---
title: "Get App Resource Role"
method: GET
path: "/v2/app-resource-roles/{id}"
tags: ["App Resource Role API"]
---

# Get App Resource Role

`GET /v2/app-resource-roles/{id}`

Get a specific app resource role by ID.

## Path parameters

- `id` string, required — The ID of the role.

## Response `200`

Success

- SvflowPublicapiGetAppResourceRoleResponse
  - `data` SvflowPubapimodelsRole — Role represents a requestable role on an app resource.
    - `id` string — The ID of the role.
    - `resourceId` string — The ID of the resource that the role belongs to.
    - `name` string — The name of the role.
    - `description` string — A description of the role.
    - `requestsEnabled` boolean — Whether requests are enabled for the role.
    - `accessPolicyId` string, nullable — The default access policy for the role.
    - `provisioningMethod` union — Provisioning configuration for a role. Exactly one method should be set.
      - object
        - `builtinWorkflow` SvflowPubapimodelsBuiltinWorkflowProvisioning, required — Provisioning is handled by the service's builtin workflow integration.
      - object
        - `customWorkflow` SvflowPubapimodelsCustomWorkflowProvisioning, required — Provisioning is handled by custom workflows for provision + deprovision.
          - `provisionWorkflowId` string — The workflow ID to provision access.
          - `deprovisionWorkflowId` string — The workflow ID to deprovision access.
      - object
        - `linkedRoles` SvflowPubapimodelsLinkedRolesProvisioning, required — Provisioning depends on prerequisite roles being provisioned first.
          - `linkedRoleIds` string[] — The IDs of prerequisite roles.
      - object
        - `manual` SvflowPubapimodelsManualProvisioning, required — Provisioning is handled manually by assigned users/groups.
          - `assignees` SvflowPubapimodelsManualProvisioningAssignee[] — Users and groups that should be assigned/notified for manual provisioning.
            - `assigneeId` string — The ID of the user or group.
            - `assigneeType` 'MANUAL_PROVISIONING_ASSIGNEE_TYPE_UNSPECIFIED' | 'MANUAL_PROVISIONING_ASSIGNEE_TYPE_USER' | 'MANUAL_PROVISIONING_ASSIGNEE_TYPE_GROUP'
    - `externalId` string, nullable — The external ID of the role in the external system (optional).
    - `externalData` string, nullable — Data from the external system as a JSON string (computed by server).
    - `requireFormConfirmation` boolean
    - `tagIds` string[] — IDs of the tags currently attached to this role.
  - `owners` SvflowPubapimodelsAccessRelationship[] — The role's owners (users/groups with relationship_type=OWNER).
    - `id` string — The ID of the access relationship.
    - `relationshipType` 'ACCESS_RELATIONSHIP_TYPE_UNSPECIFIED' | 'ACCESS_RELATIONSHIP_TYPE_OWNER'
    - `targetId` string — The ID of the target (user or group).
    - `targetType` 'ACCESS_RELATIONSHIP_TARGET_TYPE_UNSPECIFIED' | 'ACCESS_RELATIONSHIP_TARGET_TYPE_USER' | 'ACCESS_RELATIONSHIP_TARGET_TYPE_GROUP'
    - `createdAt` string, date-time — A timestamp in RFC 3339 format (e.g., "2025-01-15T01:30:15Z").
    - `subjectType` 'ACCESS_RELATIONSHIP_SUBJECT_TYPE_UNSPECIFIED' | 'ACCESS_RELATIONSHIP_SUBJECT_TYPE_APP_INSTANCE' | 'ACCESS_RELATIONSHIP_SUBJECT_TYPE_RESOURCE' | 'ACCESS_RELATIONSHIP_SUBJECT_TYPE_ENTITLEMENT' | 'ACCESS_RELATIONSHIP_SUBJECT_TYPE_TEAM' — The kind of entity a relationship is on. Generalizes the former app_relationships model (app_instance subjects only) so resources, roles (entitlements), and teams can have owners too.
    - `subjectId` string — The ID of the subject (app_instance_id | resource_id | entitlement_id | team_id), disambiguated by subject_type.

## Other responses

- `default` — Error

---

[API](https://skmtc.net/serval/apis/serval-public-api.md) · [All operations](https://skmtc.net/serval/apis/serval-public-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/serval/serval-public-api/versions/0549515e9384/schema)
