メインコンテンツへスキップ

list-roles

dci list-roles

Returns a list of roles.

CLI default view

dci list-roles presents a curated table by default:

  • Columns: name, type, and description.
  • --output json and explicit -C/--fields selections return the raw fields documented below.

Examples​

# Preset and custom roles, with descriptions.
dci list-roles
# Roles whose name or description mentions a term, matched client-side.
dci list-roles --search admin
# Each role's permission IDs, as JSON.
dci list-roles --fields id,name,type,permissions --output json

Output​

OK - List of roles returned.

By default dci renders the result as a table. Use --output json to get the full structure described below — see Output formats.

FieldTypeDescription
rowCountintegerNumber of roles returned.
rolesarray of object
roles[].idstringThe unique ID of the role.
roles[].namestringThe name of the role.
roles[].typestringThe type of the role (preset or custom). One of: "preset", "custom".
roles[].descriptionstringThe description of the role. An empty string when no description is set.
roles[].customerstringThe customer ID if this is a custom role. An empty string for a preset role.
roles[].permissionsarray of stringPermission IDs in stored order. An empty array when no permissions are assigned.
roles[].childTenantEligiblebooleanWhether the owning tenant made this role available as a child tenant role.
Raw JSON schema
{
"type": "object",
"properties": {
"rowCount": {
"type": "integer",
"description": "Number of roles returned."
},
"roles": {
"type": "array",
"items": {
"type": "object",
"description": "Definition and permissions assigned to a role.",
"required": [
"id",
"name",
"type",
"description",
"customer",
"permissions",
"childTenantEligible"
],
"properties": {
"id": {
"type": "string",
"description": "The unique ID of the role."
},
"name": {
"type": "string",
"description": "The name of the role."
},
"type": {
"type": "string",
"enum": [
"preset",
"custom"
],
"description": "The type of the role (preset or custom)."
},
"description": {
"type": "string",
"description": "The description of the role. An empty string when no description is set."
},
"customer": {
"type": "string",
"description": "The customer ID if this is a custom role. An empty string for a preset role."
},
"permissions": {
"type": "array",
"description": "Permission IDs in stored order. An empty array when no permissions are assigned.",
"items": {
"type": "string"
}
},
"childTenantEligible": {
"type": "boolean",
"description": "Whether the owning tenant made this role available as a child tenant role."
}
}
}
}
}
}

Errors​

On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.

HTTP status to exit code mapping
HTTP statusExit codeError codeMeaning
40030VALIDATION_ERRORThe arguments or request body were rejected. Review the command's flags and payload.
40110AUTHENTICATION_FAILEDNot signed in, or the API token is invalid. Run dci login or check DCI_API_KEY.
40311PERMISSION_DENIEDThe DoiT user or the active customer context does not have access.
50040API_SERVER_ERRORThe API failed to process the request. Retryable; contact DoiT support if it persists.

Aliases: listroles