Cerbos

Cerbos (latest)

Download OpenAPI specification: Download

Cerbos: info@cerbos.dev URL: https://cerbos.dev

tag/CerbosService CerbosService

Cerbos Policy Decision Point

tag/CerbosService/operation/CerbosService_CheckResourceSet Check Deprecated

[Deprecated: Use CheckResources API instead] Check whether a principal has permissions to perform the given actions on a set of resource instances.

Request Body schema: application/json required

PDP Request

requestId string
Optional application-specific ID useful for correlating logs for analysis.
actions
required
Array of strings non-empty unique
List of actions being performed on the set of resources.
principal
required
object (enginev1Principal)
A person or application attempting to perform the actions on the set of resources.
resource
required
object (v1ResourceSet)
Set of resources to check
includeMeta boolean
Opt to receive request processing metadata in the response.
auxData object (cerbosrequestv1AuxData)
Structured auxiliary data useful for evaluating the request

Responses

200

A successful response.

default

An unexpected error response.

post/api/check

https://docs.cerbos.dev/api/check

Request samples

Content type

application/json

Copy Expand all Collapse all

{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b", "actions": ["view:public", "comment"], "principal": {"id": "bugs_bunny", "policyVersion": "default", "roles": ["user"], "attr": {"beta_tester": true}, "scope": "acme.corp"}, "resource": {"kind": "album:object", "policyVersion": "default", "instances": {"XX125": {"attr": {"owner": "bugs_bunny", "public": false, "flagged": false}}, "XX225": {"attr": {"owner": "daffy_duck", "public": true, "flagged": false}}}, "scope": "^(a]w\-]*(\.w\-]*)*)*$"}, "includeMeta": true, "auxData": {"jwt": {"token": "eyJhbGciOiJFUzM4NCIsImtpZCI6IjE5TGZaYXRFZGc4M1lOYzVyMjNndU1KcXJuND0iLCJ0eXAiOiJKV1QifQ.eyJhdWQiOlsiY2VyYm9zLWp3dC10ZXN0cyJdLCJjdXN0b21BcnJheSI6WyJBIiwiQiIsIkMiXSwiY3VzdG9tSW50Ijo0MiwiY3VzdG9tTWFwIjp7IkEiOiJBQSIsIkIiOiJCQiIsIkMiOiJDQyJ9LCJjdXN0b21TdHJpbmciOiJmb29iYXIiLCJleHAiOjE5NDk5MzQwMzksImlzcyI6ImNlcmJvcy10ZXN0LXN1aXRlIn0.WN_tOScSpd_EI-P5EI1YlagxEgExSfBjAtcrgcF6lyWj1lGpR_GKx9goZEp2p_t5AVWXN_bjz_sMUmJdJa4cVd55Qm1miR-FKu6oNRHnSEWdMFmnArwPw-YDJWfylLFX", "keySetId": "my-keyset"}}}

Response samples

Content type

application/json

Copy Expand all Collapse all

{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b", "resourceInstances": {"XX125": {"actions": {"view:*": "EFFECT_ALLOW", "comment": "EFFECT_ALLOW"}}, "XX225": {"actions": {"view:*": "EFFECT_DENY", "comment": "EFFECT_DENY"}}}, "meta": {"resourceInstances": {"XX125": {"actions": {"view:*": {"matched_policy": "album:object:default"}, "comment": {"matched_policy": "album:object:default"}}, "effective_derived_roles": ["owner"]}, "XX225": {"actions": {"view:*": {"matched_policy": "album:object:default"}, "comment": {"matched_policy": "album:object:default"}}}}}}}

tag/CerbosService/operation/CerbosService_CheckResources Check resources

Check a principal's permissions to a batch of heterogeneous resources and actions.

Request Body schema: application/json required

Check resources request

requestId string
Optional application-specific ID useful for correlating logs for analysis.
includeMeta boolean
Add request processing metadata to the response.
principal
required
object (enginev1Principal)
A person or application attempting to perform the actions on the set of resources.
resources
required
Array of objects (CheckResourcesRequestResourceEntry) non-empty unique
List of resources and actions.
auxData object (cerbosrequestv1AuxData)
Structured auxiliary data useful for evaluating the request

Responses

200

A successful response.

default

An unexpected error response.

post/api/check/resources

https://docs.cerbos.dev/api/check/resources

Request samples

Content type

application/json

Copy Expand all Collapse all

{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b", "includeMeta": true, "principal": {"id": "bugs_bunny", "policyVersion": "default", "roles": ["user"], "attr": {"beta_tester": true}, "scope": "acme.corp"}, "resources": [{"actions": ["view","comment"], "resource": {"kind": "album:object", "policyVersion": "default", "id": "XX125", "attr": {"owner": "bugs_bunny", "public": false, "flagged": false}}}], "auxData": {"jwt": {"token": "eyJhbGciOiJFUzM4NCIsImtpZCI6IjE5TGZaYXRFZGc4M1lOYzVyMjNndU1KcXJuND0iLCJ0eXAiOiJKV1QifQ.eyJhdWQiOlsiY2VyYm9zLWp3dC10ZXN0cyJdLCJjdXN0b21BcnJheSI6WyJBIiwiQiIsIkMiXSwiY3VzdG9tSW50Ijo0MiwiY3VzdG9tTWFwIjp7IkEiOiJBQSIsIkIiOiJCQiIsIkMiOiJDQyJ9LCJjdXN0b21TdHJpbmciOiJmb29iYXIiLCJleHAiOjE5NDk5MzQwMzksImlzcyI6ImNlcmJvcy10ZXN0LXN1aXRlIn0.WN_tOScSpd_EI-P5EI1YlagxEgExSfBjAtcrgcF6lyWj1lGpR_GKx9goZEp2p_t5AVWXN_bjz_sMUmJdJa4cVd55Qm1miR-FKu6oNRHnSEWdMFmnArwPw-YDJWfylLFX", "keySetId": "my-keyset"}}}

Response samples

Content type

application/json

Copy Expand all Collapse all

{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b", "results": [{"resource": {"Id": "XX125", "kind": "album:object"}, "actions": {"view": "EFFECT_ALLOW", "comment": "EFFECT_DENY"}}], "cerbosCallId": "string"}

tag/CerbosService/operation/CerbosService_CheckResourceBatch Check resource batch Deprecated

[Deprecated: Use CheckResources API instead] Check a principal's permissions to a batch of heterogeneous resources and actions.

Request Body schema: application/json required

PDP Request

requestId string
Optional application-specific ID useful for correlating logs for analysis.
principal
required
object (enginev1Principal)
A person or application attempting to perform the actions on the set of resources.
resources
required
Array of objects (CheckResourceBatchRequestBatchEntry) non-empty unique
List of resources and actions.
auxData object (cerbosrequestv1AuxData)
Structured auxiliary data useful for evaluating the request

Responses

200

A successful response.

default

An unexpected error response.

post/api/check_resource_batch

https://docs.cerbos.dev/api/check_resource_batch

Request samples

Content type

application/json

Copy Expand all Collapse all

{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b", "principal": {"id": "bugs_bunny", "policyVersion": "default", "roles": ["user"], "attr": {"beta_tester": true}, "scope": "acme.corp"}, "resources": [{"actions": ["view","comment"], "resource": {"kind": "album:object", "policyVersion": "default", "id": "XX125", "attr": {"owner": "bugs_bunny", "public": false, "flagged": false}}}], "auxData": {"jwt": {"token": "eyJhbGciOiJFUzM4NCIsImtpZCI6IjE5TGZaYXRFZGc4M1lOYzVyMjNndU1KcXJuND0iLCJ0eXAiOiJKV1QifQ.eyJhdWQiOlsiY2VyYm9zLWp3dC10ZXN0cyJdLCJjdXN0b21BcnJheSI6WyJBIiwiQiIsIkMiXSwiY3VzdG9tSW50Ijo0MiwiY3VzdG9tTWFwIjp7IkEiOiJBQSIsIkIiOiJCQiIsIkMiOiJDQyJ9LCJjdXN0b21TdHJpbmciOiJmb29iYXIiLCJleHAiOjE5NDk5MzQwMzksImlzcyI6ImNlcmJvcy10ZXN0LXN1aXRlIn0.WN_tOScSpd_EI-P5EI1YlagxEgExSfBjAtcrgcF6lyWj1lGpR_GKx9goZEp2p_t5AVWXN_bjz_sMUmJdJa4cVd55Qm1miR-FKu6oNRHnSEWdMFmnArwPw-YDJWfylLFX", "keySetId": "my-keyset"}}}

Response samples

Content type

application/json

Copy Expand all Collapse all

{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b", "results": [{"resourceId": "XX125", "actions": {"view": "EFFECT_ALLOW"}}]}

tag/CerbosService/operation/CerbosService_PlanResources Plan resources

Produce a query plan with conditions that must be satisfied for accessing a set of instances of a resource.

Request Body schema: application/json required

PDP Resources Query Plan Request

requestId string
Optional application-specific ID useful for correlating logs for analysis.
action string
Action to be applied to each resource in the list.
actions Array of strings unique
List of actions to generate the query plan for. Mutually exclusive with the singular action field. Must contain at least one action and all actions must be unique.
principal
required
object (enginev1Principal)
A person or application attempting to perform the actions on the set of resources.
resource
required
object (v1PlanResourcesInputResource)
auxData object (cerbosrequestv1AuxData)
Structured auxiliary data useful for evaluating the request
includeMeta boolean
Opt to receive request processing metadata in the response.

Responses

200

A successful response.

default

An unexpected error response.

post/api/plan/resources

https://docs.cerbos.dev/api/plan/resources

Request samples

Content type

application/json

Copy Expand all Collapse all

{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b", "action": "view:public", "actions": ["view:public", "edit:profile"], "principal": {"id": "bugs_bunny", "policyVersion": "default", "roles": ["user"], "attr": {"beta_tester": true}, "scope": "acme.corp"}, "resource": {"kind": "album:object", "attr": {"property1": null, "property2": null}, "policyVersion": "default", "scope": "^(a]w\-]*(\.w\-]*)*)*$"}, "auxData": {"jwt": {"token": "eyJhbGciOiJFUzM4NCIsImtpZCI6IjE5TGZaYXRFZGc4M1lOYzVyMjNndU1KcXJuND0iLCJ0eXAiOiJKV1QifQ.eyJhdWQiOlsiY2VyYm9zLWp3dC10ZXN0cyJdLCJjdXN0b21BcnJheSI6WyJBIiwiQiIsIkMiXSwiY3VzdG9tSW50Ijo0MiwiY3VzdG9tTWFwIjp7IkEiOiJBQSIsIkIiOiJCQiIsIkMiOiJDQyJ9LCJjdXN0b21TdHJpbmciOiJmb29iYXIiLCJleHAiOjE5NDk5MzQwMzksImlzcyI6ImNlcmJvcy10ZXN0LXN1aXRlIn0.WN_tOScSpd_EI-P5EI1YlagxEgExSfBjAtcrgcF6lyWj1lGpR_GKx9goZEp2p_t5AVWXN_bjz_sMUmJdJa4cVd55Qm1miR-FKu6oNRHnSEWdMFmnArwPw-YDJWfylLFX", "keySetId": "my-keyset"}}}

Response samples

Content type

application/json

Copy Expand all Collapse all

`{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b", "action": "string", "actions": ["view:public", "edit:profile"], "resourceKind": "album:object", "policyVersion": "default", "filter": {"kind": "KIND_UNSPECIFIED", "condition": {"value": null, "expression": {"operator": "string", "operands": [{ }]},