Version
READ

list_roles

List roles across every team the caller owns or belongs to. Each role carries a flat permission list.

List roles across every team the caller owns or belongs to. Each role carries a flat permissions array — the same ability codes a token would use. Ordered newest-first.

Requires ability

The token behind the MCP session must hold it, or the call is refused with TOKEN_MISSING_ABILITY.

Runs the same action as

The REST endpoint and this tool share one action, so validation, permissions and events are identical.

Annotations

Read-only

It reads and never changes anything.

Arguments

This tool takes no arguments.

What it returns

{  "data": [    {      "id": "d05e1a83-7c46-4f29-b613-8ae407c9d251",      "team_id": "a83f0d51-4c92-4b7e-8615-2fd9e70a3c86",      "code": "manager",      "name": "Manager",      "description": "Manage plans, resources, and subscribers",      "permissions": ["project:view", "project:update", "project-user:update"],      "created_at": "2026-05-18T10:05:00Z"    }  ],  "meta": { "total": 3 }}

How it fails

AUTHENTICATION_REQUIRED

no authenticated user on the request.

TOKEN_MISSING_ABILITY

token lacks role:view-any.

How is this guide?

Last updated on