Returns every active Capability Grant in the tenant, optionally filtered by actorId, assetKid, and/or exchangeContextId (all AND-composed). Use actorId to render the Actor detail page, assetKid to render the per-key Access tab, and exchangeContextId for the exchange-context blast-radius view. The assetKid filter matches JSONB array MEMBERSHIP on assetKids — cross-kid REENCRYPT/RESIGN grants match whether the key is the source or the target. The exchangeContextId filter matches the scalar exchange-context FK on the grant. An unknown kid or exchange context (or one belonging to another tenant) returns an EMPTY page with HTTP 200 — never 403/404 — so resource existence is not disclosed. assetKid-filtered results are ordered by creation time descending (custom sort parameters are not applied on that path).
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||