Skip to main content

get-user-geographic-access-scope

dci get-user-geographic-access-scope

Returns the geographic scope assigned to a user who belongs to the target customer. The authenticated tenant must be the hierarchy root, and the target must be that root customer or one of its child customers. Targets outside that hierarchy are returned as not found. Requires the UsersManager permission.

Output

OK

By default dci renders the result as a table. Use --output json to get the full structure described below — see Output formats.

Returns: one of 4 variants

Example response (--output json)

{
"type": "country",
"countryCode": "DE",
"countryName": "Germany"
}
Raw JSON schema
{
"oneOf": [
{
"type": "object",
"additionalProperties": false,
"required": [
"type"
],
"properties": {
"type": {
"type": "string",
"enum": [
"unassigned"
],
"description": "No geographic scope is assigned."
}
}
},
{
"type": "object",
"additionalProperties": false,
"required": [
"type"
],
"properties": {
"type": {
"type": "string",
"enum": [
"global"
],
"description": "All countries and custom regions are allowed."
}
}
},
{
"type": "object",
"additionalProperties": false,
"required": [
"type",
"countryCode",
"countryName"
],
"properties": {
"type": {
"type": "string",
"enum": [
"country"
],
"description": "Access is limited to one canonical country."
},
"countryCode": {
"type": "string",
"pattern": "^[A-Z]{2}$",
"description": "Canonical ISO 3166-1 alpha-2 country code."
},
"countryName": {
"type": "string",
"description": "Canonical English country name."
}
}
},
{
"type": "object",
"additionalProperties": false,
"required": [
"type",
"customRegionId"
],
"properties": {
"type": {
"type": "string",
"enum": [
"customRegion"
],
"description": "Access is limited to one tenant-owned custom region."
},
"customRegionId": {
"type": "string",
"minLength": 1,
"maxLength": 200,
"description": "Ready custom region owned by the authenticated tenant."
}
}
}
],
"discriminator": {
"propertyName": "type"
}
}

Errors

On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.

HTTP statusExit codeError codeMeaning
40030VALIDATION_ERRORThe arguments or request body were rejected. Review the command's flags and payload.
40110AUTHENTICATION_FAILEDNot signed in, or the API token is invalid. Run dci login or check DCI_API_KEY.
40311PERMISSION_DENIEDThe DoiT user or the active customer context does not have access.
40420RESOURCE_NOT_FOUNDThe requested resource does not exist. Check the identifier argument.
40921RESOURCE_CONFLICTThe operation conflicts with the resource's current state.
42950RATE_LIMITEDToo many requests. Retryable — the CLI reports the server-provided delay.
500, 50340API_SERVER_ERRORThe API failed to process the request. Retryable; contact DoiT support if it persists.

Aliases: getusergeographicaccessscope