All Products
Search
Document Center

Data Management:ListUserPermissions

Last Updated:Aug 28, 2026

Queries the permissions of a user on databases and tables.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

dms:ListUserPermissions

list

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

Tid

integer

No

The ID of the tenant.

Note

To view the ID of the tenant, move the pointer over the profile picture in the upper-right corner of the Data Management (DMS) console. For more information, see the "View information about the current tenant" section of the Manage DMS tenants topic.

3***

PermType

string

Yes

The permissions on a specific type of resources that you want to query. Valid values:

  • DATABASE: permissions on databases

  • TABLE: permissions on tables

  • COLUMN: permissions on fields

  • INSTANCE: permissions on instances

DATABASE

UserId

string

Yes

The ID of the user. You can call the GetUser or ListUsers operation to query the ID of the user.

Note

The user ID is different from the ID of your Alibaba Cloud account.

51****

DatabaseName

string

No

The name of the database.

db_name

SearchKey

string

No

The keyword used in the query. For example, if you want to query permissions on an instance, you can specify the endpoint of the instance, such as rm-bp144d5ky4l4r****.

rm-bp144d5ky4l4r****

Logic

boolean

No

Specifies whether the database is a logical database. Valid values:

  • true: The database is a logical database.

  • false: The database is a physical database.

false

EnvType

string

No

The type of the environment to which the database belongs. Valid values:

  • product: production environment

  • dev: development environment

  • pre: staging environment

  • test: test environment

  • sit: SIT environment

  • uat: user acceptance testing (UAT) environment

  • pet: stress testing environment

  • stag: STAG environment

dev

DbType

string

No

The type of the database. For more information about the valid values of this parameter, see DbType parameter.

polardb

PageNumber

integer

No

The number of the page to return.

1

PageSize

integer

No

The number of entries to return on each page.

5

Response elements

Element

Type

Description

Example

object

TotalCount

integer

The total number of entries that meet the query conditions.

1

RequestId

string

The ID of the request.

C51420E3-144A-4A94-B473-8662FCF4AD10

ErrorCode

string

The error code.

UnknownError

ErrorMessage

string

The error message.

UnknownError

UserPermissions

object

UserPermission

array<object>

The details of the permissions that the user has.

array<object>

DbId

string

The ID of the database.

1860****

TableName

string

The name of the table.

test_table

UserId

string

The ID of the user.

51****

SchemaName

string

The name of the database.

test_db

Logic

boolean

Indicates whether the database is a logical database. Valid values:

  • true: The database is a logical database.

  • false: The database is a physical database.

false

UserNickName

string

The nickname of the user.

nick_name

InstanceId

string

The ID of the instance.

174****

PermDetails

object

PermDetail

array<object>

The details of permissions.

object

OriginFrom

string

The user who grants the permissions.

xxx授权

PermType

string

The type of the permissions. Valid values:

  • QUERY: the query permissions

  • EXPORT: the export permissions

  • CORRECT: the change permissions

QUERY

ExpireDate

string

The time when the permissions expire.

2020-12-12 00:00:00

CreateDate

string

The time when the permissions were granted.

2019-12-12 00:00:00

UserAccessId

string

The ID of the authorization record.

758****

ExtraData

string

This parameter is reserved.

xxx

EnvType

string

The type of the environment to which the database belongs. Valid values:

  • product: production environment

  • dev: development environment

  • pre: staging environment

  • test: test environment

  • sit: SIT environment

  • uat: UAT environment

  • pet: stress testing environment

  • stag: STAG environment

dev

ColumnName

string

The name of the field.

column_name

DbType

string

The type of the database. For more information about the valid values of this parameter, see DbType parameter.

polardb

DsType

string

The permissions on a specific type of objects that are granted to the user. Valid values:

  • DATABASE: permissions on physical databases

  • LOGIC_DATABASE: permissions on logical databases

  • TABLE: permissions on physical tables

  • LOGIC_TABLE: permissions on logical tables

DATABASE

TableId

string

The ID of the table.

13434

SearchName

string

The name that is used to search for the database.

test_db@xxx:3306

Alias

string

The alias of the instance.

instance_alias

Host

string

The endpoint that is used to connect the database.

rm-bp144d5ky4l4r****

Port

integer

The port that is used to connect to the instance.

3306

Success

boolean

Indicates whether the request is successful. Valid values:

  • true: The request is successful.

  • false: The request fails.

true

Examples

Success response

JSON format

{
  "TotalCount": 1,
  "RequestId": "C51420E3-144A-4A94-B473-8662FCF4AD10",
  "ErrorCode": "UnknownError",
  "ErrorMessage": "UnknownError",
  "UserPermissions": {
    "UserPermission": [
      {
        "DbId": "1860****",
        "TableName": "test_table",
        "UserId": "51****",
        "SchemaName": "test_db",
        "Logic": false,
        "UserNickName": "nick_name",
        "InstanceId": "174****",
        "PermDetails": {
          "PermDetail": [
            {
              "OriginFrom": "xxx授权",
              "PermType": "QUERY",
              "ExpireDate": "2020-12-12 00:00:00",
              "CreateDate": "2019-12-12 00:00:00",
              "UserAccessId": "758****",
              "ExtraData": "xxx"
            }
          ]
        },
        "EnvType": "dev",
        "ColumnName": "column_name",
        "DbType": "polardb",
        "DsType": "DATABASE",
        "TableId": "13434",
        "SearchName": "test_db@xxx:3306",
        "Alias": "instance_alias",
        "Host": "rm-bp144d5ky4l4r****",
        "Port": 3306
      }
    ]
  },
  "Success": true
}

Error codes

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.