Get a resource's ownership
const url = 'https://api.aletheia-ops.com/api/v1/resources/example/ownership';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.aletheia-ops.com/api/v1/resources/example/ownership \ --header 'Authorization: Bearer <token>'Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Responses
Section titled “Responses”OK
Aggregates the applications, environment, and owners of a single resource for the resource-detail page
object
Pairs an application with the membership that links it to the resource (plan 07 §2.4 resource-detail slots)
object
Public shape of an application
object
Public shape of an application-resource membership
object
object
Public shape of an environment
object
Pairs an ownership with the owning team (if any)
object
Public shape of a team/user ownership of an application or resource
object
object
Public shape of a team
object
Examplegenerated
{ "applications": [ { "application": { "id": "example", "organization_id": "example", "name": "example", "slug": "example", "description": "example", "criticality": "example", "lifecycle": "example", "source": "example", "created_by": "example", "created_at": "2026-04-15T12:00:00Z", "updated_at": "2026-04-15T12:00:00Z", "archived_at": "2026-04-15T12:00:00Z" }, "membership": { "id": "example", "organization_id": "example", "application_id": "example", "resource_id": "example", "source": "example", "confidence": "example", "status": "example", "rule_id": "example", "evidence": {}, "created_by": "example", "created_at": "2026-04-15T12:00:00Z", "updated_at": "2026-04-15T12:00:00Z" } } ], "environment": { "id": "example", "organization_id": "example", "name": "example", "class": "example", "created_at": "2026-04-15T12:00:00Z", "updated_at": "2026-04-15T12:00:00Z" }, "owners": [ { "ownership": { "id": "example", "organization_id": "example", "target_type": "example", "target_id": "example", "team_id": "example", "user_id": "example", "role": "example", "source": "example", "confidence": "example", "status": "example", "evidence": {}, "last_confirmed_at": "2026-04-15T12:00:00Z", "created_by": "example", "created_at": "2026-04-15T12:00:00Z", "updated_at": "2026-04-15T12:00:00Z" }, "team": { "id": "example", "organization_id": "example", "name": "example", "slug": "example", "description": "example", "is_active": true, "created_at": "2026-04-15T12:00:00Z", "updated_at": "2026-04-15T12:00:00Z" } } ]}No valid credential was presented, or it has expired.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "unauthorized", "message": "authentication required"}{ "code": "invalid_credentials", "message": "invalid email or password"}{ "code": "invalid_token", "message": "invalid or expired token"}{ "code": "token_reuse", "message": "session revoked"}{ "code": "webhook_unauthorized", "message": "webhook verification failed"}Authenticated, but not permitted to perform this action.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "forbidden", "message": "you do not have permission to perform this action"}{ "code": "csrf_failed", "message": "missing or invalid CSRF token"}{ "code": "account_deactivated", "message": "your account is deactivated; contact your administrator"}{ "code": "ai_disabled", "message": "the AI assistant is disabled for this organization"}The resource does not exist, or belongs to another organization. The two are deliberately indistinguishable.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "not_found", "message": "resource not found"}An unexpected failure. Diagnostic detail is logged server-side and
deliberately not returned. Quote the X-Request-Id response header when
reporting one.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "internal_error", "message": "internal server error"}