> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# List scope catalogs

> Returns, for every product that has published one, the dimensions a partner can be scoped on in that product — the WHERE half of a partner, next to the collections and verbs of its permissions. Each product declares its own catalog when it starts, so the list follows the products actually deployed; a product absent from it publishes none, and any `scope` line for it is refused with `IDE-1042` on a partner write.

Called when a partner editor opens, to render one picker per dimension in tree order (the first dimension is the top of the funnel; each later one narrows inside it). The rules a partner write is held to come from here: a `required` dimension must have a scope line (`IDE-0001`), a dimension that is not `multi` takes one value (`IDE-0002`), and listing or creating in a dimension's `collection` is denied to a partner scoped on it, because that is where its siblings live.

Read-only and global: the catalog describes the product, not your organization, so every caller sees the same list.

Failures:
- `403` — your token does not hold the `partners` resource.
- `503 IDE-0060` — the identity provider is unavailable (unreachable, too slow to answer, or failing). Nothing about the request was wrong; retry it later.



## OpenAPI

````yaml /es/openapi/v3-current/AM-identity.yaml get /v1/scope-catalog
openapi: 3.1.0
info:
  contact:
    name: Lerian Studio
    url: https://lerian.studio
  description: >-
    OpenAPI 3.1 surface for the plugin-access-manager identity component. It
    exposes the M2M-gated declarations upsert (PUT /v1/declarations/{slug}),
    through which each plugin declares its own permissions/roles/M2M contract,
    and partner management (/v1/partners), through which a tenant administrator
    grants its own customers scoped API credentials. The remaining identity
    routes stay Fiber-native and are described by the separate OAS 2 document in
    the same folder.
  license:
    name: Apache-2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Plugin Access Manager — Identity API
  version: v1
servers: []
security: []
tags:
  - description: >-
      M2M-only: each plugin declares its own permissions, roles and M2M
      contract, and the server reconciles them.
    name: Declarations
  - description: >-
      A tenant administrator's customers. Each partner holds what its
      credentials may DO (permissions, per product) and WHERE they may do it
      (scope, per product and dimension); an M2M application attached to one is
      confined to that intersection. Administrator-only: authorized on the
      "partners" resource, and every route resolves the owning organization from
      the caller's token.
    name: Partners
paths:
  /v1/scope-catalog:
    get:
      tags:
        - Partners
      summary: List scope catalogs
      description: >-
        Returns, for every product that has published one, the dimensions a
        partner can be scoped on in that product — the WHERE half of a partner,
        next to the collections and verbs of its permissions. Each product
        declares its own catalog when it starts, so the list follows the
        products actually deployed; a product absent from it publishes none, and
        any `scope` line for it is refused with `IDE-1042` on a partner write.


        Called when a partner editor opens, to render one picker per dimension
        in tree order (the first dimension is the top of the funnel; each later
        one narrows inside it). The rules a partner write is held to come from
        here: a `required` dimension must have a scope line (`IDE-0001`), a
        dimension that is not `multi` takes one value (`IDE-0002`), and listing
        or creating in a dimension's `collection` is denied to a partner scoped
        on it, because that is where its siblings live.


        Read-only and global: the catalog describes the product, not your
        organization, so every caller sees the same list.


        Failures:

        - `403` — your token does not hold the `partners` resource.

        - `503 IDE-0060` — the identity provider is unavailable (unreachable,
        too slow to answer, or failing). Nothing about the request was wrong;
        retry it later.
      operationId: listScopeCatalogs
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ScopeCatalogList'
          description: OK
        '500':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Internal Server Error
        '503':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Service Unavailable
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Error
      security:
        - BearerAuth: []
components:
  schemas:
    ScopeCatalogList:
      additionalProperties: false
      properties:
        items:
          description: >-
            One entry per product that has published a scope catalog. A product
            absent from this list publishes none, and no partner can be scoped
            on it.
          items:
            $ref: '#/components/schemas/ScopeCatalog'
          type:
            - array
            - 'null'
      required:
        - items
      type: object
    Detail:
      additionalProperties: true
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      type: object
    ScopeCatalog:
      additionalProperties: false
      properties:
        dimensions:
          description: >-
            Dimensions in tree order: the first is the top of the funnel and
            every later one narrows inside the previous. A partner scope line's
            field must be one of these names.
          items:
            $ref: '#/components/schemas/ScopeDimension'
          type:
            - array
            - 'null'
        levels:
          description: >-
            How wide one instance of each leveled resource is, per (resource,
            action). A partner is not granted a write on a resource wider than
            its scope. Absent when the product declares no level.
          items:
            $ref: '#/components/schemas/ScopeLevel'
          type:
            - array
            - 'null'
        partners:
          description: >-
            Whether the product accepts partner credentials. A partner can be
            granted the product only when true.
          examples:
            - true
          type: boolean
        product:
          description: Product slug, as returned by GET /v1/applications/available.
          examples:
            - midaz
          type: string
      required:
        - product
        - dimensions
        - partners
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
    ScopeDimension:
      additionalProperties: false
      properties:
        collection:
          description: >-
            The product collection the values are ids of. A partner scoped on
            this dimension may not list or create in this collection — that is
            where its siblings live.
          examples:
            - organizations
          type: string
        covers:
          description: >-
            Further product collections whose items each belong to ONE value of
            this dimension. A partner scoped on this dimension may not address
            them without naming its value. Absent when the dimension covers
            nothing beyond its own collection.
          examples:
            - - balances
              - operations
          items:
            type: string
          type:
            - array
            - 'null'
        from:
          description: >-
            Where the product reads the value from on its own routes: path,
            query, header or form.
          examples:
            - path
          type: string
        label:
          description: Display name for the dimension.
          examples:
            - Midaz organization
          type: string
        multi:
          description: >-
            A line for this dimension may carry more than one value; when false,
            more than one is refused with IDE-0002.
          examples:
            - false
          type: boolean
        name:
          description: The value to send as field on a partner scope line.
          examples:
            - organizationId
          type: string
        param:
          description: >-
            What carries the value on the product's routes: the path parameter,
            the query key, the header name (compared case-insensitively) or the
            form field.
          examples:
            - organization_id
          type: string
        parent:
          description: >-
            Name of the dimension of this catalog whose instances hold this
            one's: a ledger's parent is its organization. Absent for a top-level
            dimension.
          examples:
            - organizationId
          type: string
        required:
          description: >-
            A partner scoped on this product must carry a line for this
            dimension, else IDE-0001.
          examples:
            - true
          type: boolean
      required:
        - name
        - from
        - param
        - required
        - multi
        - collection
      type: object
    ScopeLevel:
      additionalProperties: false
      properties:
        action:
          description: Action of the permission.
          examples:
            - update
          type: string
        level:
          description: tenant, or a dimension name of the catalog.
          examples:
            - organizationId
          type: string
        resource:
          description: Resource the permission applies to.
          examples:
            - ledgers
          type: string
      required:
        - resource
        - action
        - level
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.