Retrieve details about a specific role including its assigned permissions.
Use this to verify role configuration, check which permissions are currently assigned, or retrieve metadata for access review. Accepts either a role ID (starting with role_) or a role name.
Required permissions:
rbac.*.read_role(to read roles in any workspace)
Note
See the API reference for the full HTTP endpoint documentation.
Usage#
Flags#
Role ID (starting with role_) or role name to retrieve. Must be 1-128 characters. Returns complete role information including all assigned permissions.
Global Flags#
| Flag | Type | Description |
|---|---|---|
--root-key | string | Override root key ($UNKEY_ROOT_KEY) |
--api-url | string | Override API base URL (default: https://api.unkey.com) |
--config | string | Path to config file (default: ~/.unkey/config.toml) |
--output | string | Output format. Use json for raw JSON |
--body | string | Send this JSON string as the request body. You cannot combine it with request-building flags. |
Examples#
Output#
Default output shows the request ID, followed by the role details:
With --output=json, the full response envelope is returned: