---
title: "Get acl"
method: GET
path: "/v1/acl/{acl_id}"
tags: ["Acls"]
---

# Get acl

`GET /v1/acl/{acl_id}`

Get an acl object by its id

## Path parameters

- `acl_id` string, uuid, required — Acl id

## Response `200`

Returns the acl object

- Acl — An ACL grants a certain permission or role to a certain user or group on an object. ACLs are inherited across the object hierarchy. So for example, if a user has read permissions on a project, they will also have read permissions on any experiment, dataset, etc. created within that project. To restrict a grant to a particular sub-object, you may specify `restrict_object_type` in the ACL, as part of a direct permission grant or as part of a role.
  - `id` string, uuid, required — Unique identifier for the acl
  - `object_type` 'organization' | 'project' | 'experiment' | 'dataset' | 'prompt' | 'prompt_session' | 'group' | 'role' | 'org_member' | 'project_log' | 'org_project', required — The object type that the ACL applies to
  - `object_id` string, uuid, required — The id of the object the ACL applies to
  - `user_id` string, uuid, nullable — Id of the user the ACL applies to. Exactly one of `user_id` and `group_id` will be provided
  - `group_id` string, uuid, nullable — Id of the group the ACL applies to. Exactly one of `user_id` and `group_id` will be provided
  - `permission` 'create' | 'read' | 'update' | 'delete' | 'create_acls' | 'read_acls' | 'update_acls' | 'delete_acls', nullable — Permission the ACL grants. Exactly one of `permission` and `role_id` will be provided
  - `restrict_object_type` 'organization' | 'project' | 'experiment' | 'dataset' | 'prompt' | 'prompt_session' | 'group' | 'role' | 'org_member' | 'project_log' | 'org_project', nullable — When setting a permission directly, optionally restricts the permission grant to just the specified object type. Cannot be set alongside a `role_id`.
  - `role_id` string, uuid, nullable — Id of the role the ACL grants. Exactly one of `permission` and `role_id` will be provided
  - `_object_org_id` string, uuid, required — The organization the ACL's referred object belongs to
  - `created` string, date-time, nullable — Date of acl creation

## Other responses

- `400` — The request was unacceptable, often due to missing a required parameter
- `401` — No valid API key provided
- `403` — The API key doesn’t have permissions to perform the request
- `429` — Too many requests hit the API too quickly. We recommend an exponential backoff of your requests
- `500` — Something went wrong on Braintrust's end. (These are rare.)

## Changes

- **2024-09-30** `ac2727014d93` — 7 breaking
  - the response's body became nullable
  - the response's body became nullable
  - the response's body became nullable
  - the response's body became nullable
  - …3 more
- **2024-09-25** `68955d9009ff` — 2 breaking, 24 info
  - the `permission` response's property type/format changed from `string`/`` to ``/`` for status `200`
  - the `restrict_object_type` response's property type/format changed from `string`/`` to ``/`` for status `200`
  - added `#/components/schemas/AclObjectType, subschema #2` to the `restrict_object_type` response property `allOf` list for the response status `200`
  - added `#/components/schemas/Permission, subschema #2` to the `permission` response property `allOf` list for the response status `200`
  - …22 more
- **2024-07-23** `9eeeeb30b963` — 6 warning, 4 info
  - added the new `org_member` enum value to the `object_type` response property for the response status `200`
  - added the new `org_member` enum value to the `restrict_object_type` response property for the response status `200`
  - added the new `org_project` enum value to the `object_type` response property for the response status `200`
  - added the new `org_project` enum value to the `restrict_object_type` response property for the response status `200`
  - …6 more
- …earlier changes not shown

[Full history](https://skmtc.dev/braintrustdata/apis/braintrust-api/changes/v1/acl/:acl_id/get.md)

---

[API](https://skmtc.dev/braintrustdata/apis/braintrust-api.md) · [All operations](https://skmtc.dev/braintrustdata/apis/braintrust-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/braintrustdata/braintrust-api/revisions/9d216c8243fe/schema)
