# List User Permissions via Rest API

**URL:** <https://forum.keycloak.org/t/list-user-permissions-via-rest-api/972>\
**Category:** Miscellanaeous\
**Created:** [January 16, 2020, 11:29am UTC](https://forum.keycloak.org/t/list-user-permissions-via-rest-api/972 "2020-01-16T11:29:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![martinor](https://avatars.discourse-cdn.com/v4/letter/m/258eb7/32.png) [@martinor](https://forum.keycloak.org/u/martinor)\
**Post date:** [January 16, 2020, 11:29am UTC](https://forum.keycloak.org/t/list-user-permissions-via-rest-api/972/1 "2020-01-16T11:29:50Z")

</div>

Hello, I’m new to keycloak.  
I’have configured my realm and my client with some users that have a role with some permissions coupled.

I need, after user authentication (that I do correctly), to retrive via rest api the list of permissions associated to this user (via it’s role) to be able to develop the user interface of my webapp. (to show some menu functionality or not)

I’m reading the api documentation but I’have not found the right service yet.

Can you help me?  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Robinyo](https://avatars.discourse-cdn.com/v4/letter/r/dec6dc/32.png) [@Robinyo](https://forum.keycloak.org/u/Robinyo)\
**Post date:** [January 19, 2020, 6:15am UTC](https://forum.keycloak.org/t/list-user-permissions-via-rest-api/972/2 "2020-01-19T06:15:36Z")

</div>

> [@martinor](#):
>
> list of permissions associated to this user

Contemporary applications use OpenID Connect (OIDC) for authentication and OAuth 2.0 (scopes and claims) for **authorization**.

See: [Angular, OAuth 2.0 and Keycloak](https://robferguson.org/blog/2019/12/31/angular-oauth2-keycloak/)

---

<div class="post-metadata">

**Author:** ![andres](https://avatars.discourse-cdn.com/v4/letter/a/a4c791/32.png) [@andres](https://forum.keycloak.org/u/andres)\
**Post date:** [March 19, 2020, 3:42pm UTC](https://forum.keycloak.org/t/list-user-permissions-via-rest-api/972/3 "2020-03-19T15:42:13Z")

</div>

Hello, I’m having the same issue, have you found a solution for this?

---

<div class="post-metadata">

**Author:** ![martinor](https://avatars.discourse-cdn.com/v4/letter/m/258eb7/32.png) [@martinor](https://forum.keycloak.org/u/martinor)\
**Post date:** [March 20, 2020, 8:17am UTC](https://forum.keycloak.org/t/list-user-permissions-via-rest-api/972/4 "2020-03-20T08:17:31Z")

</div>

Yes, you have to consume this service: “…/protocol/openid-connect/token/introspect” that accept in input your authorization token. It’s return all the information you need.  
More information in “Robinyo” response.

---

<div class="post-metadata">

**Author:** ![npasic](https://avatars.discourse-cdn.com/v4/letter/n/e19b73/32.png) [@npasic](https://forum.keycloak.org/u/npasic)\
**Post date:** [July 15, 2020, 3:09pm UTC](https://forum.keycloak.org/t/list-user-permissions-via-rest-api/972/5 "2020-07-15T15:09:31Z")

</div>

@martinor @Robinyo  
I’m having some doubts, I did what @martinor said, called the introspect api but there is still not a list of permissions. I’m only having roles.

this is the response  
{

```
"exp": 1594825689,

"iat": 1594825389,

"jti": "0e512591-0a52-4f53-8415-c7e511a9d500",

"iss": "http://localhost:8180/auth/realms/hello-world-authz",

"aud": "account",

"sub": "d200e07e-4ca4-4ddb-8a76-5b2f22c16415",

"typ": "Bearer",

"azp": "vanilla",

"session_state": "e47dd513-5739-4ca6-86d7-f537bd5a2bd4",

"name": "Beck Beckenbauer",

"given_name": "Beck",

"family_name": "Beckenbauer",

"preferred_username": "beck",

"email": "beck@keycloak.org",

"email_verified": false,

"acr": "1",

"allowed-origins": [

    "http://localhost:8080"

],

"realm_access": {

    "roles": [

        "alice account role"

    ]

},

"resource_access": {

    "account": {

        "roles": [

            "manage-account",

            "manage-account-links",

            "view-profile"

        ]

    },

    "vanilla": {

        "roles": [

            "ACCOUNT",

            "EMAIL"

        ]

    }

},

"scope": "hello-vanilla-client-scope email profile",

"example_message": [

    "REALM_ROLE_alice account role"

],

"client_id": "vanilla",

"username": "beck",

"active": true

```

}

Btw, this user is assigned to two roles, those roles are related to two scopes which are related with 2 policies and 2 permissions.  
But I’m not able to retrieve it.

I expect that permission to be related to client, resource and then permission…  
Am I wrong??
