> ## Documentation Index
> Fetch the complete documentation index at: https://docs.replicas.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Get an environment access policy

> Returns the All members baseline and custom-role permissions for a team or Global environment. Requires an organization admin.



## OpenAPI

````yaml /openapi.json get /v1/environments/{id}/access
openapi: 3.1.0
info:
  title: Replica API
  version: 2.0.0
  description: >-
    The Replica API allows you to programmatically manage cloud workspaces for
    AI agents. Use this API to manage environments (the org-scoped primitive
    workspaces are created from — including variables, files, skills, MCPs, warm
    hooks, start hooks, and warm pools), create and manage replicas, send
    messages, manage chats, stream events, read connected repositories and
    repository sets, and configure automations.
servers:
  - url: https://api.replicas.dev
    description: Production API
security:
  - apiKey: []
tags:
  - name: Environments
    description: >-
      Manage environments — the primitive that workspaces are created from.
      Variables, files, skills, MCPs, warm-hooks, and warm-pools are all scoped
      to an environment. Every organization has a singleton Global environment
      whose values apply to every workspace. Personal environments are scoped to
      the authenticated user and can be standalone or source-backed by a team
      environment.
  - name: Repository
    description: >-
      Read repositories and repository sets connected to your organization.
      Repositories are the underlying GitHub-connection layer; bind them to an
      environment to use them in workspaces.
  - name: Replica
    description: >-
      Manage replicas (workspaces) for AI agents. Workspace creation with `POST
      /v1/replica` accepts API keys and workspace engine-secret authentication.
      Other Replica operations also accept logged-in user JWTs from first-party
      clients.
  - name: Terminal
    description: Manage interactive terminal sessions in active workspaces
  - name: Tunnels
    description: Create short-lived authenticated transports to active workspaces
  - name: Preview
    description: Manage public preview URLs for workspace ports
  - name: Profile
    description: Read and update the authenticated user's profile
  - name: Credentials
    description: >-
      Manage coding-agent credentials for an organization or the authenticated
      user
  - name: Preferences
    description: Manage organization behavior preferences
  - name: Organization roles
    description: >-
      Manage custom roles and member role assignments. Organization admins
      retain full access independently of custom roles.
  - name: Slack
    description: Connect Slack identities and route threads to Replicas workspaces
  - name: Linear
    description: Connect Linear identities to Replicas accounts
  - name: Automation
    description: >-
      Create and manage automations that trigger replicas on a schedule or in
      response to events
  - name: Downloads
    description: Download Replicas applications
  - name: Media
    description: >-
      Read workspace media and obtain short-lived download or inline preview
      URLs
  - name: Analytics
    description: >-
      Read aggregated activity and usage metrics for your organization: compute
      minutes, workspaces created by source, and pull request throughput over a
      time range.
  - name: Presence
    description: >-
      Read and report ephemeral member presence: who is online, where they are
      (environment or workspace), and whether they are typing. Presence is
      backed by short-lived keys rather than the database and broadcast to other
      members over the events stream.
  - name: Plugins
    description: >-
      Install and manage native and Composio-backed workspace plugins. A plugin
      installs for a single environment, for the whole organization (which uses
      the Global environment), or for one member personally. A workspace uses
      the most specific installation available: personal, then its own
      environment, then the environment it was branched from, then Global.
      Composio Connect Links host managed OAuth, custom OAuth, API-key,
      bearer-token, basic, and dynamic OAuth authentication without exposing
      provider credentials to Replicas.
paths:
  /v1/environments/{id}/access:
    get:
      tags:
        - Environments
      summary: Get an environment access policy
      description: >-
        Returns the All members baseline and custom-role permissions for a team
        or Global environment. Requires an organization admin.
      operationId: getEnvironmentAccessPolicy
      parameters:
        - name: id
          in: path
          required: true
          description: Environment UUID or `global`.
          schema:
            type: string
      responses:
        '200':
          description: Environment access policy
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EnvironmentAccessPolicy'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  schemas:
    EnvironmentAccessPolicy:
      type: object
      properties:
        everyone:
          $ref: '#/components/schemas/EnvironmentAccess'
        roles:
          type: array
          items:
            $ref: '#/components/schemas/EnvironmentRolePermission'
      required:
        - everyone
        - roles
    EnvironmentAccess:
      type: object
      description: >-
        Effective environment permissions. Read allows discovery, full
        inspection, and selection for workspaces or automations. Write allows
        all mutations and implies Read.
      properties:
        can_write:
          type: boolean
        can_read:
          type: boolean
      required:
        - can_read
        - can_write
    EnvironmentRolePermission:
      allOf:
        - $ref: '#/components/schemas/EnvironmentAccess'
        - type: object
          properties:
            role_id:
              type: string
              format: uuid
          required:
            - role_id
    Error:
      type: object
      properties:
        error:
          type: string
          description: Error message
        details:
          type:
            - string
            - 'null'
          description: Additional error details
        code:
          type: string
          description: Machine-readable error code when available
      required:
        - error
  responses:
    Unauthorized:
      description: Unauthorized - Invalid or missing API key
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Forbidden:
      description: Forbidden - The authenticated account cannot access this resource
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    NotFound:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    InternalServerError:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: >-
        API key authentication. Obtain your API key from the Replicas dashboard
        under Organization → Settings → API Keys.

````