---
title: "Get all roles"
method: GET
path: "/roles"
tags: ["Roles"]
---

# Get all roles

`GET /roles`

Returns a paginated list of roles.

Use the `offset` and `limit` query parameters to page through results; `meta.total_count` gives the total number of matching roles. Use `user_id` to filter by a specific user, `entity_id` to filter by account group or business, and `sort`/`order` to control the ordering by `created_at` or `updated_at`.

See the User roles guide ([TOL](https://docs.upvest.co/products/tol/guides/users/users_onboarding_roles) / [BYOL](https://docs.upvest.co/products/byol/guides/users/users_onboarding_roles)) for role types and assignment rules.

## Path parameters

- `user_id` string, uuid, required — Unique identifier of the user, as a UUID.

## Query parameters

- `sort` 'created_at' | 'updated_at'
- `user_id` string, uuid — Unique identifier of the user, as a UUID.
- `entity_id` string, uuid — Unique identifier of the entity a role is attached to.
- `order` 'ASC' | 'DESC'
- `offset` integer
- `limit` integer

## Response `200`

OK

- object — Paginated list of roles. Contains a `data` array of role objects and a `meta` object with offset/limit pagination metadata.
  - `meta` object, required — Offset/limit pagination metadata for a list response. Contains the `offset` and `limit` applied to the request, the `count` of resources returned in this page, and the `total_count` of matching resources.
    - `offset` integer, required — Amount of resource to offset in the response.
    - `limit` integer, required — Total limit of the response.
    - `count` integer, required — Count of the resources returned in the response.
    - `total_count` integer, required — Total count of all the resources.
    - `sort` string — The field that the list is sorted by.
    - `order` 'ASC' | 'DESC' — The ordering applied to the list. * ASC — Ascending order. * DESC — Descending order.
  - `data` union[], required — List of roles matching the query.
    - union — A role assigned to a user for a specific entity (business or account group).
      - object — Role assignment for an account group.
        - `id` string, uuid, required — Unique identifier for the role.
        - `created_at` string, date-time, required — Date and time when the resource was created. [RFC 3339-5](https://datatracker.ietf.org/doc/html/rfc3339#section-5.6), [ISO8601 UTC](https://www.iso.org/iso-8601-date-and-time-format.html)
        - `updated_at` string, date-time, required — Date and time when the resource was last updated. [RFC 3339-5](https://datatracker.ietf.org/doc/html/rfc3339#section-5.6), [ISO8601 UTC](https://www.iso.org/iso-8601-date-and-time-format.html)
        - `user_id` string, uuid, required — Unique identifier of the user, as a UUID.
        - `entity_type` string, required — The entity type; must be `ACCOUNT_GROUP` for account group roles.
        - `entity_id` string, uuid, required — Unique identifier of the entity a role is attached to.
        - `role_type` 'OWNER' | 'GUARDIAN' | 'CHILD', required — Role type for an account group. * `OWNER` — The user owns the account group. * `GUARDIAN` — The user is a legal custodian of a child account group. * `CHILD` — The user is the child beneficiary of a child account group.
        - `custody_type` 'SOLE_CUSTODY' | 'JOINT_CUSTODY' — Custody type for child account groups. * `SOLE_CUSTODY` — A single guardian has custody of the child account group. * `JOINT_CUSTODY` — Multiple guardians are required for the child account group.
        - `status` 'PENDING' | 'ACTIVE' | 'DEACTIVATED', required — Status of the role assignment. * `PENDING` — The role has been created but is not yet active. * `ACTIVE` — The role is active. * `DEACTIVATED` — The role has been deactivated and cannot be reactivated.
      - object — Role assignment for a business entity.
        - `id` string, uuid, required — Unique identifier for the role.
        - `created_at` string, date-time, required — Date and time when the resource was created. [RFC 3339-5](https://datatracker.ietf.org/doc/html/rfc3339#section-5.6), [ISO8601 UTC](https://www.iso.org/iso-8601-date-and-time-format.html)
        - `updated_at` string, date-time, required — Date and time when the resource was last updated. [RFC 3339-5](https://datatracker.ietf.org/doc/html/rfc3339#section-5.6), [ISO8601 UTC](https://www.iso.org/iso-8601-date-and-time-format.html)
        - `user_id` string, uuid, required — Unique identifier of the user, as a UUID.
        - `entity_type` string, required — The entity type; must be `BUSINESS` for business roles.
        - `entity_id` string, uuid, required — Unique identifier of the entity a role is attached to.
        - `role_type` 'LEGAL_REPRESENTATIVE' | 'AUTHORISED_SIGNATORY' | 'ULTIMATE_BENEFICIAL_OWNER' | 'CONTRACTING_EXECUTIVE' | 'TRADER' | 'SOLE_TRADER', required — Role type for a business entity. * `LEGAL_REPRESENTATIVE` — The user is a legal representative of the business. * `AUTHORISED_SIGNATORY` — The user is authorised to sign documents and make commitments on behalf of the business. * `ULTIMATE_BENEFICIAL_OWNER` — The user ultimately owns or controls the business. * `CONTRACTING_EXECUTIVE` — The user is able to enter into contracts on behalf of the business. * `TRADER` — The user is authorised to place orders on behalf of the business. * `SOLE_TRADER` — The user places orders on behalf of a sole trader entity.
        - `status` 'PENDING' | 'ACTIVE' | 'DEACTIVATED', required — Status of the role assignment. * `PENDING` — The role has been created but is not yet active. * `ACTIVE` — The role is active. * `DEACTIVATED` — The role has been deactivated and cannot be reactivated.

## Other responses

- `400` — Bad Request. The incoming request had a malformed parameter/object.
- `401` — Unauthorized. The caller has not been authenticated.
- `403` — Forbidden. The caller has been authenticated but is not allowed to take the requested action.
- `406` — Not Acceptable. The resource does not have a current representation that would be acceptable to the user agent. "Accept" header defined unsupported value.
- `429` — Too Many Requests. The caller has exceeded their quota for the time period and has been throttled.
- `500` — Internal Server Error. The service encountered an unexpected error.
- `503` — Service Unavailable. The service handling for this request cannot be reached at this time.
- `504` — Gateway Timeout. The service gateway has reached its internal timeout.

---

[API](https://skmtc.dev/upvest/apis/upvest-investment-api.md) · [All operations](https://skmtc.dev/upvest/apis/upvest-investment-api/llms.txt) · [OpenAPI document](https://skmtc.dev/upvest/apis/upvest-investment-api/revisions/25a6cd1e39de?raw)
