Operation CategoriesList Vault categories

List Vault categories

Available to ANY member of the Vault: it's the catalog for the report and filter builder (used to choose categoryKey, groupByField, metricField, and to build categoryField). The ENTIRE list is visible: viewScope restricts access to the VALUES on operations, not to the schema; with the default owner_only, a person legitimately tags their own operations with their categories and builds reports on them. Grants and approvers (access config) aren't returned to non-admins.

For the TAGGING FORM of a specific operation, use a different endpoint, /operations/{type}/{id}/categories/available: it takes permissions on the operation's address into account, while this catalog is about the Vault as a whole.

Includes archived categories (filter in the query): a report for a past period may reference a category that has since been archived.

curl -X GET "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/operation-categories?appliesTo=transfer&archived=true&limit=42&cursor=example_string" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN"
{
  "items": [
    {
      "id": "cmr3f41z20001psp7phmyapw3",
      "vaultId": "example_string",
      "key": "example_string",
      "name": "John Doe",
      "description": "example_string",
      "emoji": "example_string",
      "color": "example_string",
      "appliesTo": "transfer",
      "viewScope": "owner_only",
      "assignScope": "owner_only",
      "editScope": "owner_only",
      "approvalScope": "none",
      "approvalThreshold": 42,
      "allowInitiatorApproval": true,
      "isSystem": true,
      "archived": true,
      "version": 42,
      "createdById": "example_string",
      "updatedById": "example_string",
      "createdAt": "2026-07-02T11:25:15.134000Z",
      "updatedAt": "2026-07-02T11:25:15.134000Z",
      "fields": [
        {
          "id": "cmr3f41z20001psp7phmyapw3",
          "categoryId": "example_string",
          "key": "example_string",
          "label": "example_string",
          "type": "text",
          "required": true,
          "optionsJson": [
            {
              "value": "example_string",
              "label": "example_string"
            }
          ],
          "scale": 42,
          "currencyFieldKey": "example_string",
          "unit": "example_string",
          "defaultJson": "null",
          "helpText": "example_string",
          "sensitive": true,
          "orderIndex": 42,
          "archived": true,
          "createdAt": "2026-07-02T11:25:15.134000Z",
          "updatedAt": "2026-07-02T11:25:15.134000Z"
        }
      ],
      "grants": [
        {
          "id": "cmr3f41z20001psp7phmyapw3",
          "vaultId": "example_string",
          "categoryId": "example_string",
          "subjectType": "user",
          "subjectUserId": "example_string",
          "subjectGroupId": "example_string",
          "canView": true,
          "canAssign": true,
          "canEdit": true,
          "grantorId": "example_string",
          "status": "example_string",
          "createdAt": "2026-07-02T11:25:15.134000Z"
        }
      ],
      "approvers": [
        {
          "id": "cmr3f41z20001psp7phmyapw3",
          "categoryId": "example_string",
          "kind": "user",
          "userId": "example_string",
          "groupId": "example_string",
          "createdAt": "2026-07-02T11:25:15.134000Z"
        }
      ]
    }
  ],
  "nextCursor": "example_string"
}
GET
/api/v1/vaults/{code}/operation-categories
GET
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token
Bearer Tokenstring
Required

Session token. Mobile/services. The web uses a cookie.

Session token. Mobile/services. The web uses a cookie.
API Key (cookie: session_token)
session_tokenstring
Required

API key (sent in cookie)

path
codestring
Required

Unique Vault code (slug)

query
appliesTostring
Options: transfer, deposit, both
query
archivedstring
Options: true, false
query
limitinteger
Min: 1 • Max: 100
Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token. Session token. Mobile/services. The web uses a cookie.

path
parameterstring
Required

API Key for authentication. Provide your API key in the cookie.

Path Parameters

codestring
Required

Unique Vault code (slug)

Example:
demo_vault

Query Parameters

appliesTostring
Allowed values:transferdepositboth
archivedstring
Allowed values:truefalse

Responses

itemsarray
Required
nextCursorstring
Required