Skip to content

Access

List what one holder is allowed and denied, with the source of each entry

Section titled “List what one holder is allowed and denied, with the source of each entry”

GET /api/v1/instance/access/effective

Operation
permissions.effective
Accepts
sessionCookie, sessionToken
Scope
user_admin:read
Rights
users.manage
Effect
reading
Rate class
read

Parameters

  • holderKind "user" | "service_principal" in query, required
  • holderId string in query, required, minLength 1

Answers

  • 200 The result

    application/json: EffectivePermissions

  • 400 BAD_REQUEST: The request cannot be read.
  • 401 UNAUTHENTICATED: No credential was presented, or the credential is not valid.
  • 403 FORBIDDEN: The caller lacks the scope or the right this operation requires.
  • 404 NOT_FOUND: The resource does not exist, is not visible to the caller, or the instance runs without this operation.
  • 422 VALIDATION_FAILED: Path, query or body do not match the operation's schema.
  • 429 RATE_LIMITED: The caller sent too many requests of this operation's rate class. details.retryAfterSeconds and the Retry-After header give the seconds to wait. The numbers are the instance's, set under rateLimits in its release config.
  • 500 INTERNAL: The instance failed. The message never carries details.

GET /api/v1/instance/access/grants

Operation
permissions.list
Accepts
sessionCookie, sessionToken
Scope
user_admin:read
Rights
users.manage
Effect
reading
Rate class
read

Parameters

  • limit integer in query, optional, default 50, minimum 1, maximum 200
  • cursor string in query, optional, minLength 1
  • holderKind GrantHolderKind in query, optional
  • holderId string in query, optional, minLength 1
  • action string in query, optional, minLength 1
  • scopeKind GrantScopeKind in query, optional

Answers

  • 200 One page of the list

    application/json: object

  • 400 BAD_REQUEST: The request cannot be read.
  • 401 UNAUTHENTICATED: No credential was presented, or the credential is not valid.
  • 403 FORBIDDEN: The caller lacks the scope or the right this operation requires.
  • 422 VALIDATION_FAILED: Path, query or body do not match the operation's schema.
  • 429 RATE_LIMITED: The caller sent too many requests of this operation's rate class. details.retryAfterSeconds and the Retry-After header give the seconds to wait. The numbers are the instance's, set under rateLimits in its release config.
  • 500 INTERNAL: The instance failed. The message never carries details.

Allow or deny a user an action in a Namespace or on one asset

Section titled “Allow or deny a user an action in a Namespace or on one asset”

POST /api/v1/instance/access/grants

Operation
permissions.grant
Accepts
sessionCookie, sessionToken
Scope
user_admin:write
Rights
users.manage
Effect
changing
Rate class
write

Request body

application/json: CreatePermissionGrantRequestInput

Answers

  • 200 The result

    application/json: PermissionGrant

  • 400 BAD_REQUEST: The request cannot be read.
  • 401 UNAUTHENTICATED: No credential was presented, or the credential is not valid.
  • 403 FORBIDDEN: The caller lacks the scope or the right this operation requires.
  • 404 NOT_FOUND: The resource does not exist, is not visible to the caller, or the instance runs without this operation.
  • 409 CONFLICT: The request conflicts with the current state of the resource.
  • 422 VALIDATION_FAILED: Path, query or body do not match the operation's schema.
  • 429 RATE_LIMITED: The caller sent too many requests of this operation's rate class. details.retryAfterSeconds and the Retry-After header give the seconds to wait. The numbers are the instance's, set under rateLimits in its release config.
  • 500 INTERNAL: The instance failed. The message never carries details.

DELETE /api/v1/instance/access/grants/{grantId}

Operation
permissions.revoke
Accepts
sessionCookie, sessionToken
Scope
user_admin:write
Rights
users.manage
Effect
changing
Rate class
write

Parameters

  • grantId string in path, required

Answers

  • 200 The result

    application/json: PermissionGrant

  • 400 BAD_REQUEST: The request cannot be read.
  • 401 UNAUTHENTICATED: No credential was presented, or the credential is not valid.
  • 403 FORBIDDEN: The caller lacks the scope or the right this operation requires.
  • 404 NOT_FOUND: The resource does not exist, is not visible to the caller, or the instance runs without this operation.
  • 422 VALIDATION_FAILED: Path, query or body do not match the operation's schema.
  • 429 RATE_LIMITED: The caller sent too many requests of this operation's rate class. details.retryAfterSeconds and the Retry-After header give the seconds to wait. The numbers are the instance's, set under rateLimits in its release config.
  • 500 INTERNAL: The instance failed. The message never carries details.

List Namespaces with the grants and assets each one covers

Section titled “List Namespaces with the grants and assets each one covers”

GET /api/v1/instance/access/namespaces

Operation
namespaces.list
Accepts
sessionCookie, sessionToken
Scope
user_admin:read
Rights
users.manage
Effect
reading
Rate class
read

Parameters

  • limit integer in query, optional, default 50, minimum 1, maximum 200
  • cursor string in query, optional, minLength 1

Answers

  • 200 One page of the list

    application/json: object

  • 400 BAD_REQUEST: The request cannot be read.
  • 401 UNAUTHENTICATED: No credential was presented, or the credential is not valid.
  • 403 FORBIDDEN: The caller lacks the scope or the right this operation requires.
  • 422 VALIDATION_FAILED: Path, query or body do not match the operation's schema.
  • 429 RATE_LIMITED: The caller sent too many requests of this operation's rate class. details.retryAfterSeconds and the Retry-After header give the seconds to wait. The numbers are the instance's, set under rateLimits in its release config.
  • 500 INTERNAL: The instance failed. The message never carries details.

POST /api/v1/instance/access/namespaces

Operation
namespaces.create
Accepts
sessionCookie, sessionToken
Scope
user_admin:write
Rights
users.manage
Effect
changing
Rate class
write

Request body

application/json: CreateNamespaceRequest

Answers

  • 200 The result

    application/json: Namespace

  • 400 BAD_REQUEST: The request cannot be read.
  • 401 UNAUTHENTICATED: No credential was presented, or the credential is not valid.
  • 403 FORBIDDEN: The caller lacks the scope or the right this operation requires.
  • 409 CONFLICT: The request conflicts with the current state of the resource.
  • 422 VALIDATION_FAILED: Path, query or body do not match the operation's schema.
  • 429 RATE_LIMITED: The caller sent too many requests of this operation's rate class. details.retryAfterSeconds and the Retry-After header give the seconds to wait. The numbers are the instance's, set under rateLimits in its release config.
  • 500 INTERNAL: The instance failed. The message never carries details.

Change a Namespace’s display name and its tool and model lists

Section titled “Change a Namespace’s display name and its tool and model lists”

PATCH /api/v1/instance/access/namespaces/{prefix}

Operation
namespaces.update
Accepts
sessionCookie, sessionToken
Scope
user_admin:write
Rights
users.manage
Effect
changing
Rate class
write

Parameters

  • prefix string in path, required

Request body

application/json: UpdateNamespaceRequest

Answers

  • 200 The result

    application/json: Namespace

  • 400 BAD_REQUEST: The request cannot be read.
  • 401 UNAUTHENTICATED: No credential was presented, or the credential is not valid.
  • 403 FORBIDDEN: The caller lacks the scope or the right this operation requires.
  • 404 NOT_FOUND: The resource does not exist, is not visible to the caller, or the instance runs without this operation.
  • 422 VALIDATION_FAILED: Path, query or body do not match the operation's schema.
  • 429 RATE_LIMITED: The caller sent too many requests of this operation's rate class. details.retryAfterSeconds and the Retry-After header give the seconds to wait. The numbers are the instance's, set under rateLimits in its release config.
  • 500 INTERNAL: The instance failed. The message never carries details.

Delete a Namespace that no grant row names

Section titled “Delete a Namespace that no grant row names”

DELETE /api/v1/instance/access/namespaces/{prefix}

Operation
namespaces.delete
Accepts
sessionCookie, sessionToken
Scope
user_admin:write
Rights
users.manage
Effect
changing
Rate class
write

Parameters

  • prefix string in path, required

Answers

  • 200 The result

    application/json: Namespace

  • 400 BAD_REQUEST: The request cannot be read.
  • 401 UNAUTHENTICATED: No credential was presented, or the credential is not valid.
  • 403 FORBIDDEN: The caller lacks the scope or the right this operation requires.
  • 404 NOT_FOUND: The resource does not exist, is not visible to the caller, or the instance runs without this operation.
  • 409 CONFLICT: The request conflicts with the current state of the resource.
  • 422 VALIDATION_FAILED: Path, query or body do not match the operation's schema.
  • 429 RATE_LIMITED: The caller sent too many requests of this operation's rate class. details.retryAfterSeconds and the Retry-After header give the seconds to wait. The numbers are the instance's, set under rateLimits in its release config.
  • 500 INTERNAL: The instance failed. The message never carries details.