> ## Documentation Index
> Fetch the complete documentation index at: https://docs.credibledata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List packages in environment

> Retrieves all packages within the specified environment, including metadata such as names,
descriptions, latest versions, and creation timestamps.

**Authorization**: Requires read access to the environment.

**Response**: Returns array of package objects with full metadata.

**Pagination**: Supports offset-based pagination with limit and offset parameters.




## OpenAPI

````yaml /controlplane-public-api-doc.yaml get /organizations/{organizationName}/environments/{environmentName}/packages
openapi: 3.1.0
info:
  title: Credible Admin API
  description: >
    The Credible Admin API is a comprehensive REST API that empowers
    organizations to manage their Malloy data modeling ecosystem with
    enterprise-grade security and governance. This API provides programmatic
    access to all administrative functions, enabling seamless integration with
    existing workflows and automation systems.


    ## Key Features


    - **Organization Management**: Create and manage organizations with
    fine-grained access controls

    - **Environment & Package Lifecycle**: Full CRUD operations for
    environments, packages, and versions

    - **Connection Management**: Secure database connection configuration and
    management

    - **Permission Management**: Granular role-based access control (RBAC) at
    organization, environment, package, workspace, and document levels

    - **Workspace Management**: Collaborative workspaces for data modeling and
    analysis

    - **User & Group Management**: Comprehensive user administration with
    group-based permissions


    ## Resource Hierarchy


    The API follows a hierarchical resource structure with fine-grained
    permission management at each level:

    ```

    Organizations

    ├── Permissions

    ├── Environments

    │   ├── Permissions

    │   ├── Packages

    │   │   ├── Permissions

    │   │   └── Versions

    │   └── Connections

    ├── Workspaces

    │   ├── Permissions

    │   └── Documents

    │       └── Permissions

    └── Groups
        ├── Permissions
        └── Members

    System-Level Resources:

    ├── Users

    ├── System Permissions

    └── Demo Operations

    ```


    ## Authentication & Authorization


    All API endpoints require proper authentication. The API implements
    fine-grained authorization using role-based permissions:

    - **Admin**: Full access to all resources within scope

    - **Modeler**: Can create and modify data models and packages

    - **Viewer**: Read-only access to resources

    - **Manager**: Workspace management capabilities

    - **Editor**: Document editing permissions


    ## Rate Limiting & Best Practices


    - API requests are rate-limited to ensure system stability

    - Implement proper error handling and retry logic

    - Cache responses when appropriate to reduce API calls


    ## Support & Documentation


    For additional support, examples, and integration guides, visit our
    developer documentation or contact our support team.
  version: v0
  contact:
    name: Credible Support
    email: support@credibledata.com
    url: https://credibledata.com/support
  license:
    name: Proprietary
    url: https://credibledata.com/license
  termsOfService: https://credibledata.com/terms
servers:
  - url: https://{organization}.admin.credibledata.com/api/v0/
    description: Production API server
    variables:
      organization:
        default: demo
        description: Your organization subdomain
security:
  - bearerAuth: []
tags:
  - name: organizations
    description: >-
      Organization management operations for creating, updating, and managing
      organizational entities
  - name: organizationPermissions
    description: >-
      Fine-grained permission management for organizations, including role
      assignments and access controls
  - name: environments
    description: >-
      Environment lifecycle management including creation, configuration, and
      deletion of data modeling environments
  - name: environmentPermissions
    description: >-
      Permission management for environments, controlling access to environment
      resources and capabilities
  - name: packages
    description: >-
      Package management for Malloy data models, including versioning,
      publishing, and distribution
  - name: packagePermissions
    description: >-
      Access control for packages, managing who can view, modify, or publish
      package versions
  - name: versions
    description: >-
      Version management for packages, including archiving, status updates, and
      lifecycle management
  - name: connections
    description: >-
      Database connection management for secure data source configuration and
      access
  - name: materializations
    description: >-
      Malloy Persistence materializations (per-version serving anchors for
      persisted sources)
  - name: indexes
    description: >-
      Malloy Persistence dimensional search indexes (per-version serving anchors
      for indexed dimensions)
  - name: runs
    description: >-
      Malloy Persistence build/refresh runs — one package-level build event
      carrying typed units (materialized sources + built indexes)
  - name: workspaces
    description: >-
      Collaborative workspace management for team-based data modeling and
      analysis
  - name: workspacePermissions
    description: >-
      Access control for workspaces, managing who can view, manage, or
      collaborate in workspaces
  - name: documents
    description: >-
      Document management within workspaces, including workbooks, dashboards,
      and other content
  - name: documentPermissions
    description: >-
      Access control for documents, managing who can view, edit, or share
      document content
  - name: groups
    description: >-
      User group management for organizing users and managing group-based
      permissions
  - name: users
    description: >-
      User account management including creation, updates, and profile
      management
  - name: demo
    description: Demo and self-service operations for quick setup and testing scenarios
  - name: permissions
    description: System-level permission management for administrative functions
  - name: bookmarks
    description: >-
      User bookmark management for saving references to workspaces, models, and
      chats
  - name: attributes
    description: Trusted user attributes for fine-grain (row/column-level) access control
  - name: invites
    description: >-
      Organization-creation invite tokens. A super-admin mints tokens one per
      call (call `POST /invites` repeatedly to populate an outreach campaign);
      each token can be redeemed once by an authenticated user to create a new
      organization on the fly.
paths:
  /organizations/{organizationName}/environments/{environmentName}/packages:
    get:
      tags:
        - packages
      summary: List packages in environment
      description: >
        Retrieves all packages within the specified environment, including
        metadata such as names,

        descriptions, latest versions, and creation timestamps.


        **Authorization**: Requires read access to the environment.


        **Response**: Returns array of package objects with full metadata.


        **Pagination**: Supports offset-based pagination with limit and offset
        parameters.
      operationId: listPackages
      parameters:
        - name: organizationName
          in: path
          required: true
          description: The unique identifier of the organization
          schema:
            $ref: '#/components/schemas/IdentifierPattern'
        - name: environmentName
          in: path
          required: true
          description: The unique identifier of the environment
          schema:
            $ref: '#/components/schemas/IdentifierPattern'
        - name: limit
          in: query
          required: false
          description: >-
            Maximum number of items to return. Use -1 or omit to return all
            results. Valid values: -1 (all results) or 1–100.
          schema:
            type: integer
            minimum: -1
            maximum: 500
            default: -1
        - name: offset
          in: query
          required: false
          description: Number of items to skip before starting to return results
          schema:
            type: integer
            minimum: 0
            default: 0
      responses:
        '200':
          description: List of packages retrieved successfully
          headers:
            Total-Count:
              description: Total number of packages available
              schema:
                type: integer
              required: true
            Link:
              description: RFC 8288 pagination links (first, prev, next, last)
              schema:
                type: string
              example: >-
                <https://demo.admin.credibledata.com/api/v0/organizations/demo/environments/myenvironment/packages?limit=100&offset=0>;
                rel="first",
                <https://demo.admin.credibledata.com/api/v0/organizations/demo/environments/myenvironment/packages?limit=100&offset=100>;
                rel="next"
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/Package'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
components:
  schemas:
    IdentifierPattern:
      type: string
      pattern: ^[a-zA-Z0-9_ -]+$
      description: Standard identifier pattern for resource names
    Package:
      type: object
      description: >-
        Represents a Malloy data model package containing models, queries, and
        related resources
      properties:
        name:
          $ref: '#/components/schemas/IdentifierPattern'
          type: string
          description: The unique name of the package within its environment
        latestVersion:
          $ref: '#/components/schemas/SemanticVersionPattern'
          type: string
          description: The version identifier of the most recent published version
        description:
          type: string
          description: Human-readable description of the package's purpose and contents
        createdAt:
          type: string
          format: date-time
          description: ISO 8601 timestamp indicating when the package was first created
        updatedAt:
          type: string
          format: date-time
          description: ISO 8601 timestamp indicating when the package was last modified
        replicationCount:
          type: integer
          description: >
            Number of replicas for high availability and performance. When sent
            on create, this value is stored as-is (within min/max). When omitted
            on create, Credible manages it for you. When omitted on update, the
            existing value is left unchanged.
          minimum: 1
          maximum: 10
        resourceIdentifier:
          $ref: '#/components/schemas/ResourceIdentifierPattern'
          description: >-
            Unique resource identifier for the package, used for API references
            and permissions
          type: string
          nullable: false
        indexStatus:
          $ref: '#/components/schemas/IndexStatus'
        autoPromote:
          type: boolean
          nullable: true
          description: >
            Package-scoped auto-promote policy applied as a default to each
            newly

            published version: when true, a new version is armed (see

            Version.promoteWhenReady) and the lifecycle reconciler promotes it
            to

            `latestVersion` once it is ready, subject to the never-been-latest

            rollback guard. Newly created packages default this to `true`: a
            package

            created without an explicit `autoPromote` gets auto-promote enabled.

            Omitting the field on update leaves the policy unchanged; toggling
            it on

            does not retroactively arm existing versions. Independent of

            `autoArchiveTtl`.
        autoArchiveTtl:
          type: string
          nullable: true
          description: >
            Package-scoped ttl auto-archive policy: how long a version is
            retained

            after it stops being latest, e.g. `30d`, `24h`, `2w` (units s, m, h,
            d,

            w). A formerly-latest version is archived (its materialized tables

            reclaimed) once it has been demoted for longer than this ttl; the
            current

            latest is never archived. `0` archives a version as soon as it is
            demoted

            (keep-only-latest, modulo the reconciler tick) — note this trades
            away the

            cheap rollback window. A non-empty value enables auto-archive; an
            empty

            string disables it. Newly created packages default to `30d`: a
            package

            created without an explicit `autoArchiveTtl` gets 30-day
            auto-archive.

            Omitting the field on update leaves the policy unchanged.
            Independent of

            `autoPromote`.
    SemanticVersionPattern:
      type: string
      pattern: >-
        ^[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z-]+(\.[0-9A-Za-z-]+)*)?(\+[0-9A-Za-z-]+(\.[0-9A-Za-z-]+)*)?$
      description: >-
        SemVer 2.0 version identifier. Required core MAJOR.MINOR.PATCH plus
        optional pre-release suffix (e.g. `-rc1`, `-alpha.2`) and optional build
        metadata (e.g. `+20231120.deadbeef`). Previously enforced strict
        MAJOR.MINOR.PATCH only, which would have started 400-ing legitimate
        pre-release versions (e.g. videoamp's -rc1/-rc2 RC builds) once
        hibernate-validator started firing.
    ResourceIdentifierPattern:
      type: string
      pattern: ^[a-zA-Z0-9_/.:-]+$
      description: Resource identifier pattern supporting slashes, dots, dashes, and colons
    IndexStatus:
      type: string
      description: >-
        Status of the indexing process. Possible values: unknown (initial state,
        indexing not yet started), indexing (currently being processed), indexed
        (successfully indexed and ready for use), failed (indexing process
        encountered an error).
      enum:
        - unknown
        - indexing
        - indexed
        - failed
        - retry
    Error:
      type: object
      x-model-name: ModelError
      description: Standard error response format used across all API endpoints
      properties:
        code:
          type: string
          description: >
            Machine-readable error code that identifies the specific error
            condition.

            Clients should branch on `code`, not on the human-readable `message`
            —

            the message text is informational and may change over time.


            Generic codes (may appear on any endpoint):

            - `VALIDATION_ERROR`: Request body or path/query parameter failed
            validation

            - `AUTHENTICATION_REQUIRED`: Valid authentication is required

            - `INSUFFICIENT_PERMISSIONS`: User lacks required permissions

            - `RESOURCE_NOT_FOUND`: Requested resource does not exist

            - `CONFLICT`: Generic resource state conflict (used when no more
            specific code applies)

            - `RATE_LIMIT_EXCEEDED`: API rate limit exceeded

            - `INTERNAL_ERROR`: Unexpected server error


            Endpoint-specific codes used by the signup / invites flow:

            - `ORGANIZATION_NAME_TAKEN`: 409 on `POST /organizations` — the
            requested
              org name (URL slug) is already in use. Retry with a different name.
            - `ORGANIZATION_NAME_RESERVED`: 409 on `POST /organizations` — the
            requested
              org name collides with a platform subdomain (e.g. `signup`, `admin`,
              `data`, `login`) and cannot be claimed. Retry with a different name.
            - `INVITE_ALREADY_CONSUMED`: 409 on `POST /organizations` — the
            supplied
              invite token has already been redeemed into an existing organization.
              Retry will not help; the token is dead.
            - `INVITE_ALREADY_CONSUMED_REVOKE`: 409 on `DELETE /invites/{token}`
            —
              consumed invites are preserved for audit and cannot be revoked.
            - `INVITE_INVALID`: 400 on `POST /organizations` — the supplied
            invite
              token is malformed or unknown.
            - `INVITE_EXPIRED`: 400 on `POST /organizations` — the supplied
            invite
              token is past its `expiresAt`.
            - `INVITE_EMAIL_MISMATCH`: 403 on `POST /organizations` — the invite
            is
              bound to a different email address than the caller.
        message:
          type: string
          description: Human-readable error message providing details about what went wrong
  responses:
    BadRequest:
      description: >-
        The request was malformed or can not be performed given the state of the
        system.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Forbidden:
      description: >-
        Can not perform the operation due to insufficient permissions or the
        state of the system.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    NotFound:
      description: The specified resource was not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````