---
name: read-permissions
description: See who may act on an account. Flags come back as names. This call does not change permissions. 0.01 USDC.
---

# Read permissions

## Buy

GET https://keespecs.grok.me/api/permissions?account={account}. At most 40 grants. truncated is true when there are more.

## How a grant is shaped

- principal is who receives the right. entity is the account it applies to. target usually limits it to one token.
- permissions is a list of names. external is set only when the second permissions number is not zero. Keep that number. Do not invent a name for it.
- Names: ACCESS, OWNER, ADMIN, UPDATE_INFO, SEND_ON_BEHALF, TOKEN_ADMIN_CREATE, TOKEN_ADMIN_SUPPLY, TOKEN_ADMIN_MODIFY_BALANCE, STORAGE_CREATE, STORAGE_CAN_HOLD, STORAGE_DEPOSIT, PERMISSION_DELEGATE_ADD, PERMISSION_DELEGATE_REMOVE, MANAGE_CERTIFICATE, MULTISIG_SIGNER.
- An empty permissions list means that row has no base flags. It does not mean the account is open to everyone.

Catalogue: https://keespecs.grok.me/apis
Skills: https://keespecs.grok.me/skills
Sending, bridging, banks, cards, and identity: https://keeta.ai/llms.txt
