---
title: "describe external principal by id"
method: GET
path: "/auth/external/principals"
tags: ["auth", "external", "experimental"]
---

# describe external principal by id

`GET /auth/external/principals`

## Response `200`

external principal

- ExternalPrincipal
  - `id` string, required — A unique identifier for the external principal i.e aws:sts::123:assumed-role/role-name
  - `user_id` string, required — lakeFS user ID to associate with an external principal.
  - `settings` object

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `404` — Resource Not Found
- `429` — too many requests
- `default` — Internal Server Error

## Changes

- **2025-11-24** `add5a8870f32` — 1 info
  - added the non-success response with the status `400`
- **2025-07-29** `27799ffec9a5` — 2 info
  - added the non-success response with the status `429`
  - removed the non-success response with the status `420`
- **2024-09-17** `3b10653a8013` — 3 info
  - added the non-success response with the status `420`
  - removed the non-success response with the status `400`
  - removed the non-success response with the status `429`

[Change history](https://skmtc.dev/treeverse/apis/lakefs-api/changes/auth/external/principals/get.md)

---

[API](https://skmtc.dev/treeverse/apis/lakefs-api.md) · [All operations](https://skmtc.dev/treeverse/apis/lakefs-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/treeverse/lakefs-api/revisions/4617f80bee61/schema)
