---
title: "List config object access grants"
method: GET
path: "/v1/config-objects/{configObjectId}/access"
tags: ["Config Objects"]
---

# List config object access grants

`GET /v1/config-objects/{configObjectId}/access`

Lists direct, team, and org-wide grants for one config object.

## Path parameters

- `configObjectId` string, typeid, required

## Response `200`

Config object access grants returned successfully.

- PluginArchAccessGrantListResponse
  - `items` PluginArchAccessGrant[], required
    - `id` union, required
      - string, typeid — Den TypeID with 'coa_' prefix and a 26-character base32 suffix.
      - string, typeid — Den TypeID with 'pag_' prefix and a 26-character base32 suffix.
      - string, typeid — Den TypeID with 'mag_' prefix and a 26-character base32 suffix.
      - string, typeid — Den TypeID with 'cia_' prefix and a 26-character base32 suffix.
    - `orgMembershipId` string, typeid, nullable, required — Den TypeID with 'om_' prefix and a 26-character base32 suffix.
    - `teamId` string, typeid, nullable, required — Den TypeID with 'tem_' prefix and a 26-character base32 suffix.
    - `orgWide` boolean, required
    - `role` 'viewer' | 'editor' | 'manager', required
    - `createdByOrgMembershipId` string, typeid, required — Den TypeID with 'om_' prefix and a 26-character base32 suffix.
    - `createdAt` string, date-time, required
    - `removedAt` string, date-time, nullable, required
  - `nextCursor` string, nullable, required

## Other responses

- `400` — The access path parameters were invalid.
- `401` — The caller must be signed in to manage config object access.
- `403` — The caller lacks permission to manage config object access.
- `404` — The config object could not be found.

## Changes

- **2026-08-20** `93df40e2efd5` — 6 info
  - removed the pattern `^cob_.*` from the `path` request parameter `configObjectId`
  - added `subschema #1, subschema #2, subschema #3, subschema #4` to the `items/items/id` response property `anyOf` list for the response status `200`
  - removed `subschema #1, subschema #2, subschema #3, subschema #4` from the `items/items/id` response property `anyOf` list for the response status `200`
  - the `items/items/createdByOrgMembershipId` response's property pattern `^om_.*` was removed for the status `200`
  - …2 more

[Change history](https://skmtc.dev/openworklabs/apis/den-api/changes/v1/config-objects/:configObjectId/access/get.md)

---

[API](https://skmtc.dev/openworklabs/apis/den-api.md) · [All operations](https://skmtc.dev/openworklabs/apis/den-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/openworklabs/den-api/revisions/fcbb34aa1702/schema)
