How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

OpenFGA Relationship Queries API

The Relationship Queries API from OpenFGA — 6 operation(s) for relationship queries.

OpenFGA Relationship Queries API is one of 6 APIs that OpenFGA publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Relationship Queries. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.

This API exposes 6 operations across 6 paths, and defines 42 schemas. It is described by OpenAPI 2.0, at version 1.x.

6 operations 6 paths 42 schemas 6 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 2.0
API Version
1.x
Contact
License
Resource Areas
1

Paths & Operations 6

Across 6 paths, the API surfaces 6 operations — 6 POST. Each is listed below with its method, path, parameters, and response codes.

Relationship Queries 6
POST
/stores/{store_id}/batch-check
Send a list of check operations in a single request
BatchCheck 2 params → 200400401403404409422500
POST
/stores/{store_id}/check
Check whether a user is authorized to access an object
Check 2 params → 200400401403404409422500
POST
/stores/{store_id}/expand
Expand all relationships in userset tree format, and following userset rewrite rules. Useful to reason about and debug a certain relationship
Expand 2 params → 200400401403404409422500
POST
/stores/{store_id}/list-objects
List all objects of the given type that the user has a relation with
ListObjects 2 params → 200400401403404409422500
POST
/stores/{store_id}/list-users
List the users matching the provided filter who have a certain relation to a particular type.
ListUsers 2 params → 200400401403404409422500
POST
/stores/{store_id}/streamed-list-objects
Stream all objects of the given type that the user has a relation with
StreamedListObjects 2 params → 200400401403404409422500

Schemas 42

The contract defines 42 schemas that model the data the API accepts and returns. The most detailed are Node (5 properties), TupleKey (4 properties), BatchCheckItem (4 properties), CheckError (3 properties). Each schema is shown below with its type and property counts.

TupleKey
object
4 properties 3 required
User
object
User. Represents any possible value for a user (subject or principal). Can be a: - Specific user object e.g.: 'user:will', 'folder:marketing', 'org:contoso', .…
3 properties
Users
object
1 property 1 required
BatchCheckResponse
object
1 property
NotFoundErrorCode
string
ErrorCode
string
ListObjectsResponse
object
1 property 1 required
ConsistencyPreference
string
Controls the consistency preferences when calling the query APIs. - UNSPECIFIED: Default if not set. Behavior will be the same as MINIMIZELATENCY. - MINIMIZELA…
UsersetTree.TupleToUserset
object
2 properties 2 required
AbortedMessageResponse
object
2 properties
ListUsersResponse
object
1 property 1 required
AuthErrorCode
string
ContextualTupleKeys
object
1 property 1 required
BatchCheckSingleResult
object
2 properties
Object
object
Object represents an OpenFGA Object. An Object is composed of a type and identifier (e.g. 'document:1') See https://openfga.dev/docs/conceptswhat-is-an-object
2 properties 2 required
CheckResponse
object
2 properties
UnprocessableContentErrorCode
string
UsersetTree
object
A UsersetTree contains the result of an Expansion.
1 property
InternalErrorMessageResponse
object
2 properties
RelationshipCondition
object
2 properties 1 required
Any
object
1 property
BatchCheckItem
object
4 properties 2 required
Status
object
3 properties
CheckError
object
3 properties
UsersetUser
object
Userset. A set or group of users, represented in the : format group:fgamember represents all members of group FGA, not to be confused by group:fga which repres…
3 properties 3 required
Leaf
object
A leaf node contains either - a set of users (which may be individual users, or usersets referencing other relations) - a computed node, which is the result of…
3 properties
ForbiddenResponse
object
2 properties
UsersetTree.Difference
object
2 properties 2 required
UserTypeFilter
object
2 properties 1 required
UnprocessableContentMessageResponse
object
2 properties
Node
object
5 properties 1 required
Nodes
object
1 property 1 required
ExpandResponse
object
1 property
UnauthenticatedResponse
object
2 properties
TypedWildcard
object
Type bound public access. Normally represented using the : syntax employee: represents every object of type employee, including those not currently present in…
1 property 1 required
PathUnknownErrorMessageResponse
object
2 properties
Computed
object
1 property 1 required
ValidationErrorMessageResponse
object
2 properties
ExpandRequestTupleKey
object
2 properties 2 required
CheckRequestTupleKey
object
3 properties 3 required
InternalErrorCode
string
StreamedListObjectsResponse
object
The response for a StreamedListObjects RPC.
1 property 1 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

openfga-relationship-queries-api-openapi.yml Raw ↑

Other APIs OpenFGA publishes across the network.

OpenFGA Assertions API
OpenFGA Authorization Models API
OpenFGA AuthZenService API
OpenFGA Relationship Tuples API
OpenFGA Stores API
Where this information came from

This is an independent, third-party profile of OpenFGA Relationship Queries API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.