Access
List what one holder is allowed and denied, with the source of each entry
Section titled “List what one holder is allowed and denied, with the source of each entry”GET /api/v1/instance/access/effective
- Operation
permissions.effective- Accepts
sessionCookie,sessionToken- Scope
user_admin:read- Rights
users.manage- Effect
- reading
- Rate class
- read
Parameters
holderKind"user"|"service_principal"in query, requiredholderIdstring in query, required, minLength1
Answers
200The resultapplication/json: EffectivePermissions400BAD_REQUEST: The request cannot be read.401UNAUTHENTICATED: No credential was presented, or the credential is not valid.403FORBIDDEN: The caller lacks the scope or the right this operation requires.404NOT_FOUND: The resource does not exist, is not visible to the caller, or the instance runs without this operation.422VALIDATION_FAILED: Path, query or body do not match the operation's schema.429RATE_LIMITED: The caller sent too many requests of this operation's rate class.details.retryAfterSecondsand theRetry-Afterheader give the seconds to wait. The numbers are the instance's, set underrateLimitsin its release config.500INTERNAL: The instance failed. The message never carries details.
List grant rows
Section titled “List grant rows”GET /api/v1/instance/access/grants
- Operation
permissions.list- Accepts
sessionCookie,sessionToken- Scope
user_admin:read- Rights
users.manage- Effect
- reading
- Rate class
- read
Parameters
limitinteger in query, optional, default50, minimum1, maximum200cursorstring in query, optional, minLength1holderKindGrantHolderKind in query, optionalholderIdstring in query, optional, minLength1actionstring in query, optional, minLength1scopeKindGrantScopeKind in query, optional
Answers
200One page of the listapplication/json: objectitemsarray of PermissionGrant requirednextCursorstring optional
400BAD_REQUEST: The request cannot be read.401UNAUTHENTICATED: No credential was presented, or the credential is not valid.403FORBIDDEN: The caller lacks the scope or the right this operation requires.422VALIDATION_FAILED: Path, query or body do not match the operation's schema.429RATE_LIMITED: The caller sent too many requests of this operation's rate class.details.retryAfterSecondsand theRetry-Afterheader give the seconds to wait. The numbers are the instance's, set underrateLimitsin its release config.500INTERNAL: The instance failed. The message never carries details.
Allow or deny a user an action in a Namespace or on one asset
Section titled “Allow or deny a user an action in a Namespace or on one asset”POST /api/v1/instance/access/grants
- Operation
permissions.grant- Accepts
sessionCookie,sessionToken- Scope
user_admin:write- Rights
users.manage- Effect
- changing
- Rate class
- write
Request body
application/json: CreatePermissionGrantRequestInput
Answers
200The resultapplication/json: PermissionGrant400BAD_REQUEST: The request cannot be read.401UNAUTHENTICATED: No credential was presented, or the credential is not valid.403FORBIDDEN: The caller lacks the scope or the right this operation requires.404NOT_FOUND: The resource does not exist, is not visible to the caller, or the instance runs without this operation.409CONFLICT: The request conflicts with the current state of the resource.422VALIDATION_FAILED: Path, query or body do not match the operation's schema.429RATE_LIMITED: The caller sent too many requests of this operation's rate class.details.retryAfterSecondsand theRetry-Afterheader give the seconds to wait. The numbers are the instance's, set underrateLimitsin its release config.500INTERNAL: The instance failed. The message never carries details.
Remove a grant row
Section titled “Remove a grant row”DELETE /api/v1/instance/access/grants/{grantId}
- Operation
permissions.revoke- Accepts
sessionCookie,sessionToken- Scope
user_admin:write- Rights
users.manage- Effect
- changing
- Rate class
- write
Parameters
grantIdstring in path, required
Answers
200The resultapplication/json: PermissionGrant400BAD_REQUEST: The request cannot be read.401UNAUTHENTICATED: No credential was presented, or the credential is not valid.403FORBIDDEN: The caller lacks the scope or the right this operation requires.404NOT_FOUND: The resource does not exist, is not visible to the caller, or the instance runs without this operation.422VALIDATION_FAILED: Path, query or body do not match the operation's schema.429RATE_LIMITED: The caller sent too many requests of this operation's rate class.details.retryAfterSecondsand theRetry-Afterheader give the seconds to wait. The numbers are the instance's, set underrateLimitsin its release config.500INTERNAL: The instance failed. The message never carries details.
List Namespaces with the grants and assets each one covers
Section titled “List Namespaces with the grants and assets each one covers”GET /api/v1/instance/access/namespaces
- Operation
namespaces.list- Accepts
sessionCookie,sessionToken- Scope
user_admin:read- Rights
users.manage- Effect
- reading
- Rate class
- read
Parameters
limitinteger in query, optional, default50, minimum1, maximum200cursorstring in query, optional, minLength1
Answers
200One page of the listapplication/json: objectitemsarray of NamespaceUsage requirednextCursorstring optional
400BAD_REQUEST: The request cannot be read.401UNAUTHENTICATED: No credential was presented, or the credential is not valid.403FORBIDDEN: The caller lacks the scope or the right this operation requires.422VALIDATION_FAILED: Path, query or body do not match the operation's schema.429RATE_LIMITED: The caller sent too many requests of this operation's rate class.details.retryAfterSecondsand theRetry-Afterheader give the seconds to wait. The numbers are the instance's, set underrateLimitsin its release config.500INTERNAL: The instance failed. The message never carries details.
Register a name prefix as a Namespace
Section titled “Register a name prefix as a Namespace”POST /api/v1/instance/access/namespaces
- Operation
namespaces.create- Accepts
sessionCookie,sessionToken- Scope
user_admin:write- Rights
users.manage- Effect
- changing
- Rate class
- write
Request body
application/json: CreateNamespaceRequest
Answers
200The resultapplication/json: Namespace400BAD_REQUEST: The request cannot be read.401UNAUTHENTICATED: No credential was presented, or the credential is not valid.403FORBIDDEN: The caller lacks the scope or the right this operation requires.409CONFLICT: The request conflicts with the current state of the resource.422VALIDATION_FAILED: Path, query or body do not match the operation's schema.429RATE_LIMITED: The caller sent too many requests of this operation's rate class.details.retryAfterSecondsand theRetry-Afterheader give the seconds to wait. The numbers are the instance's, set underrateLimitsin its release config.500INTERNAL: The instance failed. The message never carries details.
Change a Namespace’s display name and its tool and model lists
Section titled “Change a Namespace’s display name and its tool and model lists”PATCH /api/v1/instance/access/namespaces/{prefix}
- Operation
namespaces.update- Accepts
sessionCookie,sessionToken- Scope
user_admin:write- Rights
users.manage- Effect
- changing
- Rate class
- write
Parameters
prefixstring in path, required
Request body
application/json: UpdateNamespaceRequest
Answers
200The resultapplication/json: Namespace400BAD_REQUEST: The request cannot be read.401UNAUTHENTICATED: No credential was presented, or the credential is not valid.403FORBIDDEN: The caller lacks the scope or the right this operation requires.404NOT_FOUND: The resource does not exist, is not visible to the caller, or the instance runs without this operation.422VALIDATION_FAILED: Path, query or body do not match the operation's schema.429RATE_LIMITED: The caller sent too many requests of this operation's rate class.details.retryAfterSecondsand theRetry-Afterheader give the seconds to wait. The numbers are the instance's, set underrateLimitsin its release config.500INTERNAL: The instance failed. The message never carries details.
Delete a Namespace that no grant row names
Section titled “Delete a Namespace that no grant row names”DELETE /api/v1/instance/access/namespaces/{prefix}
- Operation
namespaces.delete- Accepts
sessionCookie,sessionToken- Scope
user_admin:write- Rights
users.manage- Effect
- changing
- Rate class
- write
Parameters
prefixstring in path, required
Answers
200The resultapplication/json: Namespace400BAD_REQUEST: The request cannot be read.401UNAUTHENTICATED: No credential was presented, or the credential is not valid.403FORBIDDEN: The caller lacks the scope or the right this operation requires.404NOT_FOUND: The resource does not exist, is not visible to the caller, or the instance runs without this operation.409CONFLICT: The request conflicts with the current state of the resource.422VALIDATION_FAILED: Path, query or body do not match the operation's schema.429RATE_LIMITED: The caller sent too many requests of this operation's rate class.details.retryAfterSecondsand theRetry-Afterheader give the seconds to wait. The numbers are the instance's, set underrateLimitsin its release config.500INTERNAL: The instance failed. The message never carries details.