> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pinecone.io/llms.txt
> Use this file to discover all available pages before exploring further.

# List role bindings

> List role bindings in the organization. Results are paginated.
Optional filters are described in the query parameters. Filters are combined with AND. Pagination tokens apply to the full query (including all filters).


<RequestExample>
  ```bash curl theme={null}
  PINECONE_ACCESS_TOKEN="YOUR_ACCESS_TOKEN"

  curl -X GET "https://api.pinecone.io/admin/role-bindings?principal_type=user&principal_id=e2e92523-85dc-4142-b8c2-e681be8b78df" \
  	-H "Authorization: Bearer $PINECONE_ACCESS_TOKEN" \
  	-H "accept: application/json" \
  	-H "X-Pinecone-Api-Version: 2026-04"
  ```
</RequestExample>

<ResponseExample>
  ```json curl theme={null}
  {
    "data": [
      {
        "id": "5a86ed21-daf1-448d-a9ca-f92a0fd839d3",
        "principal_type": "user",
        "principal_id": "e2e92523-85dc-4142-b8c2-e681be8b78df",
        "resource_type": "organization",
        "resource_id": "-ExampleOrgId0000000",
        "role": "OrgMember",
        "created_at": "2026-04-10T15:23:00Z"
      }
    ],
    "pagination": {
      "next": "eyJsYXN0X2lkIjoiNWE4NmVkMjEifQ=="
    }
  }
  ```
</ResponseExample>


## OpenAPI

````yaml https://raw.githubusercontent.com/pinecone-io/pinecone-api/refs/heads/main/2026-04/admin_2026-04.oas.yaml get /admin/role-bindings
openapi: 3.0.3
info:
  title: Pinecone Admin API
  description: >
    Provides an API for managing a Pinecone organization and its resources,
    including projects, API keys, organization users and invites, service
    accounts, and role bindings.
  contact:
    name: Pinecone Support
    url: https://support.pinecone.io
    email: support@pinecone.io
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  version: 2026-04
servers:
  - url: https://api.pinecone.io
    description: Production API endpoints
security:
  - BearerAuth: []
tags:
  - name: API Keys
    description: Actions that manage API Keys.
  - name: Organizations
    description: Actions that manage organizations.
  - name: Projects
    description: Actions that manage projects.
  - name: Users
    description: Actions that manage users.
  - name: Invites
    description: Actions that manage invites.
  - name: Service Accounts
    description: Actions that manage service accounts.
  - name: Role Bindings
    description: Actions that manage role bindings.
paths:
  /admin/role-bindings:
    get:
      tags:
        - Role Bindings
      summary: List role bindings
      description: >
        List role bindings in the organization. Results are paginated.

        Optional filters are described in the query parameters. Filters are
        combined with AND. Pagination tokens apply to the full query (including
        all filters).
      operationId: list_role_bindings
      parameters:
        - in: header
          name: X-Pinecone-Api-Version
          description: Required date-based version header
          required: true
          schema:
            default: 2026-04
            type: string
          style: simple
        - in: query
          name: principal_type
          description: Filter by principal type. Required when `principal_id` is set.
          schema:
            example: service_account
            description: >-
              The kind of principal that receives permissions from a role
              binding.

              Possible values: `user`, `service_account`, `api_key`, `invite`.
            x-enum:
              - user
              - service_account
              - api_key
              - invite
            type: string
          style: form
        - in: query
          name: principal_id
          description: >-
            Filter by principal ID. Requires `principal_type`. The ID is a UUID
            for all principal types (user, service account, or invite).
          schema:
            type: string
          style: form
        - in: query
          name: resource_type
          description: Filter by resource type. Required when `resource_id` is set.
          schema:
            example: project
            description: |-
              The kind of resource scope a role binding applies to.
              Possible values: `organization`, `project`.
            x-enum:
              - organization
              - project
            type: string
          style: form
        - in: query
          name: resource_id
          description: Filter by resource ID. Requires `resource_type`.
          schema:
            type: string
          style: form
        - in: query
          name: role
          description: Filter by role.
          schema:
            example: ProjectOwner
            description: A role assigned to a principal at a resource scope.
            x-enum:
              - OrgOwner
              - OrgManager
              - OrgMember
              - OrgBillingAdmin
              - ProjectOwner
              - ProjectManager
              - ProjectMember
              - ProjectEditor
              - ProjectViewer
              - ControlPlaneEditor
              - ControlPlaneViewer
              - DataPlaneEditor
              - DataPlaneViewer
            type: string
          style: form
        - in: query
          name: limit
          description: >-
            The number of results to return per page. When omitted, the server
            defaults to 100. Out-of-range values return `400 OUT_OF_RANGE`.
          schema:
            default: 100
            type: integer
            minimum: 1
            maximum: 100
          style: form
        - in: query
          name: paginationToken
          description: >-
            Cursor from `pagination.next` of a prior response. Must be reused
            with the same query context (path parameters, filters, and `limit`).
          schema:
            type: string
          style: form
      responses:
        '200':
          description: A paginated list of role bindings.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RoleBindingList'
              examples:
                org-scope-bindings:
                  summary: Org-scoped bindings
                  value:
                    data:
                      - created_at: '2026-04-10T15:23:00.000Z'
                        id: 5a86ed21-daf1-448d-a9ca-f92a0fd839d3
                        principal_id: e2e92523-85dc-4142-b8c2-e681be8b78df
                        principal_type: user
                        resource_id: '-ExampleOrgId0000000'
                        resource_type: organization
                        role: OrgMember
                    pagination:
                      next: eyJsYXN0X2lkIjoiNWE4NmVkMjEifQ==
        '400':
          description: Bad request. The request body included invalid request parameters.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                index-metric-validation-error:
                  summary: Validation error
                  value:
                    error:
                      code: INVALID_ARGUMENT
                      message: >-
                        Bad request. The request body included invalid request
                        parameters.
                    status: 400
        '401':
          description: 'Unauthorized. Possible causes: Invalid API key.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                unauthorized:
                  summary: Unauthorized
                  value:
                    error:
                      code: UNAUTHENTICATED
                      message: Invalid API key.
                    status: 401
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                internal-server-error:
                  summary: Internal server error
                  value:
                    error:
                      code: UNKNOWN
                      message: Internal server error
                    status: 500
        4XX:
          description: Unexpected error on request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
components:
  schemas:
    RoleBindingList:
      example:
        data:
          - created_at: '2026-04-10T15:23:00.000Z'
            id: 9a8e3528-b9c0-4358-84ce-84c28e91b566
            principal_id: f8a3b2c1-4d5e-6f7a-8b9c-0d1e2f3a4b5c
            principal_type: service_account
            resource_id: a2f7dddb-1597-4eff-9f71-535fde243f58
            resource_type: project
            role: DataPlaneEditor
        pagination:
          next: eyJsYXN0X2lkIjoiOWE4ZTM1MjgifQ==
      description: A paginated list of role bindings.
      type: object
      properties:
        data:
          description: The page of role bindings.
          type: array
          items:
            $ref: '#/components/schemas/RoleBinding'
        pagination:
          nullable: true
          description: >-
            Cursor envelope for the next page. `null` (or absent) on the final
            page of results.
          type: object
          allOf:
            - example:
                next: eyJsYXN0X2lkIjogImluZGV4LTQifQ==
              description: >-
                Pagination metadata for list responses. When `next` is present,
                pass it as `paginationToken` on the following request.
              x-component-name: PaginationResponse
              type: object
              properties:
                next:
                  example: eyJsYXN0X2lkIjogImluZGV4LTQifQ==
                  description: >-
                    Opaque cursor for the next page. Do not parse or construct.
                    Invalid or expired tokens return `400`.
                  type: string
      required:
        - data
    ErrorResponse:
      example:
        error:
          code: QUOTA_EXCEEDED
          message: >-
            The index exceeds the project quota of 5 pods by 2 pods. Upgrade
            your account or change the project settings to increase the quota.
        status: 429
      description: The response shape used for all error responses.
      type: object
      properties:
        status:
          example: 500
          description: The HTTP status code of the error.
          type: integer
        error:
          example:
            code: INVALID_ARGUMENT
            message: >-
              Index name must contain only lowercase alphanumeric characters or
              hyphens, and must not begin or end with a hyphen.
          description: Detailed information about the error that occurred.
          type: object
          properties:
            code:
              description: >-
                The error code.

                Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`,
                `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`,
                `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`,
                `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`,
                `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`,
                `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.        
              x-enum:
                - OK
                - UNKNOWN
                - INVALID_ARGUMENT
                - DEADLINE_EXCEEDED
                - QUOTA_EXCEEDED
                - NOT_FOUND
                - ALREADY_EXISTS
                - PERMISSION_DENIED
                - UNAUTHENTICATED
                - RESOURCE_EXHAUSTED
                - FAILED_PRECONDITION
                - ABORTED
                - OUT_OF_RANGE
                - UNIMPLEMENTED
                - INTERNAL
                - UNAVAILABLE
                - DATA_LOSS
                - FORBIDDEN
                - UNPROCESSABLE_ENTITY
              type: string
            message:
              example: >-
                Index name must contain only lowercase alphanumeric characters
                or hyphens, and must not begin or end with a hyphen.
              type: string
            details:
              description: >-
                Additional information about the error. This field is not
                guaranteed to be present.
              type: object
          required:
            - code
            - message
      required:
        - status
        - error
    RoleBinding:
      example:
        created_at: '2026-04-10T15:23:00.000Z'
        id: 9a8e3528-b9c0-4358-84ce-84c28e91b566
        principal_id: f8a3b2c1-4d5e-6f7a-8b9c-0d1e2f3a4b5c
        principal_type: service_account
        resource_id: a2f7dddb-1597-4eff-9f71-535fde243f58
        resource_type: project
        role: DataPlaneEditor
      description: Grants a `role` to a `principal` at a `resource` scope.
      type: object
      properties:
        id:
          description: The unique ID of the role binding.
          type: string
          format: uuid
        principal_type:
          example: service_account
          description: |-
            The kind of principal that receives permissions from a role binding.
            Possible values: `user`, `service_account`, `api_key`, `invite`.
          x-enum:
            - user
            - service_account
            - api_key
            - invite
          type: string
        principal_id:
          example: e2e92523-85dc-4142-b8c2-e681be8b78df
          description: >-
            The principal's ID. A UUID for all principal types (`user`,
            `service_account`, `api_key`, `invite`).
          type: string
        resource_type:
          example: project
          description: |-
            The kind of resource scope a role binding applies to.
            Possible values: `organization`, `project`.
          x-enum:
            - organization
            - project
          type: string
        resource_id:
          description: The organization or project that the binding is scoped to.
          type: string
        role:
          example: ProjectOwner
          description: A role assigned to a principal at a resource scope.
          x-enum:
            - OrgOwner
            - OrgManager
            - OrgMember
            - OrgBillingAdmin
            - ProjectOwner
            - ProjectManager
            - ProjectMember
            - ProjectEditor
            - ProjectViewer
            - ControlPlaneEditor
            - ControlPlaneViewer
            - DataPlaneEditor
            - DataPlaneViewer
          type: string
        created_at:
          description: When the role binding was created.
          type: string
          format: date-time
      required:
        - id
        - principal_type
        - principal_id
        - resource_type
        - resource_id
        - role
        - created_at
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >
        An [access
        token](https://docs.pinecone.io/guides/organizations/manage-service-accounts#retrieve-an-access-token)
        must be provided in the `Authorization` header using the `Bearer`
        scheme.

````