---
title: "list user external policies attached to a user"
method: GET
path: "/auth/users/{userId}/external/principals/ls"
tags: ["auth", "external", "experimental"]
---

# list user external policies attached to a user

`GET /auth/users/{userId}/external/principals/ls`

## Query parameters

- `prefix` string
- `after` string
- `amount` integer

## Response `200`

external principals list

- ExternalPrincipalList
  - `pagination` Pagination, required
    - `has_more` boolean, required — Next page is available
    - `next_offset` string, required — Token used to retrieve the next page
    - `results` integer, required — Number of values found in the results
    - `max_per_page` integer, required — Maximal number of entries per page
  - `results` ExternalPrincipal[], required
    - `id` string, required — A unique identifier for the external principal i.e aws:sts::123:assumed-role/role-name
    - `user_id` string, required — lakeFS user ID to associate with an external principal.
    - `settings` object

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `404` — Resource Not Found
- `429` — too many requests
- `default` — Internal Server Error

## Changes

- **2025-11-24** `add5a8870f32` — 1 info
  - added the non-success response with the status `400`
- **2025-07-29** `27799ffec9a5` — 2 info
  - added the non-success response with the status `429`
  - removed the non-success response with the status `420`
- **2024-09-17** `3b10653a8013` — 3 info
  - added the non-success response with the status `420`
  - removed the non-success response with the status `400`
  - removed the non-success response with the status `429`

[Change history](https://skmtc.dev/treeverse/apis/lakefs-api/changes/auth/users/:userId/external/principals/ls/get.md)

---

[API](https://skmtc.dev/treeverse/apis/lakefs-api.md) · [All operations](https://skmtc.dev/treeverse/apis/lakefs-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/treeverse/lakefs-api/revisions/4617f80bee61/schema)
