---
title: "Check a permission"
method: GET
path: "/relation-tuples/check"
tags: ["permission"]
---

# Check a permission

`GET /relation-tuples/check`

To learn how relationship tuples and the check works, head over to [the documentation](https://www.ory.com/docs/keto/concepts/api-overview).

## Query parameters

- `namespace` string
- `object` string
- `relation` string
- `subject_id` string
- `subject_set.namespace` string
- `subject_set.object` string
- `subject_set.relation` string
- `max-depth` integer

## Response `200`

checkPermissionResult

- CheckPermissionResult — The content of the allowed field is mirrored in the HTTP status code.
  - `allowed` boolean, required — whether the relation tuple is allowed

## Other responses

- `400` — errorGeneric
- `403` — checkPermissionResult
- `default` — errorGeneric

## Changes

- **2022-11-25** `acd2fb10eb38` — 12 info
  - api operation id `getCheckMirrorStatus` removed and replaced with `checkPermissionOrError`
  - api tag `permission` added
  - api tag `read` removed
  - added the new optional `query` request parameter `max-depth`
  - …8 more
- **2022-06-15** `f1814d31f948` — 8 warning, 1 info
  - deleted the `query` request parameter `max-depth`
  - deleted the `query` request parameter `namespace`
  - deleted the `query` request parameter `object`
  - deleted the `query` request parameter `relation`
  - …5 more
- **2022-03-29** `5927be396871` — 1 info
  - endpoint added
- **2021-09-24** `b323fac0f51a` — 1 breaking
  - api path removed without deprecation

[Change history](https://skmtc.dev/ory/apis/ory-keto/changes/relation-tuples/check/get.md)

---

[API](https://skmtc.dev/ory/apis/ory-keto.md) · [All operations](https://skmtc.dev/ory/apis/ory-keto/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/ory/ory-keto/revisions/305cb58cb754/schema)
