GET
/api/public/v1/employees/{employeeId}/permissions

Get an employee’s permissions

What one person has been granted. A grant with a null `locationId` is company-wide; one naming a location applies only there, and a company-level grant also satisfies a per-location check. A company owner has no grants and needs none — `isOwner` is how you tell "holds nothing" from "holds everything".

Required scope

The access token must carry this scope. A token missing it gets 403 Forbidden. Grant them to an API client under Settings → Company → API, and to a teammate under Employee → Permissions.

employee:permissions:read

Path Parameters

NameTypeRequiredDescription
employeeIdstringRequiredEmployee ID.
GETExample request
curl
curl -X GET "https://www.pxb.app/api/public/v1/employees/{employeeId}/permissions" \
  -H "Authorization: Bearer your_access_token"
200Example response
json
{
  "message": "Permissions retrieved successfully!",
  "content": {
    "isOwner": false,
    "scopes": [
      {
        "scope": "customers:read",
        "locationId": null
      },
      {
        "scope": "schedule:write",
        "locationId": "loc_abc123"
      }
    ]
  }
}

In the console

The same thing done by hand, for anyone comparing the API against the screen they already use.

Employees → Directory → Permissions
/employee/directory
  1. Open an employee.
  2. Permissions.