Folder grants
Who has access to the folder's addresses. Address owners aren't included, since they have access through ownership. Each item contains role; there's no need to derive it from flags on the client.
curl -X GET "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-folders/example_string/grants" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN"
import requests
import json
url = "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-folders/example_string/grants"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
response = requests.get(url, headers=headers)
print(response.json())
const response = await fetch("https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-folders/example_string/grants", {
method: "GET",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-folders/example_string/grants", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-folders/example_string/grants')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Get.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN'
response = http.request(request)
puts response.body
{
"items": [
{
"id": "cmr3f41z20001psp7phmyapw3",
"vaultId": "example_string",
"subjectType": "user",
"subjectUserId": "example_string",
"subjectGroupId": "example_string",
"targetType": "address",
"targetAddressId": "123 Main St",
"targetGroupId": "example_string",
"role": "viewer",
"canView": true,
"canTransfer": true,
"canCreateAddress": true,
"grantorId": "example_string",
"status": "active",
"createdAt": "2026-07-02T11:25:15.134000Z",
"updatedAt": "2026-07-02T11:25:15.134000Z",
"subject": {
"id": "example_string",
"name": "John Doe",
"username": "John Doe",
"image": "example_string",
"color": "example_string",
"emoji": "example_string"
},
"subjectGroup": {
"id": "example_string",
"name": "John Doe"
}
}
]
}
{
"error": "Unauthorized",
"message": "Authentication required. Please provide a valid API token",
"code": 401
}
{
"error": "Forbidden",
"message": "You don't have permission to access this resource",
"code": 403
}
{
"error": "Not Found",
"message": "The requested resource was not found",
"code": 404
}
{
"error": "Internal Server Error",
"message": "An unexpected error occurred on the server",
"code": 500,
"requestId": "req_1234567890"
}
GET
/api/v1/vaults/{code}/address-folders/{id}/grantsGET
Base URLstring
Target server for requests. Edit to use your own host.
Bearer Token
Bearer Tokenstring
RequiredSession token. Mobile/services. The web uses a cookie.
Session token. Mobile/services. The web uses a cookie.
API Key (cookie: session_token)
session_tokenstring
RequiredAPI key (sent in cookie)
path
codestring
RequiredUnique Vault code (slug)
Request Preview
Response
Response will appear here after sending the request
Authentication
header
Authorizationstring
RequiredBearer token. Session token. Mobile/services. The web uses a cookie.
path
parameterstring
RequiredAPI Key for authentication. Provide your API key in the cookie.
Path Parameters
Responses
itemsarray
RequiredWas this page helpful?