On this page

Golden 3.0.0 public API reference. Parameters, responses, and schemas for supported customer operations.

9 operations.

GET /api/data-scopes

Lists every principal that has a data scope.

Operation ID: list_2

One entry per user or access token with a scope row: the entities it may see and, per entity, whether whole or by row scope. ADMINs never have a row. Requires the ADMIN role.

Security: bearerAuth

Responses

StatusDescriptionBody
200Successful operationapplication/json: DataScopeListResponseDto
400Invalid parametersapplication/json: BaseResponseDto
401Authentication requiredapplication/json: BaseResponseDto
403Not authorizedapplication/json: BaseResponseDto
404Resource not foundapplication/json: BaseResponseDto
409Object is not in the correct stateapplication/json: BaseResponseDto

POST /api/data-scopes/bootstrap

Grants every entity, whole, to every non-ADMIN principal that has no scope yet.

Operation ID: bootstrap

Creates default data grants for principals without an existing grant. Existing grants remain unchanged. Requires the ADMIN role.

Security: bearerAuth

Responses

StatusDescriptionBody
200Successful operationapplication/json: BaseResponseDto
400Invalid parametersapplication/json: BaseResponseDto
401Authentication requiredapplication/json: BaseResponseDto
403Not authorizedapplication/json: BaseResponseDto
404Resource not foundapplication/json: BaseResponseDto
409Object is not in the correct stateapplication/json: BaseResponseDto

GET /api/data-scopes/me

The caller’s own effective data scope.

Operation ID: me

The entities the caller may see and how much of each. An ADMIN gets no scope: it is unrestricted. A principal with no row gets an empty map. Any authenticated principal.

Security: bearerAuth

Responses

StatusDescriptionBody
200Successful operationapplication/json: DataScopeResponseDto
400Invalid parametersapplication/json: BaseResponseDto
401Authentication requiredapplication/json: BaseResponseDto
403Not authorizedapplication/json: BaseResponseDto
404Resource not foundapplication/json: BaseResponseDto
409Object is not in the correct stateapplication/json: BaseResponseDto

GET /api/data-scopes/{type}/{id}

One principal’s data scope.

Operation ID: get_4

404 when the principal has no scope row. Requires the ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
typepathtruestringUSER or ACCESS_TOKEN enum: [“USER”, “ACCESS_TOKEN”]
idpathtruestringPrincipal identifier minLength: 1

Responses

StatusDescriptionBody
200Successful operationapplication/json: DataScopeResponseDto
400Invalid parametersapplication/json: BaseResponseDto
401Authentication requiredapplication/json: BaseResponseDto
403Not authorizedapplication/json: BaseResponseDto
404Resource not foundapplication/json: BaseResponseDto
409Object is not in the correct stateapplication/json: BaseResponseDto

DELETE /api/data-scopes/{type}/{id}

Removes a principal’s data scope.

Operation ID: delete_2

Back to no access at all. 404 when the principal has no scope row, exactly like the read: a delete that answers 200 for a principal that never existed reports a removal that did not happen. 409 when the row grants a locked entity, naming them: this route revokes across every entity at once, so it is the other way into a locked entity’s access list. Requires the ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
typepathtruestringUSER or ACCESS_TOKEN enum: [“USER”, “ACCESS_TOKEN”]
idpathtruestringPrincipal identifier minLength: 1

Responses

StatusDescriptionBody
200Successful operationapplication/json: BaseResponseDto
400Invalid parametersapplication/json: BaseResponseDto
401Authentication requiredapplication/json: BaseResponseDto
403Not authorizedapplication/json: BaseResponseDto
404Resource not foundapplication/json: BaseResponseDto
409Object is not in the correct stateapplication/json: BaseResponseDto

GET /api/entities/{entity}/access

The entity’s access list.

Operation ID: access

Who sees the entity and how much of it, plus the scope column and the state of its index. An empty list means only ADMINs see it. Requires the ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
entitypathtruestringEntity identifier minLength: 1

Responses

StatusDescriptionBody
200Successful operationapplication/json: EntityAccessResponseDto
400Invalid parametersapplication/json: BaseResponseDto
401Authentication requiredapplication/json: BaseResponseDto
403Not authorizedapplication/json: BaseResponseDto
404Resource not foundapplication/json: BaseResponseDto
409Object is not in the correct stateapplication/json: BaseResponseDto

PUT /api/entities/{entity}/access

Replaces the entity’s access list.

Operation ID: replaceAccess

Replaces all entity access grants. Each principal receives whole-entity access (values:null) or row access through the entity’s scope column. Omitted principals lose access. The complete request is validated before applying any grant. Unknown principals, missing scope columns for row grants, and empty or oversized value lists return 400. A locked entity returns 409. Requires the ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
entitypathtruestringEntity identifier minLength: 1

Request body

Media typeRequiredSchema
application/jsontrueEntityAccessRequestDto

Responses

StatusDescriptionBody
200Successful operationapplication/json: EntityAccessResponseDto
400Invalid parametersapplication/json: BaseResponseDto
401Authentication requiredapplication/json: BaseResponseDto
403Not authorizedapplication/json: BaseResponseDto
404Resource not foundapplication/json: BaseResponseDto
409Object is not in the correct stateapplication/json: BaseResponseDto

PUT /api/entities/{entity}/scope-column

Sets or clears the entity’s scope column.

Operation ID: setScopeColumn

A root token column of the dataset whose values are strings, scalar or array. Answers at once; the GIN index builds behind and the access list reports its state. Setting the same column again rebuilds a missing or invalid index. 409 when row scopes exist on a different column. Requires the ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
entitypathtruestringEntity identifier minLength: 1

Request body

Media typeRequiredSchema
application/jsontrueScopeColumnRequestDto

Responses

StatusDescriptionBody
200Successful operationapplication/json: EntityAccessResponseDto
400Invalid parametersapplication/json: BaseResponseDto
401Authentication requiredapplication/json: BaseResponseDto
403Not authorizedapplication/json: BaseResponseDto
404Resource not foundapplication/json: BaseResponseDto
409Object is not in the correct stateapplication/json: BaseResponseDto

GET /api/entities/{entity}/scope-values

The distinct values of the entity’s scope column.

Operation ID: scopeValues

For the administrator’s picker: sorted, capped, under a time budget; the flag says when the list was cut short. A scope for a value with no record yet is legitimate, so the picker also accepts typed values. Requires the ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
entitypathtruestringEntity identifier minLength: 1

Responses

StatusDescriptionBody
200Successful operationapplication/json: ScopeValuesResponseDto
400Invalid parametersapplication/json: BaseResponseDto
401Authentication requiredapplication/json: BaseResponseDto
403Not authorizedapplication/json: BaseResponseDto
404Resource not foundapplication/json: BaseResponseDto
409Object is not in the correct stateapplication/json: BaseResponseDto
Golden 3.0.0 · Published 2026-10-04