: Bearer <token>' \
--header 'X-Pinecone-Api-Version: <x-pinecone-api-version>'import requests
url = "https://api.pinecone.io/admin/role-bindings"
headers = {
"Authorization": "Bearer <token>",
"X-Pinecone-Api-Version": "<x-pinecone-api-version>"
}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: "GET", headers: {"Authorization": "Bearer <token>", "X-Pinecone-Api-Version": "<x-pinecone-api-version>"}};
fetch("https://api.pinecone.io/admin/role-bindings", options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.pinecone.io/admin/role-bindings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"X-Pinecone-Api-Version: <x-pinecone-api-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.pinecone.io/admin/role-bindings"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.pinecone.io/admin/role-bindings")
.header("Authorization", "Bearer <token>")
.header("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.pinecone.io/admin/role-bindings")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
request["X-Pinecone-Api-Version"] = '<x-pinecone-api-version>'
response = http.request(request)
puts response.read_body{
"data": [
{
"created_at": "2026-04-10T15:23:00.000Z",
"id": "5a86ed21-daf1-448d-a9ca-f92a0fd839d3",
"principal_id": "e2e92523-85dc-4142-b8c2-e681be8b78df",
"principal_type": "user",
"resource_id": "-ExampleOrgId0000000",
"resource_type": "organization",
"role": "OrgMember"
}
],
"pagination": {
"next": "eyJsYXN0X2lkIjoiNWE4NmVkMjEifQ=="
}
}{
"error": {
"code": "INVALID_ARGUMENT",
"message": "Bad request. The request body included invalid request parameters."
},
"status": 400
}{
"error": {
"code": "UNAUTHENTICATED",
"message": "Invalid API key."
},
"status": 401
}{
"error": {
"code": "QUOTA_EXCEEDED",
"message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
},
"status": 429
}{
"error": {
"code": "UNKNOWN",
"message": "Internal server error"
},
"status": 500
}{
"error": {
"code": "QUOTA_EXCEEDED",
"message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
},
"status": 429
}Authorizations
Section titled “Authorizations”AuthorizationstringrequiredAn access token must be provided in the Authorization header using the Bearer scheme.
Headers
Section titled “Headers”X-Pinecone-Api-VersionstringrequiredRequired date-based version header
Query Parameters
Section titled “Query Parameters”principal_type?stringFilter by principal type. Required when principal_id is set.
Example: service_account
principal_id?stringFilter by principal ID. Requires principal_type. The ID is a UUID for all principal types (user, service account, or invite).
resource_type?stringFilter by resource type. Required when resource_id is set.
Example: project
resource_id?stringFilter by resource ID. Requires resource_type.
role?stringFilter by role.
Example: ProjectOwner
limit?integerThe number of results to return per page. When omitted, the server defaults to 100. Out-of-range values return 400 OUT_OF_RANGE.
Required range: 1 <= x <= 100
paginationToken?stringCursor from pagination.next of a prior response. Must be reused with the same query context (path parameters, filters, and limit).
Response
Section titled “Response”200 — A paginated list of role bindings. When multiple filters are supplied, they are combined with AND.
A paginated list of role bindings.
dataobject[]requiredThe page of role bindings.
Show child attributes
idstringrequiredThe unique ID of the role binding.
principal_typestringrequiredThe kind of principal that receives permissions from a role binding. Possible values: user, service_account, api_key, invite.
Example: service_account
principal_idstringrequiredThe principal's ID. A UUID for all principal types (user, service_account, api_key, invite).
Example: e2e92523-85dc-4142-b8c2-e681be8b78df
resource_typestringrequiredThe kind of resource scope a role binding applies to. Possible values: organization, project.
Example: project
resource_idstringrequiredThe organization or project that the binding is scoped to.
rolestringrequiredA role assigned to a principal at a resource scope.
Example: ProjectOwner
created_atstringrequiredWhen the role binding was created.
pagination?object | nullCursor envelope for the next page. null (or absent) on the final page of results.
Show child attributes
next?stringOpaque cursor for the next page. Do not parse or construct. Invalid or expired tokens return 400.
Example: eyJsYXN0X2lkIjogImluZGV4LTQifQ==