# Permissions Requested by an Application

Returns the permission groups declared by the application. These are the rights requested for its system user when installed on a Location. The result does not report the system user's current effective rights or prove that the application is installed and active on this Location. Partners can check installation status through `GET /marketplace/salon/{location_id}/application/{application_id}` on `https://app.alteg.io`.
Useful before calling [Connect an Application to a Location](#tag/Marketplace/operation/marketplace_location_grant_access) to show the owner exactly what they are granting.
The authenticated user must have the **Manage user rights** permission on the location.
New to this flow? Follow [Install & test your app before moderation](marketplace-quickstart.md) from credentials through the final `active` status check.

Endpoint: GET /company/{company_id}/marketplace/applications/{application_id}/permissions
Version: 1.0.0
Security: BearerPartnerUser

## Security:

  - `BearerPartnerUser` (unknown)
    http bearer Bearer {PartnerToken}, User {UserToken}

## Path parameters:

  - `company_id` (integer, required)
    Location ID

  - `application_id` (integer, required)
    Application ID

## Header parameters:

  - `Accept` (string, required)
    e.g. application/vnd.api.v2+json

## Response 200:

  - `200` (unknown)
    List of declared permissions

## Response 200 fields (application/json):

  - `success` (boolean)
    Response status.
    Example: true

  - `data` (array)
    Permissions declared by the application

  - `data.title` (string)
    Human-readable permission name
    Example: Manage clients

  - `data.slug` (string)
    Permission group slug
    Example: clients

  - `data.child_permissions` (array)
    Concrete permission slugs included in this group
    Example: ["create_client","update_client"]

  - `meta` (object | array)
    Additional response data (empty object or empty array)
    Example: {}

## Response 401:

  - `401` (unknown)
    Unauthorized

## Response 401 fields (application/json):

  - `success` (boolean)
    Response status.
    Example: false

  - `data` (object | null)
    Response data.
    Example: null

  - `meta` (object)
    Additional response data.

  - `meta.message` (string)
    Error message.
    Example: Authentication needed.

## Response 403:

  - `403` (unknown)
    Forbidden — the user lacks the **Manage user rights** permission on the location.

## Response 403 fields (application/json):

  - `success` (boolean)
    Response status.
    Example: false

  - `data` (object | null)
    Response data.
    Example: null

  - `meta` (object)
    Additional response data.

  - `meta.message` (string)
    Error message.
    Example: Access denied.

## Response 404:

  - `404` (unknown)
    Application not found

## Response 404 fields (application/json):

  - `success` (boolean)
    Response status.
    Example: false

  - `data` (object | null)
    Response data.
    Example: null

  - `meta` (object | array)
    Additional response data (empty object or empty array)
    Example: {}

