> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blindsight.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Get My Permissions

> Return the caller's OWN effective permissions.

Deliberately gated on nothing but a valid session. The sibling route
``GET /roles/permissions`` returns the whole workspace role→permission map
and is rightly restricted to ``roles.manage``, but the UI needs every user
, not just admins, to know what *they* may do. Reading your own grants
leaks nothing you could not already infer by clicking around, so any
signed-in user may call this.



## OpenAPI

````yaml /api-reference/openapi.json get /api/users/me/permissions
openapi: 3.1.0
info:
  title: Blindsight API
  version: 0.1.0
  description: >-
    The full Blindsight REST surface, generated from the running application.
    Replace the server host with your own deployment.


    For the Runtime Security integration surface (scan, proxy, tool calls) see
    the Runtime Security spec, which is hand written and carries worked
    examples.
servers:
  - url: https://api.your-blindsight.com
    description: Your Blindsight deployment
security: []
paths:
  /api/users/me/permissions:
    get:
      tags:
        - users
      summary: Get My Permissions
      description: >-
        Return the caller's OWN effective permissions.


        Deliberately gated on nothing but a valid session. The sibling route

        ``GET /roles/permissions`` returns the whole workspace role→permission
        map

        and is rightly restricted to ``roles.manage``, but the UI needs every
        user

        , not just admins, to know what *they* may do. Reading your own grants

        leaks nothing you could not already infer by clicking around, so any

        signed-in user may call this.
      operationId: get_my_permissions_api_users_me_permissions_get
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MyPermissionsResponse'
components:
  schemas:
    MyPermissionsResponse:
      properties:
        roles:
          items:
            type: string
          type: array
          title: Roles
        permissions:
          items:
            type: string
          type: array
          title: Permissions
      type: object
      required:
        - roles
        - permissions
      title: MyPermissionsResponse
      description: The caller's own effective permissions. Readable by any signed-in user.

````