Cerbos
- CerbosService
- postCheck
- postCheck resources
- postCheck resource batch
- postPlan resources
- getGet server information
- CerbosAdminService
- getList audit log entries
- getList policies
- getInspect policies
- getGet policy
- delDisable policy
- postAdd or update policies
- putAdd or update policies
- postDisable policy
- putDisable policy
- postEnable policy
- putEnable policy
- getGet schema
- delDelete schema
- postAdd or update schema
- putAdd or update schema
- getList schemas
- getReload store
Cerbos (latest)
Download OpenAPI specification: Download
Cerbos: info@cerbos.dev URL: https://cerbos.dev
CerbosService CerbosService
Cerbos Policy Decision Point
Check Resource Set
[Deprecated: Use CheckResources API instead] Check whether a principal has permissions to perform the given actions on a set of resource instances.
Request Body schema: application/json required
PDP Request
| requestId | string Optional application-specific ID useful for correlating logs for analysis. |
| actions required |
Array of strings non-empty unique List of actions being performed on the set of resources. |
| principal required |
object (enginev1Principal) A person or application attempting to perform the actions on the set of resources. |
| resource required |
object (v1ResourceSet) Set of resources to check |
| includeMeta | boolean Opt to receive request processing metadata in the response. |
| auxData | object (cerbosrequestv1AuxData) Structured auxiliary data useful for evaluating the request |
Responses
200
A successful response.
default
An unexpected error response.
post/api/check
https://docs.cerbos.dev/api/check
Request samples
- Payload
Content type
application/json
`{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",
"actions": ["view:public", "comment"],
"principal": {"id": "bugs_bunny", "policyVersion":"default", "roles": ["user"], "attr": {"beta_tester": true}, "scope": "acme.corp"},
"resource": {"kind": "album:object", "policyVersion": "default", "instances": {"XX125": {"attr": {"owner": "bugs_bunny", "public": false, "flagged": false }}, "XX225": {"attr": {"owner": "daffy_duck", "public": true, "flagged": false}}},"scope":"^(a]w-](.w-]))$"},
"includeMeta": true,
"auxData": {"jwt": {"token": "eyJhbGciOiJFUzM4NCIsImtpZCI6IjE5TGZaYXRFZGc4M1lOYzVyMjNndU1KcXJuND0iLCJ0eXAiOiJKV1QifQ.eyJhdWQiOlsiY2VyYm9zLWp3dC10ZXN0cyJdLCJjdXN0b21BcnJheSI6WyJBIiwiQiIsIkMiXSwiY3VzdG9tSW50Ijo0MiwiY3VzdG9tTWFwIjp7IkEiOiJBQSIsIkIiOiJCQiIsIkMiOiJDQyJ9LCJjdXN0b21TdHJpbmciOiJmb29iYXIiLCJleHAiOjE5NDk5MzQwMzksImlzcyI6ImNlcmJvcy10ZXN0LXN1aXRlIn0.WN_tOScSpd_EI-P5EI1YlagxEgExSfBjAtcrgcF6lyWj1lGpR_GKx9goZEp2p_t5AVWXN_bjz_sMUmJdJa4cVd55Qm1miR-FKu6oNRHnSEWdMFmnArwPw-YDJWfylLFX", "keySetId": "my-keyset"}}}`
Response samples
- 200
- default
Content type
application/json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b", "resourceInstances": {"XX125": {"actions": {"view:*": "EFFECT_ALLOW", "comment": "EFFECT_ALLOW"}}, "XX225": {"actions": {"view:*": "EFFECT_DENY", "comment": "EFFECT_DENY"}}}, "meta": {"resourceInstances": {"XX125": {"actions": {"view:*": {"matched_policy": "album:object:default"}, "comment": {"matched_policy": "album:object:default"}}, "effective_derived_roles": ["owner"]}, "XX225": {"actions": {"view:*": {"matched_policy": "album:object:default"}, "comment": {"matched_policy": "album:object:default"}}}}}}}
Check Resources
Check a principal's permissions to a batch of heterogeneous resources and actions.
Request Body schema: application/json required
Check resources request
| requestId | string Optional application-specific ID useful for correlating logs for analysis. |
| includeMeta | boolean Add request processing metadata to the response. |
| principal required |
object (enginev1Principal) A person or application attempting to perform the actions on the set of resources. |
| resources required |
Array of objects (CheckResourcesRequestResourceEntry) non-empty unique List of resources and actions. |
| auxData | object (cerbosrequestv1AuxData) Structured auxiliary data useful for evaluating the request |
Responses
200
A successful response.
default
An unexpected error response.
post/api/check/resources
https://docs.cerbos.dev/api/check/resources
Request samples
- Payload
Content type
application/json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b", "includeMeta": true, "principal": {"id": "bugs_bunny", "policyVersion": "default", "roles": ["user"], "attr": {"beta_tester": true}, "scope": "acme.corp"}, "resources": [{"actions": ["view", "comment"], "resource": {"kind": "album:object", "policyVersion": "default", "id": "XX125", "attr": {"owner": "bugs_bunny", "public": false, "flagged": false}}}], "auxData": {"jwt": {"token": "eyJhbGciOiJFUzM4NCIsImtpZCI6IjE5TGZaYXRFZGc4M1lOYzVyMjNndU1KcXJuND0iLCJ0eXAiOiJKV1QifQ.eyJhdWQiOlsiY2VyYm9zLWp3dC10ZXN0cyJdLCJjdXN0b21BcnJheSI6WyJBIiwiQiIsIkMiXSwiY3VzdG9tSW50Ijo0MiwiY3VzdG9tTWFwIjp7IkEiOiJBQSIsIkIiOiJCQiIsIkMiOiJDQyJ9LCJjdXN0b21TdHJpbmciOiJmb29iYXIiLCJleHAiOjE5NDk5MzQwMzksImlzcyI6ImNlcmJvcy10ZXN0LXN1aXRlIn0.WN_tOScSpd_EI-P5EI1YlagxEgExSfBjAtcrgcF6lyWj1lGpR_GKx9goZEp2p_t5AVWXN_bjz_sMUmJdJa4cVd55Qm1miR-FKu6oNRHnSEWdMFmnArwPw-YDJWfylLFX", "keySetId": "my-keyset"}}}
Response samples
- 200
- default
Content type
application/json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b", "results": [{"resource": {"Id": "XX125", "kind": "album:object"}, "actions": {"view": "EFFECT_ALLOW", "comment": "EFFECT_DENY"}}], "cerbosCallId": "string"}