> ## Documentation Index
> Fetch the complete documentation index at: https://docs.artbucket.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Who can reach it, and why

> Scope: `read`.



## OpenAPI

````yaml /openapi.json get /api/v1/catalog/{ref}/access
openapi: 3.1.0
info:
  title: artbucket
  version: '1'
  description: >-
    Agent-first asset management. The web UI is built on this API and nothing
    else, beside signing in at /api/auth. Send `Authorization: Bearer <key>`: a
    key works in one project with one scope, and scopes are a ladder: read <
    propose < write < admin. People signed in to the app carry a session cookie
    instead, and their scope is what their grants add up to: on the
    organization, the project, or single collections and assets. A scope shown
    as needed on the project is also enough on the one collection or asset a
    route acts on. Agents (MCP at POST /api/v1/mcp) usually get `propose`: what
    they add waits for a human.
servers:
  - url: http://localhost:3000
security:
  - bearer: []
  - session: []
  - {}
paths:
  /api/v1/catalog/{ref}/access:
    parameters:
      - name: ref
        in: path
        required: true
        schema:
          type: string
        description: An id, or an address
    get:
      summary: Who can reach it, and why
      description: 'Scope: `read`.'
      parameters:
        - name: who
          in: query
          schema:
            type: string
          description: One person, by id or email
      responses:
        '200':
          description: Holders
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                    format: uuid
                    pattern: >-
                      ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                  name:
                    type: string
                  private:
                    type: boolean
                  holders:
                    type: array
                    items:
                      type: object
                      properties:
                        kind:
                          type: string
                        who:
                          type: string
                        role:
                          type: string
                        scope:
                          type:
                            - string
                            - 'null'
                        via:
                          type: string
                      required:
                        - kind
                        - who
                        - role
                        - scope
                        - via
                      additionalProperties: false
                  'on':
                    anyOf:
                      - type: object
                        properties:
                          type:
                            type: string
                            enum:
                              - asset
                              - brand
                              - collection
                          id:
                            type: string
                            format: uuid
                            pattern: >-
                              ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                          name:
                            type: string
                        required:
                          - type
                          - id
                          - name
                        additionalProperties: false
                      - type: 'null'
                    description: >-
                      What takes a grant here (a rule's or a page's brand); POST
                      /api/v1/grants with it. Null for a portal
                  granted:
                    type: array
                    items:
                      type: object
                      properties:
                        grant:
                          type: string
                          format: uuid
                          pattern: >-
                            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                        kind:
                          type: string
                          enum:
                            - person
                            - group
                        id:
                          type: string
                        who:
                          type: string
                        scope:
                          type: string
                      required:
                        - grant
                        - kind
                        - id
                        - who
                        - scope
                      additionalProperties: false
                    description: >-
                      The grants made on it, each changed with POST
                      /api/v1/grants or taken back with DELETE
                      /api/v1/grants/{grant}
                required:
                  - id
                  - name
                  - private
                  - holders
                  - 'on'
                  - granted
                additionalProperties: false
        default:
          description: An error
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                      message:
                        type: string
                      detail: {}
                    required:
                      - code
                      - message
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
components:
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      description: 'An API key: ab_...'
    session:
      type: apiKey
      in: cookie
      name: better-auth.session_token
      description: Signed in, at /api/auth

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.