Skip to main content
Pinecone Docs
current

Search documentation

Type to search this documentation.

List role bindings

List role bindings in the caller's organization, optionally filtered by principal, resource, and role.

GET/admin/role-bindings

List role bindings

8 parameters
  • X-Pinecone-Api-Versionstringheaderrequired

    Required date-based version header

  • principal_typestringquery

    Filter by principal type. Required when `principal_id` is set.

  • principal_idstringquery

    Filter by principal ID. Requires `principal_type`. The ID is a UUID for all principal types (user, service account, or invite).

  • resource_typestringquery

    Filter by resource type. Required when `resource_id` is set.

  • resource_idstringquery

    Filter by resource ID. Requires `resource_type`.

  • rolestringquery

    Filter by role.

  • limitintegerquery

    The number of results to return per page. When omitted, the server defaults to 100. Out-of-range values return `400 OUT_OF_RANGE`.

  • paginationTokenstringquery

    Cursor from `pagination.next` of a prior response. Must be reused with the same query context (path parameters, filters, and `limit`).

cURL
curl --request GET \
  --url https://api.pinecone.io/admin/role-bindings \
  --header 'Authorization: Bearer <token>' \
  --header 'X-Pinecone-Api-Version: <x-pinecone-api-version>'
Python
import requests

url = "https://api.pinecone.io/admin/role-bindings"

headers = {
    "Authorization": "Bearer <token>",
    "X-Pinecone-Api-Version": "<x-pinecone-api-version>"
}

response = requests.get(url, headers=headers)

print(response.text)
JavaScript
const options = {method: "GET", headers: {"Authorization": "Bearer <token>", "X-Pinecone-Api-Version": "<x-pinecone-api-version>"}};

fetch("https://api.pinecone.io/admin/role-bindings", options)
  .then(res => res.json())
  .then(res => console.log(res))
  .catch(err => console.error(err));
PHP
<?php

$curl = curl_init();

curl_setopt_array($curl, [
  CURLOPT_URL => "https://api.pinecone.io/admin/role-bindings",
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_CUSTOMREQUEST => "GET",
  CURLOPT_HTTPHEADER => [
    "Authorization: Bearer <token>",
    "X-Pinecone-Api-Version: <x-pinecone-api-version>"
  ],
]);

$response = curl_exec($curl);
$err = curl_error($curl);

curl_close($curl);

if ($err) {
  echo "cURL Error #:" . $err;
} else {
  echo $response;
}
Go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.pinecone.io/admin/role-bindings"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("X-Pinecone-Api-Version", "<x-pinecone-api-version>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(string(body))

}
Java
HttpResponse<String> response = Unirest.get("https://api.pinecone.io/admin/role-bindings")
  .header("Authorization", "Bearer <token>")
  .header("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
  .asString();
Ruby
require 'uri'
require 'net/http'

url = URI("https://api.pinecone.io/admin/role-bindings")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
request["X-Pinecone-Api-Version"] = '<x-pinecone-api-version>'

response = http.request(request)
puts response.read_body
200
{
  "data": [
    {
      "created_at": "2026-04-10T15:23:00.000Z",
      "id": "5a86ed21-daf1-448d-a9ca-f92a0fd839d3",
      "principal_id": "e2e92523-85dc-4142-b8c2-e681be8b78df",
      "principal_type": "user",
      "resource_id": "-ExampleOrgId0000000",
      "resource_type": "organization",
      "role": "OrgMember"
    }
  ],
  "pagination": {
    "next": "eyJsYXN0X2lkIjoiNWE4NmVkMjEifQ=="
  }
}
400
{
  "error": {
    "code": "INVALID_ARGUMENT",
    "message": "Bad request. The request body included invalid request parameters."
  },
  "status": 400
}
401
{
  "error": {
    "code": "UNAUTHENTICATED",
    "message": "Invalid API key."
  },
  "status": 401
}
403
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
500
{
  "error": {
    "code": "UNKNOWN",
    "message": "Internal server error"
  },
  "status": 500
}
4XX
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
Authorizationstringrequired

An access token must be provided in the Authorization header using the Bearer scheme.

X-Pinecone-Api-Versionstringrequired

Required date-based version header

Typestring
Default2026-07
principal_type?string

Filter by principal type. Required when principal_id is set.

Example: service_account

Typestring
principal_id?string

Filter by principal ID. Requires principal_type. The ID is a UUID for all principal types (user, service account, or invite).

Typestring
resource_type?string

Filter by resource type. Required when resource_id is set.

Example: project

Typestring
resource_id?string

Filter by resource ID. Requires resource_type.

Typestring
role?string

Filter by role.

Example: ProjectOwner

Typestring
limit?integer

The number of results to return per page. When omitted, the server defaults to 100. Out-of-range values return 400 OUT_OF_RANGE.

Required range: 1 <= x <= 100

Typeinteger
Default100
paginationToken?string

Cursor from pagination.next of a prior response. Must be reused with the same query context (path parameters, filters, and limit).

Typestring

200 — A paginated list of role bindings. When multiple filters are supplied, they are combined with AND.

A paginated list of role bindings.

dataobject[]required

The page of role bindings.

Typeobject[]
Show child attributes
idstringrequired

The unique ID of the role binding.

Typestring
principal_typestringrequired

The kind of principal that receives permissions from a role binding. Possible values: user, service_account, api_key, invite.

Example: service_account

Typestring
principal_idstringrequired

The principal's ID. A UUID for all principal types (user, service_account, api_key, invite).

Example: e2e92523-85dc-4142-b8c2-e681be8b78df

Typestring
resource_typestringrequired

The kind of resource scope a role binding applies to. Possible values: organization, project.

Example: project

Typestring
resource_idstringrequired

The organization or project that the binding is scoped to.

Typestring
rolestringrequired

A role assigned to a principal at a resource scope.

Example: ProjectOwner

Typestring
created_atstringrequired

When the role binding was created.

Typestring
pagination?object | null

Cursor envelope for the next page. null (or absent) on the final page of results.

Typeobject | null
Show child attributes
next?string

Opaque cursor for the next page. Do not parse or construct. Invalid or expired tokens return 400.

Example: eyJsYXN0X2lkIjogImluZGV4LTQifQ==

Typestring
Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu