> ## Documentation Index
> Fetch the complete documentation index at: https://docs.textql.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Who Am I

> Describe what a key is allowed to do.



## OpenAPI

````yaml api-reference/speakeasy/textql-api-with-code-samples.yaml POST /textql.rpc.public.rbac.RBACService/WhoAmI
openapi: 3.1.0
info:
  title: TextQL API
  version: 1.0.0
  description: |
    TextQL public API. Generated from protobuf service definitions; internal
    endpoints are excluded via google.api.visibility / file_visibility.
servers:
  - url: https://app.textql.com/rpc/public
security:
  - apiKey: []
tags:
  - name: DashboardService
  - name: AppService
    description: |-
      AppService manages data apps: the generative app execution primitive.
       An app is agent-authored single-file HTML/JS/CSS executing in a CSP sandbox,
       fed a snapshot of its declared data sources. First-class resource, not a dashboard.
  - name: ConnectorService
  - name: PowerBIService
  - name: TableauService
  - name: DatasetService
  - name: OntologyManagementService
  - name: ChatService
  - name: AgentService
  - name: SecretService
  - name: ApiOAuthService
  - name: AuditLogService
  - name: MCPService
  - name: MetricsExportService
  - name: ObservabilityService
  - name: PlaybookService
  - name: RBACService
    description: RBAC service for managing roles, permissions, and access control
  - name: SandboxAdminService
  - name: SandboxQueryService
  - name: SandboxCapabilityService
  - name: SandboxExecService
  - name: ScimService
  - name: SettingsService
  - name: SlackService
  - name: TeamsService
paths:
  /textql.rpc.public.rbac.RBACService/WhoAmI:
    post:
      tags:
        - RBACService
      summary: Describe what a key is allowed to do.
      description: Describe what a key is allowed to do.
      operationId: RBACService_WhoAmI
      parameters:
        - name: Connect-Protocol-Version
          in: header
          required: true
          schema:
            $ref: '#/components/schemas/connect-protocol-version'
        - name: Connect-Timeout-Ms
          in: header
          schema:
            $ref: '#/components/schemas/connect-timeout-header'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/textql.rpc.public.rbac.WhoAmIRequest'
        required: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/textql.rpc.public.rbac.WhoAmIResponse'
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
      x-codeSamples:
        - lang: typescript
          label: TypeScript (SDK)
          source: |-
            import { Textql } from "@textql/sdk";

            const textql = new Textql({
              apiKey: process.env["TEXTQL_API_KEY"] ?? "",
            });

            async function run() {
              const result = await textql.rbac.whoAmI({
                body: {},
              });

              console.log(result);
            }

            run();
        - lang: python
          label: Python (SDK)
          source: |-
            import os
            from textql_sdk import Textql


            with Textql(
                api_key=os.getenv("TEXTQL_API_KEY", ""),
            ) as textql:

                res = textql.rbac.who_am_i(body={})

                # Handle response
                print(res)
components:
  schemas:
    connect-protocol-version:
      type: number
      title: Connect-Protocol-Version
      enum:
        - 1
      description: Define the version of the Connect protocol
      const: 1
      default: 1
    connect-timeout-header:
      type: number
      title: Connect-Timeout-Ms
      description: Define the timeout, in ms
    textql.rpc.public.rbac.WhoAmIRequest:
      type: object
      title: WhoAmIRequest
      additionalProperties: false
      description: WhoAmI messages
    textql.rpc.public.rbac.WhoAmIResponse:
      type: object
      properties:
        memberId:
          type: string
          title: member_id
        orgId:
          type: string
          title: org_id
        email:
          type: string
          title: email
          nullable: true
        credential:
          $ref: '#/components/schemas/textql.rpc.public.rbac.CallerCredential'
          title: credential
        roles:
          type: array
          items:
            $ref: '#/components/schemas/textql.rpc.public.rbac.Role'
          title: roles
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/textql.rpc.public.rbac.Permission'
          title: permissions
        modelAccess:
          $ref: '#/components/schemas/textql.rpc.public.rbac.CallerModelAccess'
          title: model_access
        sharedAccess:
          type: array
          items:
            $ref: '#/components/schemas/textql.rpc.public.rbac.SharedObject'
          title: shared_access
        sharedAccessTruncated:
          type: boolean
          title: shared_access_truncated
      title: WhoAmIResponse
      additionalProperties: false
    connect.error:
      type: object
      properties:
        code:
          type: string
          examples:
            - not_found
          enum:
            - canceled
            - unknown
            - invalid_argument
            - deadline_exceeded
            - not_found
            - already_exists
            - permission_denied
            - resource_exhausted
            - failed_precondition
            - aborted
            - out_of_range
            - unimplemented
            - internal
            - unavailable
            - data_loss
            - unauthenticated
          description: >-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
        message:
          type: string
          description: >-
            A developer-facing error message, which should be in English. Any
            user-facing error message should be localized and sent in the
            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized by the client.
        details:
          type: array
          items:
            $ref: '#/components/schemas/connect.error_details.Any'
          description: >-
            A list of messages that carry the error details. There is no limit
            on the number of messages.
      title: Connect Error
      additionalProperties: true
      description: >-
        Error type returned by Connect:
        https://connectrpc.com/docs/go/errors/#http-representation
    textql.rpc.public.rbac.CallerCredential:
      type: object
      properties:
        authMethod:
          type: string
          title: auth_method
        apiKeyId:
          type: string
          title: api_key_id
          nullable: true
        apiKeyName:
          type: string
          title: api_key_name
          nullable: true
        apiKeyShort:
          type: string
          title: api_key_short
          nullable: true
        expiresAt:
          $ref: '#/components/schemas/google.protobuf.Timestamp'
          title: expires_at
          nullable: true
        status:
          $ref: '#/components/schemas/textql.rpc.public.rbac.ApiKeyStatus'
          title: status
        assumedRoleNames:
          type: array
          items:
            type: string
          title: assumed_role_names
          description: Current names of existing roles in the credential's scope.
        assumedRoleIds:
          type: array
          items:
            type: string
          title: assumed_role_ids
        clientId:
          type: string
          title: client_id
          nullable: true
        scopes:
          type: array
          items:
            type: string
          title: scopes
      title: CallerCredential
      additionalProperties: false
      description: The credential that authenticated the request.
    textql.rpc.public.rbac.Role:
      type: object
      properties:
        name:
          type: string
          title: name
          description: >-
            Unique within this organization; use as role_name when reading or
            updating.
        description:
          type: string
          title: description
        id:
          type: string
          title: id
        orgId:
          type: string
          title: org_id
        isSystem:
          type: boolean
          title: is_system
        createdAt:
          $ref: '#/components/schemas/google.protobuf.Timestamp'
          title: created_at
        updatedAt:
          $ref: '#/components/schemas/google.protobuf.Timestamp'
          title: updated_at
        allowedModels:
          type: array
          items:
            $ref: '#/components/schemas/textql.rpc.public.chat.LlmModel'
          title: allowed_models
        defaultModel:
          $ref: '#/components/schemas/textql.rpc.public.chat.LlmModel'
          title: default_model
          nullable: true
        allowModelChoice:
          type: boolean
          title: allow_model_choice
          nullable: true
        isScimManaged:
          type: boolean
          title: is_scim_managed
        color:
          type: string
          title: color
        icon:
          type: string
          title: icon
      title: Role
      additionalProperties: false
    textql.rpc.public.rbac.Permission:
      type: object
      properties:
        spec:
          $ref: '#/components/schemas/textql.rpc.public.rbac.PermissionSpec'
          title: spec
          description: >-
            Typed resource and action. Use this value when assigning or removing
            permissions.
        resource:
          type: string
          title: resource
        action:
          type: string
          title: action
        description:
          type: string
          title: description
        createdAt:
          $ref: '#/components/schemas/google.protobuf.Timestamp'
          title: created_at
      title: Permission
      additionalProperties: false
    textql.rpc.public.rbac.CallerModelAccess:
      type: object
      properties:
        allowedModels:
          type: array
          items:
            $ref: '#/components/schemas/textql.rpc.public.chat.LlmModel'
          title: allowed_models
        defaultModel:
          $ref: '#/components/schemas/textql.rpc.public.chat.LlmModel'
          title: default_model
        restricted:
          type: boolean
          title: restricted
      title: CallerModelAccess
      additionalProperties: false
      description: Which LLM models the caller may run.
    textql.rpc.public.rbac.SharedObject:
      type: object
      properties:
        objectType:
          type: string
          title: object_type
        objectId:
          type: string
          title: object_id
        accessType:
          type: string
          title: access_type
        grantedVia:
          type: string
          title: granted_via
        roleName:
          type: string
          title: role_name
          description: Current name of the role receiving access.
          nullable: true
        roleId:
          type: string
          title: role_id
          nullable: true
        expiresAt:
          $ref: '#/components/schemas/google.protobuf.Timestamp'
          title: expires_at
          nullable: true
        groupId:
          type: string
          title: group_id
          nullable: true
      title: SharedObject
      additionalProperties: false
    connect.error_details.Any:
      type: object
      properties:
        type:
          type: string
          description: >-
            A URL that acts as a globally unique identifier for the type of the
            serialized message. For example:
            `type.googleapis.com/google.rpc.ErrorInfo`. This is used to
            determine the schema of the data in the `value` field and is the
            discriminator for the `debug` field.
        value:
          type: string
          format: binary
          description: >-
            The Protobuf message, serialized as bytes and base64-encoded. The
            specific message type is identified by the `type` field.
        debug:
          oneOf:
            - type: object
              title: Any
              additionalProperties: true
              description: Detailed error information.
          discriminator:
            propertyName: type
          title: Debug
          description: >-
            Deserialized error detail payload. The 'type' field indicates the
            schema. This field is for easier debugging and should not be relied
            upon for application logic.
      additionalProperties: true
      description: >-
        Contains an arbitrary serialized message along with a @type that
        describes the type of the serialized message, with an additional debug
        field for ConnectRPC error details.
    google.protobuf.Timestamp:
      type: string
      examples:
        - '2023-01-15T01:30:15.01Z'
        - '2024-12-25T12:00:00Z'
      format: date-time
      description: >-
        A Timestamp represents a point in time independent of any time zone or
        local
         calendar, encoded as a count of seconds and fractions of seconds at
         nanosecond resolution. The count is relative to an epoch at UTC midnight on
         January 1, 1970, in the proleptic Gregorian calendar which extends the
         Gregorian calendar backwards to year one.

         All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap
         second table is needed for interpretation, using a [24-hour linear
         smear](https://developers.google.com/time/smear).

         The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By
         restricting to that range, we ensure that we can convert to and from [RFC
         3339](https://www.ietf.org/rfc/rfc3339.txt) date strings.

         # Examples

         Example 1: Compute Timestamp from POSIX `time()`.

             Timestamp timestamp;
             timestamp.set_seconds(time(NULL));
             timestamp.set_nanos(0);

         Example 2: Compute Timestamp from POSIX `gettimeofday()`.

             struct timeval tv;
             gettimeofday(&tv, NULL);

             Timestamp timestamp;
             timestamp.set_seconds(tv.tv_sec);
             timestamp.set_nanos(tv.tv_usec * 1000);

         Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`.

             FILETIME ft;
             GetSystemTimeAsFileTime(&ft);
             UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime;

             // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z
             // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z.
             Timestamp timestamp;
             timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL));
             timestamp.set_nanos((INT32) ((ticks % 10000000) * 100));

         Example 4: Compute Timestamp from Java `System.currentTimeMillis()`.

             long millis = System.currentTimeMillis();

             Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000)
                 .setNanos((int) ((millis % 1000) * 1000000)).build();

         Example 5: Compute Timestamp from Java `Instant.now()`.

             Instant now = Instant.now();

             Timestamp timestamp =
                 Timestamp.newBuilder().setSeconds(now.getEpochSecond())
                     .setNanos(now.getNano()).build();

         Example 6: Compute Timestamp from current time in Python.

             timestamp = Timestamp()
             timestamp.GetCurrentTime()

         # JSON Mapping

         In JSON format, the Timestamp type is encoded as a string in the
         [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the
         format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z"
         where {year} is always expressed using four digits while {month}, {day},
         {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional
         seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution),
         are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone
         is required. A ProtoJSON serializer should always use UTC (as indicated by
         "Z") when printing the Timestamp type and a ProtoJSON parser should be
         able to accept both UTC and other timezones (as indicated by an offset).

         For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past
         01:30 UTC on January 15, 2017.

         In JavaScript, one can convert a Date object to this format using the
         standard
         [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString)
         method. In Python, a standard `datetime.datetime` object can be converted
         to this format using
         [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with
         the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use
         the Joda Time's [`ISODateTimeFormat.dateTime()`](
         http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime()
         ) to obtain a formatter capable of generating timestamps in this format.
    textql.rpc.public.rbac.ApiKeyStatus:
      type: string
      title: ApiKeyStatus
      enum:
        - API_KEY_STATUS_UNSPECIFIED
        - API_KEY_STATUS_ACTIVE
        - API_KEY_STATUS_EXPIRED
        - API_KEY_STATUS_REVOKED
    textql.rpc.public.chat.LlmModel:
      type: string
      title: LlmModel
      enum:
        - MODEL_UNKNOWN
        - MODEL_DEFAULT
        - MODEL_DEFAULT_SYSTEM
        - MODEL_HAIKU_4_5
        - MODEL_OPUS_4_8
        - MODEL_FABLE_5
        - MODEL_SONNET_5
        - MODEL_OPUS_5
        - MODEL_FABLE_5_1
        - MODEL_OPUS_5_5
        - MODEL_SONNET_5_5
        - MODEL_GPT_5_6_SOL
        - MODEL_GEMINI_3_FLASH
        - MODEL_GEMINI_3_PRO
        - MODEL_GEMINI_3_1_PRO
        - MODEL_GEMINI_3_5_FLASH
        - MODEL_GEMINI_3_8_FLASH
        - MODEL_GPT_5_6_TERRA
        - MODEL_GPT_5_6_LUNA
        - MODEL_GPT_6_ASTRA
        - MODEL_GPT_6_SOL
        - MODEL_GPT_6_LUNA
        - MODEL_GPT_6_1_SOL
        - MODEL_DEEPSEEK_3_2
        - MODEL_GLM_5
        - MODEL_VLLM
        - MODEL_KIMI_K2_6
        - MODEL_GLM_5_2
        - MODEL_KIMI_K2_7_CODE
        - MODEL_QWEN3_7_PLUS
        - MODEL_KIMI_K3
        - MODEL_GLM_5_3_FLASH
        - MODEL_GLM_5_3
        - MODEL_DEEPSEEK_V4P1_FLASH
        - MODEL_MUSE_SPARK_1_1
        - MODEL_MUSE_SPARK_1_2
    textql.rpc.public.rbac.PermissionSpec:
      type: object
      oneOf:
        - type: object
          properties:
            agent:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.AgentPermissionAction
              title: agent
          title: agent
          required:
            - agent
        - type: object
          properties:
            apiAccessKey:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.ApiAccessKeyPermissionAction
              title: api_access_key
          title: api_access_key
          required:
            - apiAccessKey
        - type: object
          properties:
            auditLog:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.AuditLogPermissionAction
              title: audit_log
          title: audit_log
          required:
            - auditLog
        - type: object
          properties:
            billing:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.BillingPermissionAction
              title: billing
          title: billing
          required:
            - billing
        - type: object
          properties:
            chat:
              $ref: '#/components/schemas/textql.rpc.public.rbac.ChatPermissionAction'
              title: chat
          title: chat
          required:
            - chat
        - type: object
          properties:
            connector:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.ConnectorPermissionAction
              title: connector
          title: connector
          required:
            - connector
        - type: object
          properties:
            context:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.ContextPermissionAction
              title: context
          title: context
          required:
            - context
        - type: object
          properties:
            contextPolicy:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.ContextPolicyPermissionAction
              title: context_policy
          title: context_policy
          required:
            - contextPolicy
        - type: object
          properties:
            dashboard:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.DashboardPermissionAction
              title: dashboard
          title: dashboard
          required:
            - dashboard
        - type: object
          properties:
            dataset:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.DatasetPermissionAction
              title: dataset
          title: dataset
          required:
            - dataset
        - type: object
          properties:
            designSystem:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.DesignSystemPermissionAction
              title: design_system
          title: design_system
          required:
            - designSystem
        - type: object
          properties:
            feed:
              $ref: '#/components/schemas/textql.rpc.public.rbac.FeedPermissionAction'
              title: feed
          title: feed
          required:
            - feed
        - type: object
          properties:
            group:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.GroupPermissionAction
              title: group
          title: group
          required:
            - group
        - type: object
          properties:
            mcp:
              $ref: '#/components/schemas/textql.rpc.public.rbac.McpPermissionAction'
              title: mcp
          title: mcp
          required:
            - mcp
        - type: object
          properties:
            member:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.MemberPermissionAction
              title: member
          title: member
          required:
            - member
        - type: object
          properties:
            memory:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.MemoryPermissionAction
              title: memory
          title: memory
          required:
            - memory
        - type: object
          properties:
            observability:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.ObservabilityPermissionAction
              title: observability
          title: observability
          required:
            - observability
        - type: object
          properties:
            ontology:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.OntologyPermissionAction
              title: ontology
          title: ontology
          required:
            - ontology
        - type: object
          properties:
            organization:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.OrganizationPermissionAction
              title: organization
          title: organization
          required:
            - organization
        - type: object
          properties:
            packages:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.PackagesPermissionAction
              title: packages
          title: packages
          required:
            - packages
        - type: object
          properties:
            pipeline:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.PipelinePermissionAction
              title: pipeline
          title: pipeline
          required:
            - pipeline
        - type: object
          properties:
            playbook:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.PlaybookPermissionAction
              title: playbook
          title: playbook
          required:
            - playbook
        - type: object
          properties:
            role:
              $ref: '#/components/schemas/textql.rpc.public.rbac.RolePermissionAction'
              title: role
          title: role
          required:
            - role
        - type: object
          properties:
            rolePermission:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.RolePermissionPermissionAction
              title: role_permission
          title: role_permission
          required:
            - rolePermission
        - type: object
          properties:
            sandbox:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.SandboxPermissionAction
              title: sandbox
          title: sandbox
          required:
            - sandbox
        - type: object
          properties:
            scim:
              $ref: '#/components/schemas/textql.rpc.public.rbac.ScimPermissionAction'
              title: scim
          title: scim
          required:
            - scim
        - type: object
          properties:
            secret:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.SecretPermissionAction
              title: secret
          title: secret
          required:
            - secret
        - type: object
          properties:
            usage:
              $ref: >-
                #/components/schemas/textql.rpc.public.rbac.UsagePermissionAction
              title: usage
          title: usage
          required:
            - usage
      title: PermissionSpec
      additionalProperties: false
      description: >-
        A single RBAC permission. Select a resource and one of its supported
        actions.
    textql.rpc.public.rbac.AgentPermissionAction:
      type: string
      title: AgentPermissionAction
      enum:
        - AGENT_ACTION_UNSPECIFIED
        - AGENT_ACTION_READ
        - AGENT_ACTION_READ_PRIVATE
        - AGENT_ACTION_WRITE
        - AGENT_ACTION_WRITE_PRIVATE
    textql.rpc.public.rbac.ApiAccessKeyPermissionAction:
      type: string
      title: ApiAccessKeyPermissionAction
      enum:
        - API_ACCESS_KEY_ACTION_UNSPECIFIED
        - API_ACCESS_KEY_ACTION_DELEGATE
        - API_ACCESS_KEY_ACTION_READ
        - API_ACCESS_KEY_ACTION_READ_PRIVATE
        - API_ACCESS_KEY_ACTION_WRITE
        - API_ACCESS_KEY_ACTION_WRITE_PRIVATE
    textql.rpc.public.rbac.AuditLogPermissionAction:
      type: string
      title: AuditLogPermissionAction
      enum:
        - AUDIT_LOG_ACTION_UNSPECIFIED
        - AUDIT_LOG_ACTION_READ
    textql.rpc.public.rbac.BillingPermissionAction:
      type: string
      title: BillingPermissionAction
      enum:
        - BILLING_ACTION_UNSPECIFIED
        - BILLING_ACTION_READ
    textql.rpc.public.rbac.ChatPermissionAction:
      type: string
      title: ChatPermissionAction
      enum:
        - CHAT_ACTION_UNSPECIFIED
        - CHAT_ACTION_READ
        - CHAT_ACTION_READ_PRIVATE
        - CHAT_ACTION_WRITE
        - CHAT_ACTION_WRITE_PRIVATE
    textql.rpc.public.rbac.ConnectorPermissionAction:
      type: string
      title: ConnectorPermissionAction
      enum:
        - CONNECTOR_ACTION_UNSPECIFIED
        - CONNECTOR_ACTION_RAW_SQL
        - CONNECTOR_ACTION_READ
        - CONNECTOR_ACTION_READ_PRIVATE
        - CONNECTOR_ACTION_WRITE
        - CONNECTOR_ACTION_WRITE_PRIVATE
    textql.rpc.public.rbac.ContextPermissionAction:
      type: string
      title: ContextPermissionAction
      enum:
        - CONTEXT_ACTION_UNSPECIFIED
        - CONTEXT_ACTION_READ
        - CONTEXT_ACTION_READ_PRIVATE
        - CONTEXT_ACTION_WRITE
        - CONTEXT_ACTION_WRITE_PRIVATE
    textql.rpc.public.rbac.ContextPolicyPermissionAction:
      type: string
      title: ContextPolicyPermissionAction
      enum:
        - CONTEXT_POLICY_ACTION_UNSPECIFIED
        - CONTEXT_POLICY_ACTION_READ
        - CONTEXT_POLICY_ACTION_WRITE
    textql.rpc.public.rbac.DashboardPermissionAction:
      type: string
      title: DashboardPermissionAction
      enum:
        - DASHBOARD_ACTION_UNSPECIFIED
        - DASHBOARD_ACTION_READ
        - DASHBOARD_ACTION_READ_PRIVATE
        - DASHBOARD_ACTION_WRITE
        - DASHBOARD_ACTION_WRITE_PRIVATE
    textql.rpc.public.rbac.DatasetPermissionAction:
      type: string
      title: DatasetPermissionAction
      enum:
        - DATASET_ACTION_UNSPECIFIED
        - DATASET_ACTION_READ
        - DATASET_ACTION_READ_PRIVATE
        - DATASET_ACTION_WRITE
        - DATASET_ACTION_WRITE_PRIVATE
    textql.rpc.public.rbac.DesignSystemPermissionAction:
      type: string
      title: DesignSystemPermissionAction
      enum:
        - DESIGN_SYSTEM_ACTION_UNSPECIFIED
        - DESIGN_SYSTEM_ACTION_WRITE
    textql.rpc.public.rbac.FeedPermissionAction:
      type: string
      title: FeedPermissionAction
      enum:
        - FEED_ACTION_UNSPECIFIED
        - FEED_ACTION_READ
        - FEED_ACTION_READ_PRIVATE
        - FEED_ACTION_WRITE
        - FEED_ACTION_WRITE_PRIVATE
    textql.rpc.public.rbac.GroupPermissionAction:
      type: string
      title: GroupPermissionAction
      enum:
        - GROUP_ACTION_UNSPECIFIED
        - GROUP_ACTION_READ
        - GROUP_ACTION_WRITE
    textql.rpc.public.rbac.McpPermissionAction:
      type: string
      title: McpPermissionAction
      enum:
        - MCP_ACTION_UNSPECIFIED
        - MCP_ACTION_READ
        - MCP_ACTION_WRITE
    textql.rpc.public.rbac.MemberPermissionAction:
      type: string
      title: MemberPermissionAction
      enum:
        - MEMBER_ACTION_UNSPECIFIED
        - MEMBER_ACTION_READ
        - MEMBER_ACTION_WRITE
    textql.rpc.public.rbac.MemoryPermissionAction:
      type: string
      title: MemoryPermissionAction
      enum:
        - MEMORY_ACTION_UNSPECIFIED
        - MEMORY_ACTION_WRITE
    textql.rpc.public.rbac.ObservabilityPermissionAction:
      type: string
      title: ObservabilityPermissionAction
      enum:
        - OBSERVABILITY_ACTION_UNSPECIFIED
        - OBSERVABILITY_ACTION_READ
        - OBSERVABILITY_ACTION_WRITE
    textql.rpc.public.rbac.OntologyPermissionAction:
      type: string
      title: OntologyPermissionAction
      enum:
        - ONTOLOGY_ACTION_UNSPECIFIED
        - ONTOLOGY_ACTION_READ
        - ONTOLOGY_ACTION_READ_PRIVATE
        - ONTOLOGY_ACTION_WRITE
        - ONTOLOGY_ACTION_WRITE_PRIVATE
    textql.rpc.public.rbac.OrganizationPermissionAction:
      type: string
      title: OrganizationPermissionAction
      enum:
        - ORGANIZATION_ACTION_UNSPECIFIED
        - ORGANIZATION_ACTION_READ
        - ORGANIZATION_ACTION_WRITE
    textql.rpc.public.rbac.PackagesPermissionAction:
      type: string
      title: PackagesPermissionAction
      enum:
        - PACKAGES_ACTION_UNSPECIFIED
        - PACKAGES_ACTION_READ
        - PACKAGES_ACTION_WRITE
    textql.rpc.public.rbac.PipelinePermissionAction:
      type: string
      title: PipelinePermissionAction
      enum:
        - PIPELINE_ACTION_UNSPECIFIED
        - PIPELINE_ACTION_READ
        - PIPELINE_ACTION_RUN
        - PIPELINE_ACTION_WRITE
    textql.rpc.public.rbac.PlaybookPermissionAction:
      type: string
      title: PlaybookPermissionAction
      enum:
        - PLAYBOOK_ACTION_UNSPECIFIED
        - PLAYBOOK_ACTION_READ
        - PLAYBOOK_ACTION_READ_PRIVATE
        - PLAYBOOK_ACTION_WRITE
        - PLAYBOOK_ACTION_WRITE_PRIVATE
    textql.rpc.public.rbac.RolePermissionAction:
      type: string
      title: RolePermissionAction
      enum:
        - ROLE_ACTION_UNSPECIFIED
        - ROLE_ACTION_READ
        - ROLE_ACTION_WRITE
    textql.rpc.public.rbac.RolePermissionPermissionAction:
      type: string
      title: RolePermissionPermissionAction
      enum:
        - ROLE_PERMISSION_ACTION_UNSPECIFIED
        - ROLE_PERMISSION_ACTION_READ
        - ROLE_PERMISSION_ACTION_WRITE
    textql.rpc.public.rbac.SandboxPermissionAction:
      type: string
      title: SandboxPermissionAction
      enum:
        - SANDBOX_ACTION_UNSPECIFIED
        - SANDBOX_ACTION_READ
        - SANDBOX_ACTION_READ_PRIVATE
        - SANDBOX_ACTION_WRITE
        - SANDBOX_ACTION_WRITE_PRIVATE
    textql.rpc.public.rbac.ScimPermissionAction:
      type: string
      title: ScimPermissionAction
      enum:
        - SCIM_ACTION_UNSPECIFIED
        - SCIM_ACTION_READ
        - SCIM_ACTION_WRITE
    textql.rpc.public.rbac.SecretPermissionAction:
      type: string
      title: SecretPermissionAction
      enum:
        - SECRET_ACTION_UNSPECIFIED
        - SECRET_ACTION_READ
        - SECRET_ACTION_READ_PRIVATE
        - SECRET_ACTION_WRITE
        - SECRET_ACTION_WRITE_PRIVATE
    textql.rpc.public.rbac.UsagePermissionAction:
      type: string
      title: UsagePermissionAction
      enum:
        - USAGE_ACTION_UNSPECIFIED
        - USAGE_ACTION_READ
  securitySchemes:
    apiKey:
      type: apiKey
      in: header
      name: tql_api_key

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.