Skip to main content

list-roles

List all roles in your Unkey workspace using the CLI, including their assigned permissions. Review your full RBAC configuration at a glance.
2 min read

Retrieve all roles in your workspace including their assigned permissions. Results are paginated and sorted by their id.

Use this to audit your access control setup, verify role-permission mappings, or build automation that reacts to your current RBAC configuration.

Required permissions:

  • rbac.*.read_role
Note

See the API reference for the full HTTP endpoint documentation.

Usage#

Flags#

--limitinteger#

Maximum number of roles to return in a single response (1-100, default 100). Use smaller values for faster response times and better UI performance. Use larger values when you need to process many roles efficiently. Results exceeding this limit will be paginated with a cursor for continuation.

--cursorstring#

Pagination cursor from a previous response to fetch the next page of roles. Include this when you need to retrieve additional roles beyond the first page. Each response containing more results will include a cursor value that can be used here. Leave empty or omit this flag to start from the beginning of the role list.

Global Flags#

FlagTypeDescription
--root-keystringOverride root key ($UNKEY_ROOT_KEY)
--api-urlstringOverride API base URL (default: https://api.unkey.com)
--configstringPath to config file (default: ~/.unkey/config.toml)
--outputstringOutput format. Use json for raw JSON
--bodystringSend this JSON string as the request body. You cannot combine it with request-building flags.

Examples#

Output#

Default output shows the request ID, followed by the list of roles and their permissions:

With --output=json, the full response envelope is returned including pagination metadata: