curl --request GET \
--url https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles \
--header 'Authorization: Bearer <token>'import requests
url = "https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"items": [
{
"resourceType": "EVENT",
"resourceId": "9876",
"capabilities": [
"<string>"
]
}
]
}{
"code": "C0005",
"message": "pageSize must be 50 or less. Input: 51",
"timestamp": "2026-05-20T09:00:00",
"details": "startDate"
}{
"code": "C0005",
"message": "pageSize must be 50 or less. Input: 51",
"timestamp": "2026-05-20T09:00:00",
"details": "startDate"
}{
"code": "C0005",
"message": "pageSize must be 50 or less. Input: 51",
"timestamp": "2026-05-20T09:00:00",
"details": "startDate"
}{
"code": "C0005",
"message": "pageSize must be 50 or less. Input: 51",
"timestamp": "2026-05-20T09:00:00",
"details": "startDate"
}Query resource-level roles (precise check / list)
Returns the aggregated roles and capabilities for a specific resource (event or job). If resourceId is specified, performs a precise check (0 or 1 result); otherwise returns a paginated list of resources for which roles were explicitly granted. Response always contains an items list. Requires company:manage:read scope.
Authentication: The Authorization: Bearer <jwt> header is required.
Required OAuth scope: company:manage:read.
curl --request GET \
--url https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles \
--header 'Authorization: Bearer <token>'import requests
url = "https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://openapi.rocketpunch.com/api/v1/me/company-permissions/{companyPermalink}/resource-roles")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"items": [
{
"resourceType": "EVENT",
"resourceId": "9876",
"capabilities": [
"<string>"
]
}
]
}{
"code": "C0005",
"message": "pageSize must be 50 or less. Input: 51",
"timestamp": "2026-05-20T09:00:00",
"details": "startDate"
}{
"code": "C0005",
"message": "pageSize must be 50 or less. Input: 51",
"timestamp": "2026-05-20T09:00:00",
"details": "startDate"
}{
"code": "C0005",
"message": "pageSize must be 50 or less. Input: 51",
"timestamp": "2026-05-20T09:00:00",
"details": "startDate"
}{
"code": "C0005",
"message": "pageSize must be 50 or less. Input: 51",
"timestamp": "2026-05-20T09:00:00",
"details": "startDate"
}Authorizations
Access token for user-context authentication. Send it in the Authorization: Bearer <jwt> header. Use the token your OAuth client app obtained via the Authorization Code + PKCE flow.
Headers
Supported response locales: ko, en, ja, zh-CN, zh-TW, es, fr, de, pt, th, vi. Default is ko.
"ko"
Path Parameters
Company identifier (permalink)
Query Parameters
Resource type (EVENT or JOB)
Resource identifier for an exact check (string). Omit to use list mode.
Page number for list mode (starts at 1)
Page size for list mode (1-50, default 20)
Response
Success. Returns an empty items array if the user has no matching roles.
Resource-level permissions. With resourceId = precise check (0–1 items); without = explicitly granted list (paginated).
Show child attributes
Show child attributes
Was this page helpful?