---
title: "Check a permission"
method: GET
path: "/relation-tuples/check/openapi"
tags: ["permission"]
---

# Check a permission

`GET /relation-tuples/check/openapi`

To learn how relationship tuples and the check works, head over to [the documentation](https://www.ory.com/docs/keto/concepts/api-overview).

## Query parameters

- `namespace` string
- `object` string
- `relation` string
- `subject_id` string
- `subject_set.namespace` string
- `subject_set.object` string
- `subject_set.relation` string
- `max-depth` integer

## Response `200`

checkPermissionResult

- CheckPermissionResult — The content of the allowed field is mirrored in the HTTP status code.
  - `allowed` boolean, required — whether the relation tuple is allowed

## Other responses

- `400` — errorGeneric
- `default` — errorGeneric

## Changes

- **2022-11-25** `acd2fb10eb38` — 4 info
  - api operation id `getCheck` removed and replaced with `checkPermission`
  - api tag `permission` added
  - api tag `read` removed
  - removed the non-success response with the status `500`
- **2022-06-15** `f1814d31f948` — 1 info
  - endpoint added
- **2021-09-24** `b323fac0f51a` — 1 breaking
  - api path removed without deprecation

[Change history](https://skmtc.dev/ory/apis/ory-keto/changes/relation-tuples/check/openapi/get.md)

---

[API](https://skmtc.dev/ory/apis/ory-keto.md) · [All operations](https://skmtc.dev/ory/apis/ory-keto/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/ory/ory-keto/revisions/305cb58cb754/schema)
