> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pinecone.io/llms.txt
> Use this file to discover all available pages before exploring further.

# List role bindings

> List role bindings in the caller's organization, optionally filtered by principal, resource, and role.


<RequestExample>
  ```bash curl theme={null}
  PINECONE_ACCESS_TOKEN="YOUR_ACCESS_TOKEN"

  curl -X GET "https://api.pinecone.io/admin/role-bindings?principal_type=user&principal_id=e2e92523-85dc-4142-b8c2-e681be8b78df" \
  	-H "Authorization: Bearer $PINECONE_ACCESS_TOKEN" \
  	-H "accept: application/json" \
  	-H "X-Pinecone-Api-Version: 2026-04"
  ```
</RequestExample>

<ResponseExample>
  ```json curl theme={null}
  {
    "data": [
      {
        "id": "5a86ed21-daf1-448d-a9ca-f92a0fd839d3",
        "principal_type": "user",
        "principal_id": "e2e92523-85dc-4142-b8c2-e681be8b78df",
        "resource_type": "organization",
        "resource_id": "-ExampleOrgId0000000",
        "role": "OrgMember",
        "created_at": "2026-04-10T15:23:00Z"
      }
    ],
    "pagination": {
      "next": "eyJsYXN0X2lkIjoiNWE4NmVkMjEifQ=="
    }
  }
  ```
</ResponseExample>


## OpenAPI

````yaml https://raw.githubusercontent.com/pinecone-io/pinecone-api/refs/heads/main/2026-04/admin_2026-04.oas.yaml get /admin/role-bindings
openapi: 3.0.3
info:
  title: Pinecone Admin API
  description: >
    Provides an API for managing a Pinecone organization and its resources,
    including projects, API keys, organization users and invites, service
    accounts, and role bindings.
  contact:
    name: Pinecone Support
    url: https://support.pinecone.io
    email: support@pinecone.io
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  version: 2026-04
servers:
  - url: https://api.pinecone.io
    description: Production API endpoints
security:
  - BearerAuth: []
tags:
  - name: API Keys
    description: Actions that manage API Keys.
  - name: Organizations
    description: Actions that manage organizations.
  - name: Projects
    description: Actions that manage projects.
  - name: Users
    description: >-
      Actions that manage users. Role bindings are not included in user
      responses; use the Role Bindings endpoints to view them.
  - name: Invites
    description: >-
      Actions that manage invites. An invite's role bindings are first-class and
      appear in the Role Bindings endpoints with `principal_type=invite`.
  - name: Service Accounts
    description: >-
      Actions that manage service accounts. Role bindings are not included in
      service account responses; use the Role Bindings endpoints to view them.
  - name: Role Bindings
    description: Actions that manage role bindings.
paths:
  /admin/role-bindings:
    get:
      tags:
        - Role Bindings
      summary: List role bindings
      description: >
        List role bindings in the caller's organization, optionally filtered by
        principal, resource, and role.
      operationId: list_role_bindings
      parameters:
        - in: header
          name: X-Pinecone-Api-Version
          description: Required date-based version header
          required: true
          schema:
            default: 2026-04
            type: string
          style: simple
        - in: query
          name: principal_type
          description: Filter by principal type. Required when `principal_id` is set.
          schema:
            example: service_account
            description: >-
              The kind of principal that receives permissions from a role
              binding.

              Possible values: `user`, `service_account`, `api_key`, `invite`.
            x-enum:
              - user
              - service_account
              - api_key
              - invite
            type: string
          style: form
        - in: query
          name: principal_id
          description: >-
            Filter by principal ID. Requires `principal_type`. The ID is a UUID
            for all principal types (user, service account, or invite).
          schema:
            type: string
          style: form
        - in: query
          name: resource_type
          description: Filter by resource type. Required when `resource_id` is set.
          schema:
            example: project
            description: |-
              The kind of resource scope a role binding applies to.
              Possible values: `organization`, `project`.
            x-enum:
              - organization
              - project
            type: string
          style: form
        - in: query
          name: resource_id
          description: Filter by resource ID. Requires `resource_type`.
          schema:
            type: string
          style: form
        - in: query
          name: role
          description: Filter by role.
          schema:
            example: ProjectOwner
            description: A role assigned to a principal at a resource scope.
            x-enum:
              - OrgOwner
              - OrgManager
              - OrgMember
              - OrgBillingAdmin
              - ProjectOwner
              - ProjectManager
              - ProjectMember
              - ProjectEditor
              - ProjectViewer
              - ControlPlaneEditor
              - ControlPlaneViewer
              - DataPlaneEditor
              - DataPlaneViewer
            type: string
          style: form
        - in: query
          name: limit
          description: >-
            The number of results to return per page. When omitted, the server
            defaults to 100. Out-of-range values return `400 OUT_OF_RANGE`.
          schema:
            default: 100
            type: integer
            minimum: 1
            maximum: 100
          style: form
        - in: query
          name: paginationToken
          description: >-
            Cursor from `pagination.next` of a prior response. Must be reused
            with the same query context (path parameters, filters, and `limit`).
          schema:
            type: string
          style: form
      responses:
        '200':
          description: >-
            A paginated list of role bindings. When multiple filters are
            supplied, they are combined with AND.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RoleBindingList'
              examples:
                org-scope-bindings:
                  summary: Org-scoped bindings
                  value:
                    data:
                      - created_at: '2026-04-10T15:23:00.000Z'
                        id: 5a86ed21-daf1-448d-a9ca-f92a0fd839d3
                        principal_id: e2e92523-85dc-4142-b8c2-e681be8b78df
                        principal_type: user
                        resource_id: '-ExampleOrgId0000000'
                        resource_type: organization
                        role: OrgMember
                    pagination:
                      next: eyJsYXN0X2lkIjoiNWE4NmVkMjEifQ==
        '400':
          description: Bad request. The request body included invalid request parameters.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                index-metric-validation-error:
                  summary: Validation error
                  value:
                    error:
                      code: INVALID_ARGUMENT
                      message: >-
                        Bad request. The request body included invalid request
                        parameters.
                    status: 400
        '401':
          description: 'Unauthorized. Possible causes: Invalid API key.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                unauthorized:
                  summary: Unauthorized
                  value:
                    error:
                      code: UNAUTHENTICATED
                      message: Invalid API key.
                    status: 401
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                internal-server-error:
                  summary: Internal server error
                  value:
                    error:
                      code: UNKNOWN
                      message: Internal server error
                    status: 500
        4XX:
          description: Unexpected error on request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
components:
  schemas:
    RoleBindingList:
      example:
        data:
          - created_at: '2026-04-10T15:23:00.000Z'
            id: 9a8e3528-b9c0-4358-84ce-84c28e91b566
            principal_id: f8a3b2c1-4d5e-6f7a-8b9c-0d1e2f3a4b5c
            principal_type: service_account
            resource_id: a2f7dddb-1597-4eff-9f71-535fde243f58
            resource_type: project
            role: DataPlaneEditor
        pagination:
          next: eyJsYXN0X2lkIjoiOWE4ZTM1MjgifQ==
      description: A paginated list of role bindings.
      type: object
      properties:
        data:
          description: The page of role bindings.
          type: array
          items:
            $ref: '#/components/schemas/RoleBinding'
        pagination:
          nullable: true
          description: >-
            Cursor envelope for the next page. `null` (or absent) on the final
            page of results.
          type: object
          allOf:
            - example:
                next: eyJsYXN0X2lkIjogImluZGV4LTQifQ==
              description: >-
                Pagination metadata for list responses. When `next` is present,
                pass it as `paginationToken` on the following request.
              x-component-name: PaginationResponse
              type: object
              properties:
                next:
                  example: eyJsYXN0X2lkIjogImluZGV4LTQifQ==
                  description: >-
                    Opaque cursor for the next page. Do not parse or construct.
                    Invalid or expired tokens return `400`.
                  type: string
      required:
        - data
    ErrorResponse:
      example:
        error:
          code: QUOTA_EXCEEDED
          message: >-
            The index exceeds the project quota of 5 pods by 2 pods. Upgrade
            your account or change the project settings to increase the quota.
        status: 429
      description: The response shape used for all error responses.
      type: object
      properties:
        status:
          example: 500
          description: The HTTP status code of the error.
          type: integer
        error:
          example:
            code: INVALID_ARGUMENT
            message: >-
              Index name must contain only lowercase alphanumeric characters or
              hyphens, and must not begin or end with a hyphen.
          description: Detailed information about the error that occurred.
          type: object
          properties:
            code:
              description: >-
                The error code.

                Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`,
                `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`,
                `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`,
                `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`,
                `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`,
                `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.        
              x-enum:
                - OK
                - UNKNOWN
                - INVALID_ARGUMENT
                - DEADLINE_EXCEEDED
                - QUOTA_EXCEEDED
                - NOT_FOUND
                - ALREADY_EXISTS
                - PERMISSION_DENIED
                - UNAUTHENTICATED
                - RESOURCE_EXHAUSTED
                - FAILED_PRECONDITION
                - ABORTED
                - OUT_OF_RANGE
                - UNIMPLEMENTED
                - INTERNAL
                - UNAVAILABLE
                - DATA_LOSS
                - FORBIDDEN
                - UNPROCESSABLE_ENTITY
              type: string
            message:
              example: >-
                Index name must contain only lowercase alphanumeric characters
                or hyphens, and must not begin or end with a hyphen.
              type: string
            details:
              description: >-
                Additional information about the error. This field is not
                guaranteed to be present.
              type: object
          required:
            - code
            - message
      required:
        - status
        - error
    RoleBinding:
      example:
        created_at: '2026-04-10T15:23:00.000Z'
        id: 9a8e3528-b9c0-4358-84ce-84c28e91b566
        principal_id: f8a3b2c1-4d5e-6f7a-8b9c-0d1e2f3a4b5c
        principal_type: service_account
        resource_id: a2f7dddb-1597-4eff-9f71-535fde243f58
        resource_type: project
        role: DataPlaneEditor
      description: Grants a `role` to a `principal` at a `resource` scope.
      type: object
      properties:
        id:
          description: The unique ID of the role binding.
          type: string
          format: uuid
        principal_type:
          example: service_account
          description: |-
            The kind of principal that receives permissions from a role binding.
            Possible values: `user`, `service_account`, `api_key`, `invite`.
          x-enum:
            - user
            - service_account
            - api_key
            - invite
          type: string
        principal_id:
          example: e2e92523-85dc-4142-b8c2-e681be8b78df
          description: >-
            The principal's ID. A UUID for all principal types (`user`,
            `service_account`, `api_key`, `invite`).
          type: string
        resource_type:
          example: project
          description: |-
            The kind of resource scope a role binding applies to.
            Possible values: `organization`, `project`.
          x-enum:
            - organization
            - project
          type: string
        resource_id:
          description: The organization or project that the binding is scoped to.
          type: string
        role:
          example: ProjectOwner
          description: A role assigned to a principal at a resource scope.
          x-enum:
            - OrgOwner
            - OrgManager
            - OrgMember
            - OrgBillingAdmin
            - ProjectOwner
            - ProjectManager
            - ProjectMember
            - ProjectEditor
            - ProjectViewer
            - ControlPlaneEditor
            - ControlPlaneViewer
            - DataPlaneEditor
            - DataPlaneViewer
          type: string
        created_at:
          description: When the role binding was created.
          type: string
          format: date-time
      required:
        - id
        - principal_type
        - principal_id
        - resource_type
        - resource_id
        - role
        - created_at
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >
        An [access
        token](https://docs.pinecone.io/guides/organizations/manage-service-accounts#retrieve-an-access-token)
        must be provided in the `Authorization` header using the `Bearer`
        scheme.

````