---
title: "Check a permission"
method: GET
path: "/relation-tuples/check"
tags: ["permission"]
---

# Check a permission

`GET /relation-tuples/check`

To learn how relationship tuples and the check works, head over to [the documentation](https://www.ory.com/docs/keto/concepts/api-overview).

## Query parameters

- `namespace` string
- `object` string
- `relation` string
- `subject_id` string
- `subject_set.namespace` string
- `subject_set.object` string
- `subject_set.relation` string
- `max-depth` integer

## Response `200`

checkPermissionResult

- CheckPermissionResult — The content of the allowed field is mirrored in the HTTP status code.
  - `allowed` boolean, required — whether the relation tuple is allowed

## Other responses

- `400` — errorGeneric
- `403` — checkPermissionResult
- `default` — errorGeneric

## Changes

- **2022-11-25** `5f207fe3fcc0` — 6 warning, 13 info
  - removed the optional property `code` from the response with the `400` status
  - removed the optional property `details` from the response with the `400` status
  - removed the optional property `message` from the response with the `400` status
  - removed the optional property `reason` from the response with the `400` status
  - …15 more
- **2022-06-15** `cda743c1e8c1` — 8 warning, 1 info
  - deleted the `query` request parameter `max-depth`
  - deleted the `query` request parameter `namespace`
  - deleted the `query` request parameter `object`
  - deleted the `query` request parameter `relation`
  - …5 more
- **2022-03-29** `770289c14605` — 1 info
  - endpoint added
- **2021-10-07** `e90046dbd055` — 1 breaking
  - api path removed without deprecation

[Change history](https://skmtc.dev/ory/apis/ory-keto-api/changes/relation-tuples/check/get.md)

---

[API](https://skmtc.dev/ory/apis/ory-keto-api.md) · [All operations](https://skmtc.dev/ory/apis/ory-keto-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/ory/ory-keto-api/revisions/4e980fe4b29b/schema)
