Cerbos

Cerbos (latest)

CerbosService

Check Resources

Check a principal's permissions to a batch of heterogeneous resources and actions.

Request Body schema: application/json required

requestId string
Optional application-specific ID useful for correlating logs for analysis.
includeMeta boolean
Add request processing metadata to the response.
principal
required
object (enginev1Principal)
A person or application attempting to perform the actions on the set of resources.
resources
required
Array of objects (CheckResourcesRequestResourceEntry) non-empty unique
List of resources and actions.
auxData object (cerbosrequestv1AuxData)
Structured auxiliary data useful for evaluating the request

Responses

200

A successful response.

post/api/check/resources

https://docs.cerbos.dev/api/check/resources

Request samples

Content type

application/json

{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",

"includeMeta": true,

"principal": {"id": "bugs_bunny",

"policyVersion": "default",

"roles": ["user"],

"attr": {"beta_tester": true},

"scope": "acme.corp"},

"resources": [{"actions": ["view","comment"],

"resource": {"kind": "album:object","policyVersion": "default","id": "XX125","attr": {"owner": "bugs_bunny","public": false,"flagged": false}}}],

"auxData": {"jwt": {"token": "eyJhbGciOiJFUzM4NCIsImtpZCI6IjE5TGZaYXRFZGc4M1lOYzVyMjNndU1KcXJuND0iLCJ0eXAiOiJKV1QifQ.eyJhdWQiOlsiY2VyYm9zLWp3dC10ZXN0cyJdLCJjdXN0b21BcnJheSI6WyJBIiwiQiIsIkMiXSwiY3VzdG9tSW50Ijo0MiwiY3VzdG9tTWFwIjp7IkEiOiJBQSIsIkIiOiJCQiIsIkMiOiJDQyJ9LCJjdXN0b21TdHJpbmciOiJmb29iYXIiLCJleHAiOjE5NDk5MzQwMzksImlzcyI6ImNlcmJvcy10ZXN0LXN1aXRlIn0.WN_tOScSpd_EI-P5EI1YlagxEgExSfBjAtcrgcF6lyWj1lGpR_GKx9goZEp2p_t5AVWXN_bjz_sMUmJdJa4cVd55Qm1miR-FKu6oNRHnSEWdMFmnArwPw-YDJWfylLFX",

"keySetId": "my-keyset"}}}"

Response samples

Content type

application/json

{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",

"results": [{"resource": {"Id": "XX125","kind": "album:object"},

"actions": {"view": "EFFECT_ALLOW","comment": "EFFECT_DENY"}}],

"cerbosCallId": "string"}

CerbosAdminService

List Policies

Authorizations:

BasicAuth

query Parameters
includeDisabled boolean
Include disabled policies
nameRegexp string
Filter policies by name with regexp
scopeRegexp string
Filter policies by scope with regexp
versionRegexp string
Filter policies by version with regexp
policyId Array of strings
For blob, disk, git stores use file name (.yaml). For mysql, postgres, sqlite3 use id (..) of the policy

Responses

200

A successful response.

get/admin/policies

https://docs.cerbos.dev/admin/policies

Response samples

Content type

application/json

{"policyIds": ["string"]}

Inspect Policies

Authorizations:

BasicAuth

Responses

200

A successful response.

get/admin/policies/inspect

https://docs.cerbos.dev/admin/policies/inspect

Response samples

Content type

application/json

{"results": {"property1": {"actions": ["string"],"variables": [{"name": "string","value": "string","kind": "KIND_UNSPECIFIED","source": "string","used": true}],"policyId": "string","derivedRoles": [{"name": "string","kind": "KIND_UNSPECIFIED","source": "string"}],"attributes": [{"kind": "KIND_UNSPECIFIED","name": "string"}],"constants": [{"name": "string","value": null,"kind": "KIND_UNSPECIFIED","source": "string","used": true}]},"property2": {"actions": ["string"],"variables": [{"name": "string","value": "string","kind": "KIND_UNSPECIFIED","source": "string","used": true}],"policyId": "string","derivedRoles": [{"name": "string","kind": "KIND_UNSPECIFIED","source": "string"}],"attributes": [{"kind": "KIND_UNSPECIFIED","name": "string"}],"constants": [{"name": "string","value": null,"kind": "KIND_UNSPECIFIED","source": "string","used": true}]} }
}

Get Policy

Authorizations:

BasicAuth

query Parameters
id
required
Array of strings
For blob, disk, git stores use file name (.yaml). For mysql, postgres, sqlite3 use id (..) of the policy

Responses

200

A successful response.

get/admin/policy

https://docs.cerbos.dev/admin/policy

Response samples

Content type

application/json

{"policies": [{"apiVersion": "string","disabled": true,"description": "string","metadata": {"sourceFile": "string","annotations": {"property1": "string","property2": "string"},"hash": "string","storeIdentifer": "string","storeIdentifier": "string","sourceAttributes": {"attributes": {"property1": null,"property2": null}}},"resourcePolicy": {"resource": "string","version": "string","importDerivedRoles": ["string"],"rules": [{"actions": ["string"],"derivedRoles": ["string"],"roles": ["string"],"condition": {"match": {"all": {"of": [null]},"any": {"of": [null]},"none": {"of": [null]},"expr": "string"},"script": "string"},"effect": "EFFECT_UNSPECIFIED","name": "string","output": {"expr": "string","when": {"ruleActivated": "string","conditionNotMet": "string"}}}],"scope": "string","schemas": {"principalSchema": {"ref": "string","ignoreWhen": {"actions": ["string"]}},"resourceSchema": {"ref": "string","ignoreWhen": {"actions": ["string"]}}},"variables": {"import": ["string"],"local": {"property1": "string","property2": "string"}},"scopePermissions": "SCOPE_PERMISSIONS_UNSPECIFIED","constants": {"import": ["string"],"local": {"property1": null,"property2": null}}},"principalPolicy": {"principal": "string","version": "string","rules": [{"resource": "string","actions": [{"action": "string","condition": {"match": {"all": null,"any": null,"none": null,"expr": null},"script": "string"},"effect": "EFFECT_UNSPECIFIED","name": "string","output": {"expr": "string","when": {"ruleActivated": null,"conditionNotMet": null}}}]} }]}}]}

List Schemas

Authorizations:

BasicAuth

Responses

200

A successful response.

get/admin/schemas

https://docs.cerbos.dev/admin/schemas

Response samples

Content type

application/json

{"schemaIds": ["string"]}

Reload Store

Authorizations:

BasicAuth

query Parameters
wait boolean
Wait until the reloading process finishes

Responses

200

A successful response.

get/admin/store/reload

https://docs.cerbos.dev/admin/store/reload

Response samples

Content type

application/json

{ }