GET | List all access policies

Prev Next

Description

List the access policies available to your authorization in PAM Core. Returns a paginated, filterable projection of the entity.

This endpoint returns a reduced set of fields for each policy enough to identify and filter it. To retrieve the full configuration of a single policy, including its password, session, approver, criteria, and access limitation settings, access GET | List an access policy by [id].


Prerequisites

Info

An access token carries only the authorizations that existed when it was generated. After the administrator enables Access Policy (V2), generate a new token for the application an existing token won't gain the new authorization.


Request

GET /api/v2/pam/access-policies

Query parameters

All query parameters are optional. When no parameters are provided, the endpoint returns the access policies accessible to the authorization, using the fields shown in the response example.

Filters

Field Type Description
name string Filters by policy name. Matches the name exactly.
active boolean Filters by active status. Accepted values: true, false.
search string Searches across the name and description fields.

Sorting

Field Type Description
sort_by string Sorts the result set in the format field:asc or field:desc. Example: sort_by=name:asc.

For full sorting rules, access API v2 - Conventions and shared behaviors.

Pagination

Field Type Description
page integer Page number. Default: 1.
limit integer Results per page. Default: 50.

For full pagination rules, access API v2 - Conventions and shared behaviors.

Field projection

Field Type Description
fields string Restricts the response to the listed fields. Supports every field available in the list and detail representations.

For the full field projection syntax, access API v2 - Conventions and shared behaviors.


Example request

GET {{url}}/api/v2/pam/access-policies?page=1&limit=50&active=true


Response

HTTP/1.1 200 OK

Example response body

{
    "data": [
        {
            "id": 3001,
            "access_policy": {
                "name": "PAM Administrators",
                "active": true,
                "description": "Full access for PAM admins."
            }
        },
        {
            "id": 3002,
            "access_policy": {
                "name": "SOC Analysts",
                "active": true,
                "description": "Read-only access for SOC."
            }
        }
    ],
    "meta": {
        "pagination": {
            "page": 1,
            "limit": 50,
            "total_items": 2,
            "total_pages": 1
        },
        "links": {
            "self": "/api/v2/pam/access-policies?page=1&limit=50&active=true"
        }
    }
}

Response body fields

Field Type Description
data array of objects List of access policies matching the request filters.
data[].id integer Unique identification code of the access policy, assigned by Segura® in POST | Create access policy.
data[].access_policy object Core attributes of the access policy.
data[].access_policy.name string Name of the access policy.
data[].access_policy.active boolean Indicates whether the policy is active.
data[].access_policy.description string Description of the access policy. Returns null when not provided.
meta object Pagination metadata and navigation links.
meta.pagination object Pagination details for the current result set.
meta.pagination.page integer Current page number.
meta.pagination.limit integer Maximum number of results per page.
meta.pagination.total_items integer Total number of access policies matching the filters.
meta.pagination.total_pages integer Total number of pages.
meta.links object Navigation links for the result set.
meta.links.self string URL of the current page.
Info

The list representation returns only the access_policy namespace for each policy. The password, session, approvers_config, criteria, and access_limitation namespaces are returned only by GET | List an access policy by [id].


Errors

HTTP code Message Possible cause Solution
401 api.auth.token.invalid The access token is missing or has expired. Request a new access token.
403 api.permission.denied The authorization doesn't have permission to read access policies. Ask the administrator to check the Access Policy (V2) authorization and the PAM resource permission in A2A, then generate a new token.
422 api.enum.invalid_value A filter received a value outside its allowed list, such as a non-boolean value for active. Check the query parameters and resend the request.
429 rate_limit_exceeded The request rate limit was exceeded. Reduce the request rate and try again.
500 api.internal.error Internal server error. Contact the Segura® support team.

For authentication error messages and the 403 versus 404 policy, access API v2 - Conventions and shared behaviors.