> ## Documentation Index
> Fetch the complete documentation index at: https://astronomer.io/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# List authorization permission groups

> List the available permissions you can grant to a custom role.



## OpenAPI

````yaml /astro/api/v-1-beta-1/iam/openapi.yaml get /authorization/permission-groups
openapi: 3.0.3
info:
  contact: {}
  description: Astro Identity and Access Management (IAM) API
  title: Astro Identity and Access Management (IAM) API
  version: v1beta1
servers:
  - url: https://api.astronomer.io/iam/v1beta1
security:
  - JWT: []
tags:
  - description: >-
      The `user` object represents a user account in your Astro Organization.
      Astro creates a new `user` object whenever you invite a user by email or
      add a user to Astro through an identity provider. The object contains all
      information about a user, including their personal information, roles, and
      login attempts. It doesn't include attributes for actions that the user
      completes after they log in, such as updating a Deployment. Make requests
      to `user` endpoints to manage permissions for existing users both at the
      Organization and Workspace level. To create new users, make requests to
      `invite` endpoints instead.
    name: User
  - description: >-
      The `team` object represents an Astro Team, which is a group of users that
      share the same permissions across your Organization and Workspaces. Make
      requests to `team` endpoints to create, update, and delete Teams across an
      Organization. See [Configure Teams on
      Astro](https://astronomer.io/docs/astro/manage-teams).
    name: Team
  - description: >-
      The `apitoken` object represents a single API token within your
      Organization. API tokens are used to authenticate automated tools and
      processes to your Organization. They have varying levels of access to your
      resources based on their Organization, Workspace, and Deployment roles.
      See [Workspace API tokens](workspace-api-tokens.md) and [Organization API
      tokens](organization-api-tokens.md).
    name: api-token
    x-group: API Token
  - description: >-
      The `invite` object represents the record of a user invite generated by
      Astro. It includes information both about the inviter and the invitee.
      Invites can be generated both by manual invitations through the Astro UI
      and automatic invitations through an identity provider. An `invite` record
      persists until its associated invite expires. Make requests to `invite`
      endpoints to create, delete, or audit invites for users across your
      Organization. See [Manage Organization
      users](https://astronomer.io/docs/astro/manage-organization-users) and
      [Manage Workspace
      users](https://astronomer.io/docs/astro/manage-workspace-users).
    name: Invite
  - name: allowed-ip-address-range
    x-group: Allowed IP Address Range
  - name: agent-token
    x-group: Agent Token
paths:
  /authorization/permission-groups:
    get:
      tags:
        - Authorization
      summary: List authorization permission groups
      description: List the available permissions you can grant to a custom role.
      operationId: ListPermissionGroups
      parameters:
        - description: >-
            Filter the returned permissions based on the scope they apply to.
            Note that currently, the only available permissions are in the
            `DEPLOYMENT` and `DAG` scopes.
          in: query
          name: scopeType
          schema:
            enum:
              - DEPLOYMENT
              - WORKSPACE
              - ORGANIZATION
              - DAG
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                items:
                  $ref: '#/components/schemas/PermissionGroup'
                type: array
          description: OK
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Bad Request
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Unauthorized
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Forbidden
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Internal Server Error
      security:
        - JWT: []
components:
  schemas:
    PermissionGroup:
      properties:
        description:
          description: The permission group's description.
          example: >-
            Astro notification channel defines where alert messages can be sent.
            For example, alert messages issued via email or slack.
          type: string
        name:
          description: The permission group's name.
          example: workspace.notificationChannels
          type: string
        permissions:
          description: The permission group's permissions.
          items:
            $ref: '#/components/schemas/PermissionEntry'
          type: array
        scope:
          description: The permission group's scope.
          example: Workspace NotificationChannels
          type: string
      required:
        - description
        - name
        - permissions
        - scope
      type: object
    Error:
      properties:
        message:
          type: string
        requestId:
          type: string
        statusCode:
          maximum: 600
          minimum: 400
          type: integer
      required:
        - message
        - requestId
        - statusCode
      type: object
    PermissionEntry:
      properties:
        action:
          description: The permission's action.
          example: get
          type: string
        description:
          description: The permission's description.
          example: Subject is permitted to get the scope.
          type: string
      required:
        - action
        - description
      type: object
  securitySchemes:
    JWT:
      scheme: bearer
      type: http

````