Skip to content

Permissions (RBAC) ​

Every API route belongs to exactly one action - a resource:verb key such as flow:view or run:trigger - declared in apps/api/auth/actions.yaml with a default policy and a description. apps/api/auth/routes.yaml maps every route to its action, and the loader in apps/api/auth/permissions.py flattens the two files into the rule table that RBACMiddleware enforces on every request (most specific path wins). A route's default policy is its action's policy. This page lists the 109 actions across 43 resources, in registry order, with the 342 route rules they cover.

Administrators change who may do what at runtime under Settings → Permissions, which has two tabs:

  • Actions allocates a whole action to a policy; every route of the action follows (stored in permission_action_overrides).
  • Routes pins a single method and path to a policy as an escape hatch; a route override wins over its action (stored in permission_overrides).

The policy in effect for a request is resolved as route override → action override → action default. Structural policies cannot be overridden at either layer, the pinned permission:manage keeps its default policy so no override can hand the permission matrix to a lower role, and a target-org policy can only be assigned where every affected route carries an {org_ref} parameter. One override target is not a role: disabled switches the action or route off for every caller until an administrator assigns another policy. No action may declare it as its default, and auth:me refuses it at both layers so the console can always load and reach this editor to undo it. Overrides are audited, applied immediately on the API instance that saved them and within 30 s on every other instance, and surfaced by the same endpoints that power that page (GET /settings/permissions/actions and GET /settings/permissions). Both override layers round-trip through configuration exchange as the permission_action_overrides and permission_overrides bundle sections. The OpenAPI schema carries the effective security requirement per operation.

Policies ​

PolicyWho it grantsOverridable
publicNo authentication requiredno (structural)
authenticatedAny authenticated calleryes
viewerGranted to roles admin, auditor, operator, vieweryes
auditorGranted to roles admin, auditor, operatoryes
operatorGranted to roles admin, operatoryes
approverGranted to roles admin, approveryes
adminGranted to roles adminyes
org_memberAuthorized against the organization named by the route's {org_ref} parameter: platform admins always pass; otherwise the caller needs any membership in that organizationyes
org_adminAuthorized against the organization named by the route's {org_ref} parameter: platform admins always pass; otherwise the caller needs the admin membership role in that organizationyes
internalWorker and scheduler callbacks presenting X-Internal-Token (not checked when auth is disabled, or when no token is configured and HEGEMONY_INTERNAL_API_TOKEN_OPTIONAL=true)no (structural)
customThe endpoint authenticates the caller itselfno (structural)
disabledNobody — the endpoint is switched off for every caller, platform admins included, until an administrator assigns another policyyes

system ​

system:health ​

Liveness and readiness probes.

Default policy: public — no authentication required.

MethodsPath
GET/health
GET/ready

system:docs ​

Interactive API documentation and the OpenAPI schema.

Default policy: public — no authentication required.

MethodsPath
GET/docs/oauth2-redirect
GET/openapi.json
GET/redoc
GET/docs

auth ​

auth:config ​

OIDC discovery for the UI and BFF ticket validation.

Default policy: public — no authentication required.

MethodsPath
GET/auth/bff/validate
GET/auth/config

auth:me ​

The caller's own identity, effective roles, capabilities and BFF tickets.

Default policy: authenticated — any authenticated caller. Reallocatable but never disableable: the console loads it before it can render anything, so switching it off would leave no way back to the permission editor.

MethodsPath
GET/auth/capabilities
POST/auth/bff/ticket
GET/auth/me

org ​

org:list ​

List organizations (filtered per caller in the router).

Default policy: authenticated — any authenticated caller.

MethodsPath
GET/orgs

org:view ​

Read an organization and its member list.

Default policy: org_member — authorized against the organization named by the route's {org_ref} parameter: platform admins always pass; otherwise the caller needs any membership in that organization.

MethodsPath
GET/orgs/{org_ref}/members
GET/orgs/{org_ref}

org:manage ​

Create, rename, deactivate and delete organizations (platform admin), and designate the shared organization whose resources become readable by every tenant.

Default policy: admin — granted to roles admin.

MethodsPath
DELETE, PATCH/orgs/{org_ref}
POST/orgs

org_member ​

org_member:manage ​

Add, change the role of, and remove organization members.

Default policy: org_admin — authorized against the organization named by the route's {org_ref} parameter: platform admins always pass; otherwise the caller needs the admin membership role in that organization.

MethodsPath
GET/orgs/{org_ref}/addable-users
POST/orgs/{org_ref}/members
DELETE, PATCH/orgs/{org_ref}/members/{user_id}

org_idp_mapping ​

org_idp_mapping:manage ​

Maintain IdP group-claim to organization-role mappings; these grant org roles, including org admin, automatically at login.

Default policy: org_admin — authorized against the organization named by the route's {org_ref} parameter: platform admins always pass; otherwise the caller needs the admin membership role in that organization.

MethodsPath
GET, POST/orgs/{org_ref}/idp-mappings
DELETE, PATCH/orgs/{org_ref}/idp-mappings/{mapping_id}

internal ​

internal:run_callbacks ​

Worker run-execution callbacks: create child runs, read run state and outputs, replace run vars, report step, event, artifact and approval progress, cancel runs and assign shared workers.

Default policy: internal — worker and scheduler callbacks presenting X-Internal-Token (not checked when auth is disabled, or when no token is configured and HEGEMONY_INTERNAL_API_TOKEN_OPTIONAL=true).

MethodsPath
POST/internal/runs/{run_id}/assign-shared-worker
POST/internal/runs/{run_id}/artifacts/upload
POST/internal/runs/{run_id}/tf-state-access
POST/internal/runs/{run_id}/registry-access
GET/internal/runs/{run_id}/step-outputs
POST/internal/runs/{run_id}/artifacts
POST/internal/runs/{run_id}/approvals
POST/internal/runs/{run_id}/step-runs
PUT/internal/runs/{run_id}/run-vars
GET/internal/runs/{run_id}/outputs
POST/internal/runs/{run_id}/cancel
POST/internal/runs/{run_id}/events
POST/internal/runs
DELETE/internal/runs/{run_id}/tf-state-access/{token_id}
DELETE/internal/runs/{run_id}/registry-access/{token_id}
PATCH/internal/step-runs/{step_run_id}
PATCH/internal/approvals/{approval_id}
GET, PATCH/internal/runs/{run_id}

internal:monitor_callbacks ​

Worker monitor callbacks: create and update monitors, poll for an external stop, batch-insert samples and finalize a run's monitors.

Default policy: internal — worker and scheduler callbacks presenting X-Internal-Token (not checked when auth is disabled, or when no token is configured and HEGEMONY_INTERNAL_API_TOKEN_OPTIONAL=true).

MethodsPath
POST/api/v1/monitor-samples/batch
POST/api/v1/monitors
POST/api/v1/monitors/finalize-for-run/{run_id}
GET/api/v1/monitors/{monitor_db_id}
PATCH/api/v1/monitors/{monitor_db_id}

internal:resolve ​

Worker lookups of attachments, subscriptions, destinations, backends, variables and device download URLs.

Default policy: internal — worker and scheduler callbacks presenting X-Internal-Token (not checked when auth is disabled, or when no token is configured and HEGEMONY_INTERNAL_API_TOKEN_OPTIONAL=true).

MethodsPath
GET/internal/flows/{flow_id}/notification-subscriptions
GET/internal/runs/{run_id}/registry-credentials
GET/internal/flows/{flow_id}/attachments
POST/files/{file_id}/device-download-url
GET/internal/runs/{run_id}/attachments
GET/internal/secrets-backends
GET/internal/variables
GET/internal/notification-destinations/{destination_id}

internal:scheduler ​

Scheduler callbacks for due schedules and maintenance ticks.

Default policy: internal — worker and scheduler callbacks presenting X-Internal-Token (not checked when auth is disabled, or when no token is configured and HEGEMONY_INTERNAL_API_TOKEN_OPTIONAL=true).

MethodsPath
POST/internal/schedules/{schedule_id}/trigger
POST/internal/maintenance/tick
GET/internal/schedules/due

internal:worker_registry ​

Worker heartbeats (the Workers registry) and each worker's report of the environment-variable names it exposes.

Default policy: internal — worker and scheduler callbacks presenting X-Internal-Token (not checked when auth is disabled, or when no token is configured and HEGEMONY_INTERNAL_API_TOKEN_OPTIONAL=true).

MethodsPath
POST/internal/workers/heartbeat
POST/internal/runtime/env-keys
DELETE/internal/runtime/env-keys/{worker_id}

run ​

run:stream ​

Live run event and monitor streams over SSE.

Default policy: custom — the endpoint authenticates the caller itself.

MethodsPath
GET/bff/runs/{run_id}/events/stream
GET/runs/{run_id}/monitors/stream

run:view ​

Browse runs, their events, monitors and monitor samples, and download run artifacts.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/runs/{run_id}/artifacts/{artifact_id}/download
GET/runs/{run_id}/monitors/{monitor_id}/samples
GET/runs/{run_id}/artifacts/download-all
GET/runs/{run_id}/monitors
GET/runs/{run_id}/events
GET/runs/filter-options
GET/runs/{run_id}/monitors/{monitor_id}
GET/runs/{run_id}
GET/runs

run:trigger ​

Start a run.

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/runs

run:control ​

Cancel, pause, resume and rename runs; soft-delete and restore them.

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/runs/{run_id}/restore
POST/runs/{run_id}/cancel
POST/runs/{run_id}/resume
POST/runs/{run_id}/pause
PATCH/runs/{run_id}
DELETE/runs/{run_id}

run:purge ​

Permanently delete runs.

Default policy: admin — granted to roles admin.

MethodsPath
DELETE/runs/{run_id}/permanent

approval ​

approval:view ​

Browse pending and historical approval requests.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/approvals/node-defaults
GET/runs/{run_id}/approvals
GET/approvals/pending
GET/approvals/{approval_id}
GET/approvals

approval:decide ​

Approve or reject an approval request.

Default policy: approver — granted to roles admin, approver.

MethodsPath
POST/runs/{run_id}/approvals/{approval_id}/decision
POST/approvals/{approval_id}/decision

site ​

site:view ​

Browse sites and the site tree.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/sites/tree
GET/sites/{site_id}
GET/sites

site:manage ​

Create, edit, duplicate, soft-delete and restore sites.

Default policy: admin — granted to roles admin.

MethodsPath
POST/sites/{site_id}/duplicate
POST/sites/{site_id}/restore
POST/sites/bulk/restore
POST/sites/bulk/delete
PATCH/sites/{site_id}
DELETE/sites/{site_id}
POST/sites

site:purge ​

Permanently delete sites.

Default policy: admin — granted to roles admin.

MethodsPath
DELETE/sites/{site_id}/permanent
POST/sites/bulk/permanent

device ​

device:view ​

Browse and search devices.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/devices/search/ids
GET/devices/search
GET/devices/{device_id}
GET/devices

device:manage ​

Create, edit, duplicate, soft-delete and restore devices.

Default policy: admin — granted to roles admin.

MethodsPath
POST/devices/{device_id}/duplicate
POST/devices/{device_id}/restore
POST/devices/bulk/restore
POST/devices/bulk/delete
PUT/devices/{device_id}
DELETE/devices/{device_id}
POST/devices

device:annotate ​

Set the local overlay beside a provider-sourced device's own data - the local tags and the maintenance-state override - without touching what the provider reports.

Default policy: operator — granted to roles admin, operator.

MethodsPath
PATCH/devices/{device_id}/overlay

device:purge ​

Permanently delete devices.

Default policy: admin — granted to roles admin.

MethodsPath
DELETE/devices/{device_id}/permanent
POST/devices/bulk/permanent

inventory_object ​

inventory_object:view ​

Browse generic inventory objects, their object types and the registered provider types.

Default policy: operator — granted to roles admin, operator.

MethodsPath
GET/inventory/objects/{object_type}/resolve
GET/inventory/object-types/counts
GET/inventory/provider-types
GET/inventory/object-types
GET/inventory/objects/{object_type}/{object_id}
GET/inventory/objects/{object_type}

inventory_provider ​

inventory_provider:view ​

Read inventory provider configurations (credentials redacted), their sync history and per-provider imported-inventory counts.

Default policy: admin — granted to roles admin.

MethodsPath
GET/inventory/providers/{provider_id}/sync-history
GET/inventory/provider-inventory
GET/inventory/providers
GET/inventory/providers/{provider_id}

inventory_provider:manage ​

Create, edit, soft-delete and restore inventory provider configurations.

Default policy: admin — granted to roles admin.

MethodsPath
POST/inventory/providers/{provider_id}/discover
POST/inventory/providers/{provider_id}/restore
POST/inventory/providers
PATCH/inventory/providers/{provider_id}
DELETE/inventory/providers/{provider_id}

inventory_provider:test ​

Test connectivity to an inventory provider using its stored credentials.

Default policy: admin — granted to roles admin.

MethodsPath
POST/inventory/providers/{provider_id}/test-connection

inventory_provider:sync ​

Run a full sync from a provider now; creates, updates, restores and marks stale the devices, sites and objects imported from it.

Default policy: admin — granted to roles admin.

MethodsPath
POST/inventory/providers/{provider_id}/sync

inventory_provider:purge ​

Permanently delete a soft-deleted provider, or hard-delete every device, site, object and sync-history row it imported (irreversible).

Default policy: admin — granted to roles admin.

MethodsPath
POST/inventory/providers/{provider_id}/purge-inventory
DELETE/inventory/providers/{provider_id}/permanent

worker ​

worker:view ​

Read the worker registry.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/workers

flow ​

flow:view ​

Browse flows and their committed versions, preview YAML, validate definitions, render the launch form and resolve its option sources, and read step-handler documentation.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/flows/step-handler-types/{handler_id}/docs
POST/flows/{flow_id}/interface/preview-resolve
POST/flows/{flow_id}/interface/validate
POST/flows/{flow_id}/interface/options
GET/flows/{flow_id}/versions/compare
GET/flows/{flow_id}/versioning-info
GET/flows/{flow_id}/launch-contract
GET/flow-interface/option-sources
GET/flows/{flow_id}/yaml-preview
GET/flow-interface/field-types
GET/flows/{flow_id}/interface
POST/flows/{flow_id}/validate
GET/flows/{flow_id}/versions
GET/flows/{flow_id}/versions/{version}
GET/flows/{flow_id}
GET/flows

flow:manage ​

Create, edit and duplicate flows; save, revert and load an earlier version into their drafts; soft-delete and restore flows.

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/flows/{flow_id}/revert-draft
PATCH/flows/{flow_id}/manual-runs
POST/flows/{flow_id}/duplicate
POST/flows/{flow_id}/restore
POST/flows/{flow_id}/draft
PATCH/flows/{flow_id}/pin
POST/flows/{flow_id}/restore/{version}
PUT/flows/{flow_id}
DELETE/flows/{flow_id}
POST/flows

flow:commit ​

Commit the current draft as a new published version.

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/flows/{flow_id}/commit

flow:purge ​

Permanently delete flows.

Default policy: admin — granted to roles admin.

MethodsPath
DELETE/flows/{flow_id}/permanent

flow_attachment ​

flow_attachment:view ​

Browse and download flow attachments.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/flows/{flow_id}/attachments/{attachment_id}/download
GET/flows/{flow_id}/attachments
GET/flows/{flow_id}/attachments/{attachment_id}

flow_attachment:manage ​

Upload, edit, rename, move and delete flow attachments and attachment folders.

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/flows/{flow_id}/attachments/bulk-rename
POST/flows/{flow_id}/attachments/bulk
POST/flows/{flow_id}/attachments
PATCH/flows/{flow_id}/attachments/{attachment_id}
DELETE/flows/{flow_id}/attachments/{attachment_id}

flow_subscription ​

flow_subscription:view ​

Read a flow's notification subscriptions.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/flows/{flow_id}/notifications/subscriptions

flow_subscription:manage ​

Create, edit and delete a flow's notification subscriptions.

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/flows/{flow_id}/notifications/subscriptions
PATCH/flows/{flow_id}/notifications/subscriptions/{subscription_id}
DELETE/flows/{flow_id}/notifications/subscriptions/{subscription_id}

flow_git ​

flow_git:view ​

Read a flow's git sync history.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/flows/{flow_id}/git-sync-history

flow_git:manage ​

Link a flow to a git repository path, detach it, and pull from the repository; a pull overwrites the definition and can discard an uncommitted draft.

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/flows/{flow_id}/sync-from-git
POST/flows/{flow_id}/git/detach
PATCH/flows/{flow_id}/git

flow_git:push ​

Commit and push a flow's committed version to its git remote (force may overwrite the remote branch).

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/flows/{flow_id}/push-to-git

schedule ​

schedule:view ​

Browse schedules and validate cron expressions.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
POST/schedules/validate-cron
GET/schedules/{schedule_id}
GET/schedules

schedule:manage ​

Create, edit, soft-delete and restore schedules.

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/schedules/{schedule_id}/restore
PATCH/schedules/{schedule_id}
DELETE/schedules/{schedule_id}
POST/schedules

schedule:trigger ​

Run a schedule immediately.

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/schedules/{schedule_id}/run

schedule:purge ​

Permanently delete schedules.

Default policy: admin — granted to roles admin.

MethodsPath
DELETE/schedules/{schedule_id}/permanent

webhook ​

webhook:view ​

Browse webhook endpoints, including each endpoint's public trigger path token and allowed-source-IP list.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/webhooks/{webhook_id}
GET/webhooks

webhook:manage ​

Create, edit, soft-delete and restore webhook endpoints, and dry-run validate an endpoint's configuration (nothing is sent, no run is created).

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/webhooks/{webhook_id}/restore
POST/webhooks/{webhook_id}/test
PATCH/webhooks/{webhook_id}
DELETE/webhooks/{webhook_id}
POST/webhooks

webhook:rotate_secret ​

Re-point a webhook endpoint at a different existing secret for HMAC/bearer verification.

Default policy: admin — granted to roles admin.

MethodsPath
POST/webhooks/{webhook_id}/rotate-secret

webhook:purge ​

Permanently delete webhook endpoints.

Default policy: admin — granted to roles admin.

MethodsPath
DELETE/webhooks/{webhook_id}/permanent

webhook:receive ​

Public trigger URL called by external systems.

Default policy: public — no authentication required.

MethodsPath
POST/hooks/{path_token}

webhook_delivery ​

webhook_delivery:view ​

Inspect a webhook's delivery log: source IP, signature result, response status, run ids and a payload hash (never payload bodies).

Default policy: operator — granted to roles admin, operator.

MethodsPath
GET/webhooks/{webhook_id}/deliveries

notification_destination ​

notification_destination:view ​

Browse notification destinations and destination types, including each destination's full configuration (credentials appear only as secret references).

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/notifications/destination-types
GET/notifications/flow-defaults
GET/notifications/destinations
GET/notifications/destinations/{destination_id}

notification_destination:manage ​

Create, edit, duplicate, soft-delete and restore notification destinations.

Default policy: admin — granted to roles admin.

MethodsPath
POST/notifications/destinations/{destination_id}/duplicate
POST/notifications/destinations/{destination_id}/restore
POST/notifications/destinations
PATCH/notifications/destinations/{destination_id}
DELETE/notifications/destinations/{destination_id}

notification_destination:test ​

Dispatch a real test message to a saved destination or an ad-hoc configuration; the worker resolves embedded secret() references before sending.

Default policy: admin — granted to roles admin.

MethodsPath
POST/notifications/destinations/{destination_id}/test
POST/notifications/destinations/test-config

notification_destination:purge ​

Permanently delete notification destinations.

Default policy: admin — granted to roles admin.

MethodsPath
DELETE/notifications/destinations/{destination_id}/permanent

secret ​

secret:view ​

Browse secret references and providers. Values are never returned, but reading a secret performs a live read against its backend to list key names.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/secrets/providers
GET/secrets/{secret_id}
GET/secrets

secret:discover ​

List secrets that exist in a backend but were not created via Hegemony (names only).

Default policy: operator — granted to roles admin, operator.

MethodsPath
GET/secrets/discovered

secret:manage ​

Create and edit secrets, writing their values into the external backend; delete secrets, which also removes them from the backend (no restore).

Default policy: admin — granted to roles admin.

MethodsPath
POST/secrets/{secret_id}/duplicate
PATCH/secrets/{secret_id}
DELETE/secrets/{secret_id}
POST/secrets

tf_state ​

tf_state:view ​

Browse managed Terraform/OpenTofu states: names, versions, sizes and who holds a lock. Never the state documents themselves.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/tf-states/{name}/versions
GET/tf-states/{name}
GET/tf-states

tf_state:read ​

Read and download managed state documents, which can hold resource secrets (the HTTP backend's read). A tf.plan or tf.apply step's token acts with the operator role: allocating this above operator, or disabling it, also refuses those steps.

Default policy: operator — granted to roles admin, operator.

MethodsPath
GET/tf-states/{name}/versions/{version}/content
GET/tf-states/{name}/state

tf_state:write ​

Write, lock and unlock managed states (the HTTP backend), import a state file as a new state, and roll a state back to an earlier version. Forcing another holder's lock (tofu force-unlock) also needs tf_state:manage. A tf.plan or tf.apply step's token acts with the operator role: allocating this above operator, or disabling it, also refuses those steps.

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/tf-states/{name}/rollback
POST/tf-states/{name}/import
POST/tf-states/{name}/state
DELETE, POST/tf-states/{name}/lock

tf_state:manage ​

Force-unlock a state held by someone else (here or with tofu force-unlock), and delete a state with all its versions (no restore).

Default policy: admin — granted to roles admin.

MethodsPath
POST/tf-states/{name}/force-unlock
DELETE/tf-states/{name}

secret_backend ​

secret_backend:view ​

Browse secret backend configurations and backend types; the detail view includes the store address and credential env/file names (never values).

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/settings/secret-backend-types
GET/settings/secrets-backends
GET/settings/secrets-backends/{backend_id}

secret_backend:manage ​

Create, edit and delete secret backends; editing a backend can repoint where every secret() reference resolves.

Default policy: admin — granted to roles admin.

MethodsPath
POST/settings/secrets-backends
PATCH/settings/secrets-backends/{backend_id}
DELETE/settings/secrets-backends/{backend_id}

secret_backend:test ​

Run a backend's connectivity and authentication self-test against the external store.

Default policy: admin — granted to roles admin.

MethodsPath
POST/settings/secrets-backends/{backend_id}/test

secret_backend:browse ​

List item and vault names inside a backend's external store (names only, never values).

Default policy: admin — granted to roles admin.

MethodsPath
GET/settings/secrets-backends/{backend_id}/items

variable ​

variable:view ​

Browse variables.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/variables/{variable_id}
GET/variables

variable:manage ​

Create, edit, soft-delete and restore variables.

Default policy: admin — granted to roles admin.

MethodsPath
POST/variables/{variable_id}/restore
PATCH/variables/{variable_id}
DELETE/variables/{variable_id}
POST/variables

variable:purge ​

Permanently delete variables.

Default policy: admin — granted to roles admin.

MethodsPath
DELETE/variables/{variable_id}/permanent

variable_context ​

variable_context:view ​

Editor support for the variable picker: list variables, secret key names, environment-variable names and step outputs, and dry-run validate templates (never values).

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
POST/variable-contexts/validate
GET/variable-contexts
POST/variable-contexts

file_repository ​

file_repository:view ​

Browse file repositories, their kinds and folders.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/file-repositories/{file_repository_id}/folders
GET/file-repositories/kinds
GET/file-repositories/{file_repository_id}
GET/file-repositories

file_repository:manage ​

Create, edit, delete and set the default file repository; editing endpoint, bucket or credentials repoints where the org's files are stored.

Default policy: admin — granted to roles admin.

MethodsPath
POST/file-repositories/{file_repository_id}/set-default
POST/file-repositories/ensure-default
PATCH/file-repositories/{file_repository_id}
DELETE/file-repositories/{file_repository_id}
POST/file-repositories

file_repository:test ​

Test connectivity to a file repository.

Default policy: admin — granted to roles admin.

MethodsPath
POST/file-repositories/{file_repository_id}/test-connection

registry_credential ​

registry_credential:view ​

List the organization's logins for external container registries (host, username and the password's secret reference, never its value).

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/registry-credentials/{credential_id}
GET/registry-credentials

registry_credential:manage ​

Add, edit and delete registry logins; container steps in the organization use them automatically when pulling images from that registry host.

Default policy: admin — granted to roles admin.

MethodsPath
PATCH/registry-credentials/{credential_id}
DELETE/registry-credentials/{credential_id}
POST/registry-credentials

registry_credential:test ​

Try a registry login against the registry.

Default policy: admin — granted to roles admin.

MethodsPath
POST/registry-credentials/{credential_id}/test

registry ​

registry:authorize ​

The platform registry proxy's per-request authorization. Answers only the proxy (a shared secret) and checks a container step's registry token itself: pulls from the step's organization, the shared organization and the global namespace, pushes into the organization's image cache.

Default policy: custom — the endpoint authenticates the caller itself.

MethodsPath
GET/registry/authorize

image ​

image:view ​

Browse the platform registry's images visible from the organization: its own namespace, the shared organization's and the global one, with tags, sizes and pull statistics.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/images/repositories
GET/images/namespaces
GET/images/repository

image:manage ​

Delete tags and repositories in the organization's own namespace of the platform registry (cached copies included).

Default policy: admin — granted to roles admin.

MethodsPath
DELETE/images/repository/tag
DELETE/images/repository

image:manage_global ​

Delete tags and repositories in the registry's global namespace and read every namespace's usage. Platform admins only: the routes are platform-scoped, so the admin policy means the realm role, not an organization membership.

Default policy: admin — granted to roles admin.

MethodsPath
DELETE/platform/images/repository/tag
DELETE/platform/images/repository
GET/platform/images/usage

file ​

file:view ​

Browse, download and inspect usage of stored files, including minting time-limited presigned download URLs that work without authentication.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
POST/files/{file_id}/download-url
GET/files/{file_id}/download
GET/files/{file_id}/usage
GET/files/{file_id}/{filename}
GET/files/{file_id}
GET/files

file:manage ​

Upload files, import files from a URL fetched by the server, manage folders, move files, and permanently delete files (no soft-delete).

Default policy: admin — granted to roles admin.

MethodsPath
POST/file-repositories/{file_repository_id}/folders/rename
POST/file-repositories/{file_repository_id}/files/upload
POST/file-repositories/{file_repository_id}/files/import
POST/file-repositories/{file_repository_id}/folders
DELETE/file-repositories/{file_repository_id}/folders
POST/files/{file_id}/move
DELETE/files/{file_id}

git_repository ​

git_repository:view ​

Browse git repositories and their sync history, and read the tree and file contents of the remote (any path or branch) using the stored credentials.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/git-repositories/{repo_id}/sync-history
GET/git-repositories/{repo_id}/tree
GET/git-repositories/{repo_id}/file
GET/git-repositories/{repo_id}
GET/git-repositories

git_repository:manage ​

Create, edit and soft-delete git repositories; editing the URL, branch or credentials redirects every linked flow's pulls and pushes.

Default policy: operator — granted to roles admin, operator.

MethodsPath
PATCH/git-repositories/{repo_id}
DELETE/git-repositories/{repo_id}
POST/git-repositories

git_repository:test ​

Test connectivity and credentials of a git repository (shallow clone).

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/git-repositories/{repo_id}/test-connection

git_repository:sync ​

Pull-sync every flow linked to a repository in one operation (force can overwrite dirty drafts).

Default policy: operator — granted to roles admin, operator.

MethodsPath
POST/git-repositories/{repo_id}/sync

binary_artifact ​

binary_artifact:view ​

Browse storage usage of binary run artifacts across all runs and download them in bulk.

Default policy: admin — granted to roles admin.

MethodsPath
POST/binary-artifacts/bulk-download
GET/binary-artifacts

binary_artifact:purge ​

Permanently delete binary artifact content from object storage (no restore).

Default policy: admin — granted to roles admin.

MethodsPath
POST/binary-artifacts/bulk-delete
DELETE/binary-artifacts/{artifact_id}

dashboard ​

dashboard:view ​

Home-page aggregate of the active organization's runs, flows and devices; every figure is viewer-visible through the list endpoints it summarizes.

Default policy: viewer — granted to roles admin, auditor, operator, viewer.

MethodsPath
GET/dashboard/stats

dashboard:org_health ​

Health roll-up of the caller's own organization (members, activity, approvals, schedules, inventory sync).

Default policy: admin — granted to roles admin.

MethodsPath
GET/dashboard/org-health

api_token ​

api_token:manage ​

Issue personal access tokens (plaintext shown once) and list and revoke tokens, including every token owned by a user.

Default policy: admin — granted to roles admin.

MethodsPath
DELETE/api-tokens/by-user/{username}
DELETE/api-tokens/{token_id}
POST/api-tokens
GET/api-tokens

audit_log ​

audit_log:view ​

Browse the audit log and its statistics.

Default policy: admin — granted to roles admin.

MethodsPath
GET/audit-logs/filter-options
GET/audit-logs/stats
GET/audit-logs/resource/{resource_type}/{resource_id}
GET/audit-logs/{audit_id}
GET/audit-logs

audit_log:cleanup ​

Delete old audit-log entries.

Default policy: admin — granted to roles admin.

MethodsPath
POST/audit-logs/cleanup

permission ​

permission:manage ​

Read the effective route and action permission matrix and set or clear overrides; holders can grant any role any overridable capability.

Default policy: admin — granted to roles admin. Pinned: no override may reallocate this action or pin one of its routes.

MethodsPath
PUT/settings/permissions/actions/override
DELETE/settings/permissions/actions/override
PUT/settings/permissions/override
DELETE/settings/permissions/override
GET/settings/permissions/actions
GET/settings/permissions

plugin ​

plugin:view ​

Read the installed out-of-tree plugins overview, including inventory plugins.

Default policy: operator — granted to roles admin, operator.

MethodsPath
GET/inventory/plugins
GET/settings/plugins

environment_variable ​

environment_variable:view ​

Browse environment variable names visible to the API and worker.

Default policy: admin — granted to roles admin.

MethodsPath
GET/settings/environment-variables

maintenance_job ​

maintenance_job:view ​

Monitor scheduler-owned maintenance jobs.

Default policy: admin — granted to roles admin.

MethodsPath
GET/settings/maintenance/jobs

platform ​

platform:health ​

Deployment-wide health with cross-tenant counts; platform-scoped so an organization admin cannot satisfy it.

Default policy: admin — granted to roles admin.

MethodsPath
GET/platform/health

platform_sync ​

platform_sync:view ​

Read platform-sync profiles, runs, plans, drift and destructive authorizations.

Default policy: admin — granted to roles admin.

MethodsPath
GET/platform-sync/profiles/{profile_id}/destructive-authorizations
GET/platform-sync/profiles/{profile_id}/drift
GET/platform-sync/profiles/{profile_id}/runs
GET/platform-sync/profiles
GET/platform-sync/plans/{plan_id}/families/{family}
GET/platform-sync/profiles/{profile_id}
GET/platform-sync/plans/{plan_id}
GET/platform-sync/runs/{run_id}

platform_sync:manage ​

Create, edit and delete platform-sync profiles.

Default policy: admin — granted to roles admin.

MethodsPath
POST/platform-sync/profiles
PATCH/platform-sync/profiles/{profile_id}
DELETE/platform-sync/profiles/{profile_id}

platform_sync:execute ​

Export platform configuration to the profile's git remote, compute drift plans, apply repository state back into the platform and resolve conflicts.

Default policy: admin — granted to roles admin.

MethodsPath
POST/platform-sync/profiles/{profile_id}/conflicts/{change_id}/resolve
POST/platform-sync/profiles/{profile_id}/export
POST/platform-sync/profiles/{profile_id}/apply
POST/platform-sync/profiles/{profile_id}/plan

platform_sync:authorize_destructive ​

Grant or revoke the scoped authorizations that allow a destructive platform-sync apply to proceed.

Default policy: admin — granted to roles admin.

MethodsPath
POST/platform-sync/profiles/{profile_id}/destructive-authorizations/{authorization_id}/revoke
POST/platform-sync/profiles/{profile_id}/destructive-authorizations

config_exchange ​

config_exchange:view ​

Read the configuration-exchange schema, families, projection and operation status.

Default policy: admin — granted to roles admin.

MethodsPath
GET/config-exchange/resource-families
GET/config-exchange/projection
GET/config-exchange/schema
GET/config-exchange/operations/{correlation_id}

config_exchange:execute ​

Export the whole platform configuration as YAML (never secret values), and plan or apply a bundle that creates, updates and deletes resources across every family, including secrets and permission overrides.

Default policy: admin — granted to roles admin.

MethodsPath
POST/config-exchange/operations/{correlation_id}/cancel
POST/config-exchange/operations

Released as open source under the AGPL-3.0-or-later license. Development is sponsored by Rexonix s.r.o.. Contact — [email protected].