Authorize API operations

View as Markdown
Returns the supplied generated API operations that the current caller may call, alongside its existing permission grant and access class. Candidate operations are checked without being executed.

Authentication

AuthorizationBearer

User bearer token: Clerk session JWT, Clerk OAuth access token, or Clerk API key

Request

This endpoint expects an object.
operationlist of objectsRequired
Generated API operation candidates to authorize.

Response headers

X-RateLimit-Limitinteger

Requests allowed per client IP in the current rate-limit window.

X-RateLimit-Remaininginteger

Requests left before the tightest applicable rate-limit bucket rejects.

X-RateLimit-Resetinteger

Seconds until the exhausted rate-limit bucket admits another request; 0 when none is exhausted.

Response

OK
operationlist of objects
Supplied operations admitted by the current session.
operationAccessenum
Highest access class represented by the current session.
Allowed values:
permissionGrantobject
Existing role and permission grant for the current session.

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
406
Not Acceptable Error
409
Conflict Error
415
Unsupported Media Type Error
422
Unprocessable Entity Error
429
Too Many Requests Error
500
Internal Server Error
503
Service Unavailable Error