> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plungeai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get permissions

> A bot’s permission presets, admin locks and spend caps.


## OpenAPI

```yaml openapi.json get /v1/workflows/{id}/permissions
openapi: 3.1.0
info:
  title: Ocean One API
  version: 2.3.1
servers:
  - url: https://api.plungeai.com
paths:
  /v1/workflows/{id}/permissions:
    get:
      operationId: get-v1-workflows-id-permissions
      tags:
        - Bots
      summary: A bot’s permission presets, admin locks and spend caps
      description: The policy the engine applies to every run of the bot, from every door. Owner only.
      security:
        - ozkBearer: []
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
          description: Saved workflow id (a bot you own)
      responses:
        "200":
          description: Stored policy and its effective classes Response format negotiates via the `format` field, an Accept header (application/json, text/yaml, text/markdown, text/plain), or the request Content-Type mirror; default JSON.
          content:
            application/json:
              schema:
                type: object
                properties:
                  classes:
                    type: object
                    description: Stored preset per permission class; a class absent here falls back to the bot YAML / default
                    additionalProperties:
                      type: string
                      enum:
                        - allow
                        - ask
                        - deny
                        - hand_off
                    propertyNames:
                      enum:
                        - send
                        - write
                        - pay
                        - delete
                  locks:
                    type: array
                    items:
                      type: string
                      enum:
                        - send
                        - write
                        - pay
                        - delete
                    description: "Admin locks: a locked class forces the bot’s own `allow` up to `ask`"
                  budget_usd_run:
                    type:
                      - number
                      - "null"
                    minimum: 0
                    description: Per-run spend cap in USD; null = none
                  budget_usd_month:
                    type:
                      - number
                      - "null"
                    minimum: 0
                    description: Monthly spend cap in USD; null = none
                  effective:
                    type: object
                    description: "The preset each class runs under: the stored one (the engine applies it on every run, from every door), else `allow` — a class no preset names is let through. A locked class still lifts `allow` to `ask`, and the money floor always asks. `hand_off` is a One Agent verdict; other agent runtimes treat it as `deny`."
                    properties:
                      send:
                        type: string
                        enum:
                          - allow
                          - ask
                          - deny
                          - hand_off
                      write:
                        type: string
                        enum:
                          - allow
                          - ask
                          - deny
                          - hand_off
                      pay:
                        type: string
                        enum:
                          - allow
                          - ask
                          - deny
                          - hand_off
                      delete:
                        type: string
                        enum:
                          - allow
                          - ask
                          - deny
                          - hand_off
            text/yaml:
              schema:
                type: string
            text/markdown:
              schema:
                type: string
            text/plain:
              schema:
                type: string
        "400":
          description: invalid_format — format must be one of json, yaml, markdown, text
          content:
            application/json:
              schema:
                $ref: "#/components/schemas/Error"
        "401":
          description: unauthorized — missing, invalid or revoked ozk_ key
          content:
            application/json:
              schema:
                $ref: "#/components/schemas/Error"
        "404":
          description: "workflow_not_found — no saved workflow with that id for this account (foreign and missing ids answer alike); not_found — no route for this method on this path: every other method answers it"
          content:
            application/json:
              schema:
                $ref: "#/components/schemas/Error"
components:
  schemas:
    Error:
      type: object
      description: Standard error envelope. Every error response also carries an `X-Error-Code` response header equal to error.code, so a client branches on the header regardless of the negotiated body format (json | yaml | markdown | text). When the request created an execution, the `X-Execution-Id` response header is also set. Errors follow the negotiated format like success bodies.
      properties:
        error:
          type: object
          properties:
            code:
              type: string
            message:
              type: string
            connect:
              type: object
              description: "On a 424 connection_required / credential_required: where the missing connection is made."
              properties:
                provider:
                  type: string
                method:
                  type: string
                  enum:
                    - oauth
                    - api_key
                    - wallet
                link:
                  type: string
                  example: POST /v1/connections/stripe/link
          required:
            - code
            - message
          additionalProperties: true
      required:
        - error
  securitySchemes:
    ozkBearer:
      type: http
      scheme: bearer
      description: "ozk_ platform API key (Authorization: Bearer ozk_…)"
```
