Retrieve the Identity Config for one Identity and Template.
GET /api/v1/forward/identities/{identity_id}/templates/{template_id}/config
Returns the stored Forward Identity Config DSL. This is the override layer, not the compiled runtime config.
Headers
| Header | Required | Description |
|---|---|---|
Authorization | Yes | Bearer <PAT or SAT> |
Path parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
identity_id | string | Yes | Forward Identity ID. |
template_id | string | Yes | Forward Template ID. |
Example request
Example response
HTTP 200 OK
Response fields
| Field | Type | Description |
|---|---|---|
type | string | Always config. |
identity_config | object | Stored user-level override DSL. For nested fields, enums, inheritance, and merge rules, see Identity config object. |
identity_config.model | string | object | Stored model override; an object can contain id, effort, speed, and context_window. Returns only the override layer without filling in the Template model. See Model for fields and update rules. |
identity_config.managed_tool_config | object | Sparse Forward managed-capability switches stored for this Identity. Selectors inherited from the Template are not expanded. |
metadata | object | Custom metadata. |
Errors
| HTTP | Type | Code | Trigger |
|---|---|---|---|
| 401 | authentication_error | authentication_required | The PAT or SAT is invalid or expired. |
| 404 | not_found_error | - | The Identity, Template, or Config does not exist. |
Notes
- Use Get Effective Config to see the compiled runtime config.
- The returned
identity_configis the stored override DSL. You can read it, modify it, and send it back to Upsert Identity Config. managed_tool_configpreserves the stored sparse selectors without expanding inherited entries.scheduleis a bundle override for the three Schedule capabilities, anddriveis an override for the Drive capability.enabled=falsein a resource map disables resources inherited from the Template.environment_variablesreturns the storedset/unsetoverride DSL. See Effective Config for compiled values.- GitHub repository overrides return stored fields such as
url,mount_path, andenabled, but do not return the write-onlyauthorization_token.

