---
title: "lookup entity"
method: POST
path: "/v1/tenants/{tenant_id}/permissions/lookup-entity"
tags: ["Permission"]
---

# lookup entity

`POST /v1/tenants/{tenant_id}/permissions/lookup-entity`

## Path parameters

- `tenant_id` string, required

## Request body

- LookupEntityBody — PermissionLookupEntityRequest is the request message for the LookupEntity method in the Permission service.
  - `metadata` PermissionLookupEntityRequestMetadata — PermissionLookupEntityRequestMetadata metadata for the PermissionLookupEntityRequest.
    - `schema_version` string — Version of the schema.
    - `snap_token` string — The snap token to avoid stale cache, see more details on [Snap Tokens](../../operations/snap-tokens).
    - `depth` integer — Query limit when if recursive database queries got in loop.
  - `entity_type` string — Type of the entity to lookup, required, must start with a letter and can include alphanumeric and underscore, max 64 bytes.
  - `permission` string — Name of the permission to check, required, must start with a letter and can include alphanumeric and underscore, max 64 bytes.
  - `subject` Subject — Subject represents an entity subject with a type, an identifier, and a relation.
    - `type` string
    - `id` string
    - `relation` string
  - `context` Context — Context encapsulates the information related to a single operation, including the tuples involved and the associated attributes.
    - `tuples` Tuple[] — A repeated field of tuples involved in the operation.
      - `entity` Entity — Entity represents an entity with a type and an identifier.
        - `type` string
        - `id` string
      - `relation` string
      - `subject` Subject — Subject represents an entity subject with a type, an identifier, and a relation.
        - `type` string
        - `id` string
        - `relation` string
    - `attributes` Attribute[] — A repeated field of attributes associated with the operation.
      - `entity` Entity — Entity represents an entity with a type and an identifier.
        - `type` string
        - `id` string
      - `attribute` string
      - `value` Any — `Any` contains an arbitrary serialized protocol buffer message along with a URL that describes the type of the serialized message. Protobuf library provides support to pack/unpack Any values in the form of utility functions or additional generated methods of the Any type. Example 1: Pack and unpack a message in C++. Foo foo = ...; Any any; any.PackFrom(foo); ... if (any.UnpackTo(&foo)) { ... } Example 2: Pack and unpack a message in Java. Foo foo = ...; Any any = Any.pack(foo); ... if (any.is(Foo.class)) { foo = any.unpack(Foo.class); } // or ... if (any.isSameTypeAs(Foo.getDefaultInstance())) { foo = any.unpack(Foo.getDefaultInstance()); } Example 3: Pack and unpack a message in Python. foo = Foo(...) any = Any() any.Pack(foo) ... if any.Is(Foo.DESCRIPTOR): any.Unpack(foo) ... Example 4: Pack and unpack a message in Go foo := &pb.Foo{...} any, err := anypb.New(foo) if err != nil { ... } ... foo := &pb.Foo{} if err := any.UnmarshalTo(foo); err != nil { ... } The pack methods provided by protobuf library will by default use 'type.googleapis.com/full.type.name' as the type URL and the unpack methods only use the fully qualified type name after the last '/' in the type URL, for example "foo.bar.com/x/y.z" will yield type name "y.z". JSON ==== The JSON representation of an `Any` value uses the regular representation of the deserialized, embedded message, with an additional field `@type` which contains the type URL. Example: package google.profile; message Person { string first_name = 1; string last_name = 2; } { "@type": "type.googleapis.com/google.profile.Person", "firstName": <string>, "lastName": <string> } If the embedded message type is well-known and has a custom JSON representation, that representation will be embedded adding a field `value` which holds the custom JSON in addition to the `@type` field. Example (for message [google.protobuf.Duration][]): { "@type": "type.googleapis.com/google.protobuf.Duration", "value": "1.212s" }
        - `@type` string — A URL/resource name that uniquely identifies the type of the serialized protocol buffer message. This string must contain at least one "/" character. The last segment of the URL's path must represent the fully qualified name of the type (as in `path/google.protobuf.Duration`). The name should be in a canonical form (e.g., leading "." is not accepted). In practice, teams usually precompile into the binary all types that they expect it to use in the context of Any. However, for URLs which use the scheme `http`, `https`, or no scheme, one can optionally set up a type server that maps type URLs to message definitions as follows: * If no scheme is provided, `https` is assumed. * An HTTP GET on the URL must yield a [google.protobuf.Type][] value in binary format, or produce an error. * Applications are allowed to cache lookup results based on the URL, or have them precompiled into a binary to avoid any lookup. Therefore, binary compatibility needs to be preserved on changes to types. (Use versioned type names to manage breaking changes.) Note: this functionality is not currently available in the official protobuf release, and it is not used for type URLs beginning with type.googleapis.com. As of May 2023, there are no widely used type server implementations and no plans to implement one. Schemes other than `http`, `https` (or the empty scheme) might be used with implementation specific semantics.
    - `data` object — Additional data associated with the context.
  - `scope` object — Scope: A map that associates entity types with lists of identifiers. Each entry helps filter requests by specifying which entities are relevant to the operation.
  - `page_size` integer — page_size is the number of entities to be returned in the response. The value should be between 1 and 100.
  - `continuous_token` string — continuous_token is an optional parameter used for pagination. It should be the value received in the previous response.

## Response `200`

A successful response.

- PermissionLookupEntityResponse — PermissionLookupEntityResponse is the response message for the LookupEntity method in the Permission service.
  - `entity_ids` string[] — List of identifiers for entities that match the lookup.
  - `continuous_token` string — continuous_token is a string that can be used to paginate and retrieve the next set of results.

## Other responses

- `default` — An unexpected error response.

## Changes

- **2025-12-28** `f37e45046dd2` — 2 breaking, 1 info
  - the `context/attributes/items/value/additionalProperties/` request property type changed from `object` to no type
  - the `details/items/additionalProperties/` response's property type changed from `object` to no type for status `default`
  - added the new optional request property `scope`
- **2024-08-26** `b7278a55155e` — 3 info
  - added the new optional request property `continuous_token`
  - added the new optional request property `page_size`
  - added the optional property `continuous_token` to the response with the `200` status
- **2024-08-26** `89d2d169f9dd` — 3 warning
  - removed the request property `continuous_token`
  - removed the request property `page_size`
  - removed the optional property `continuous_token` from the response with the `200` status
- **2024-08-23** `f3b10e35081b` — 1 breaking, 2 info
  - added required request body
  - added the media type `application/json` for the response with the status `200`
  - added the media type `application/json` for the response with the status `default`
- **2024-08-22** `282fb7ba2640` — 3 breaking
  - removed the request body
  - removed the media type `application/json` for the response with the status `200`
  - removed the media type `application/json` for the response with the status `default`

[Full history](https://skmtc.dev/permify/apis/permify-api/changes/v1/tenants/:tenant_id/permissions/lookup-entity/post.md)

---

[API](https://skmtc.dev/permify/apis/permify-api.md) · [All operations](https://skmtc.dev/permify/apis/permify-api/llms.txt) · [OpenAPI document](https://skmtc.dev/permify/apis/permify-api/revisions/736b14aefddf?raw)
