> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developers.brevo.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developers.brevo.com/_mcp/server.

# Check admin user permissions

GET https://api.brevo.com/v3/corporate/user/{email}/permissions

This endpoint will provide the list of admin user permissions

Reference: https://developers.brevo.com/reference/get-corporate-user-permission

## Authentication

- `api-key` header (required) — The API key should be passed in the request headers as `api-key` for authentication.

## Request

### Path parameters

- `email` (string, required) — Email of the invited user.

## Response

### 200

List of user's permissions

- `email` (string, required) — Email address of the user.
- `feature_access` (object, required) — Granular feature permissions given to the user.
  - `analytics` (list of string, optional) — Permission on analytics
  - `api_keys` (list of string, optional) — Permission on api keys
  - `apps_management` (list of string, optional) — Permission on apps management
  - `create_sub_organizations` (list of string, optional) — Permission on create sub-accounts
  - `manage_sub_organizations` (list of string, optional) — Permission on manage sub-accounts
  - `my_plan` (list of string, optional) — Permission on my plan
  - `sub_organization_groups` (list of string, optional) — Permission on groups
  - `user_management` (list of string, optional) — Permission on user management
- `groups` (list of object, required)
  - `id` (string, optional) — group identifier
  - `name` (string, optional) — Group name
- `status` (string, required) — Status of the invited user.

## Errors

### 400 Bad Request Error

bad request

- `code` (enum, required) — Error code displayed in case of a failure
  - Allowed values: `invalid_parameter`, `missing_parameter`, `out_of_range`, `campaign_processing`, `campaign_sent`, `document_not_found`, `not_enough_credits`, `permission_denied`, `duplicate_parameter`, `duplicate_request`, `method_not_allowed`, `unauthorized`, `account_under_validation`, `not_acceptable`, `bad_request`, `unprocessable_entity`, `Domain does not exist`, `Contact email not found`, `Attribute not found`, `Category id not found`, `Invalid parameters passed`, `Record(s) for identifier not found`, `Returned when query params are invalid`, `Returned when invalid data posted`, `Feed not found`, `Campaign ID not found`, `api-key not found`, `DMARC policy requires domain authentication`, `DNS records not properly configured`, `Invalid OTP code provided`, `OTP code has expired`, `Domain already exists in your account`, `The sum of all IP weights must equal 100`, `Authentication failed`, `Insufficient credits`, `Request already processed`
- `message` (string, required) — Readable message associated to the failure

## Examples

**Response**

```json
{
  "email": "invitedUser@company.com",
  "feature_access": {
    "analytics": [
      "download_data",
      "create_alerts",
      "my_looks",
      "explore_create"
    ],
    "api_keys": [
      "all"
    ],
    "apps_management": [
      "all"
    ],
    "create_sub_organizations": [
      "all"
    ],
    "manage_sub_organizations": [
      "all"
    ],
    "my_plan": [
      "all",
      "all"
    ],
    "sub_organization_groups": [
      "create",
      "edit_delete"
    ],
    "user_management": [
      "none"
    ]
  },
  "groups": [
    {
      "id": "6543ab3667ffbb00142e4486",
      "name": "Support"
    },
    {
      "id": "174bab366732bbce142e4412",
      "name": "Technical"
    }
  ],
  "status": "active"
}
```

**SDK Code**

```typescript response
import { BrevoClient } from "@getbrevo/brevo";

async function main() {
    const client = new BrevoClient({
        apiKey: "YOUR_API_KEY_HERE",
    });
    await client.masterAccount.getCorporateUserPermission({
        email: "email",
    });
}
main();

```

```python response
from brevo import Brevo

client = Brevo(
    api_key="YOUR_API_KEY_HERE",
)

client.master_account.get_corporate_user_permission(
    email="email",
)

```

```php response
<?php

namespace Example;

use Brevo\Brevo;

$client = new Brevo(
    apiKey: 'YOUR_API_KEY_HERE',
);
$client->masterAccount->getCorporateUserPermission(
    'email',
);

```

```go response
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.brevo.com/v3/corporate/user/email/permissions"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("api-key", "<apiKey>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby response
require 'uri'
require 'net/http'

url = URI("https://api.brevo.com/v3/corporate/user/email/permissions")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["api-key"] = '<apiKey>'

response = http.request(request)
puts response.read_body
```

```java response
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api.brevo.com/v3/corporate/user/email/permissions")
  .header("api-key", "<apiKey>")
  .asString();
```

```csharp response
using RestSharp;

var client = new RestClient("https://api.brevo.com/v3/corporate/user/email/permissions");
var request = new RestRequest(Method.GET);
request.AddHeader("api-key", "<apiKey>");
IRestResponse response = client.Execute(request);
```

```swift response
import Foundation

let headers = ["api-key": "<apiKey>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://api.brevo.com/v3/corporate/user/email/permissions")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```