Cerbos

Cerbos (latest)

Download OpenAPI specification: Download

Cerbos: info@cerbos.devURL: https://cerbos.dev

CerbosService

Cerbos Policy Decision Point

Check Deprecated

[Deprecated: Use CheckResources API instead] Check whether a principal has permissions to perform the given actions on a set of resource instances.

Request Body schema: application/json required

requestId string
Optional application-specific ID useful for correlating logs for analysis.
actions
required
Array of strings non-empty unique
List of actions being performed on the set of resources.
principal
required
object (enginev1Principal)
A person or application attempting to perform the actions on the set of resources.
resource
required
object (v1ResourceSet)
Set of resources to check
includeMeta boolean
Opt to receive request processing metadata in the response.
auxData object (cerbosrequestv1AuxData)
Structured auxiliary data useful for evaluating the request

Responses

200

A successful response.

default

An unexpected error response.

Request samples

Content type

application/json

{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",

"actions": ["view:public",

"comment"

],

"principal": {"id": "bugs_bunny",

"policyVersion": "default",

"roles": ["user"

],

"attr": {"beta_tester": true

},

"scope": "acme.corp"

},

"resource": {"kind": "album:object",

"policyVersion": "default",

"instances": {"XX125": {"attr": {"owner": "bugs_bunny",

"public": false,

"flagged": false

}

},

"XX225": {"attr": {"owner": "daffy_duck",

"public": true,

"flagged": false

}

}

},

"scope": "^(0(\.)*)*$"

},

"includeMeta": true,

"auxData": {"jwt": {"token": "eyJhbGciOiJFUzM4NCIsImtpZCI6IjE5TGZaYXRFZGc4M1lOYzVyMjNndU1KcXJuND0iLCJ0eXAiOiJKV1QifQ.eyJhdWQiOlsiY2VyYm9zLWp3dC10ZXN0cyJdLCJjdXN0b21BcnJheSI6WyJBIiwiQiIsIkMiXSwiY3VzdG9tSW50Ijo0MiwiY3VzdG9tTWFwIjp7IkEiOiJBQSIsIkIiOiJCQiIsIkMiOiJDQyJ9LCJjdXN0b21TdHJpbmciOiJmb29iYXIiLCJleHAiOjE5NDk5MzQwMzksImlzcyI6ImNlcmJvcy10ZXN0LXN1aXRlIn0.WN_tOScSpd_EI-P5EI1YlagxEgExSfBjAtcrgcF6lyWj1lGpR_GKx9goZEp2p_t5AVWXN_bjz_sMUmJdJa4cVd55Qm1miR-FKu6oNRHnSEWdMFmnArwPw-YDJWfylLFX",

"keySetId": "my-keyset"

}

}

Response samples

Check resources

Check a principal's permissions to a batch of heterogeneous resources and actions.

Request Body schema: application/json required

requestId string
Optional application-specific ID useful for correlating logs for analysis.
includeMeta boolean
Add request processing metadata to the response.
principal
required
object (enginev1Principal)
A person or application attempting to perform the actions on the set of resources.
resources
required
Array of objects (CheckResourcesRequestResourceEntry) non-empty unique
List of resources and actions.
auxData object (cerbosrequestv1AuxData)
Structured auxiliary data useful for evaluating the request

Responses

200

A successful response.

default

An unexpected error response.

Request samples

Content type

application/json

{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",

"includeMeta": true,

"principal": {"id": "bugs_bunny",

"policyVersion": "default",

"roles": ["user"

],

"attr": {"beta_tester": true

},

"scope": "acme.corp"

},

"resources": [{"actions": ["view",

"comment"

],

"resource": {"kind": "album:object",

"policyVersion": "default",

"id": "XX125",

"attr": {"owner": "bugs_bunny",

"public": false,

"flagged": false

}}}],

"keySetId": "my-keyset"

}

}

Response samples

CerbosAdminService

Cerbos administration service

List audit log entries

BasicAuth

path Parameters

kind
required
string
Enum:"KIND_UNSPECIFIED" "KIND_ACCESS" "KIND_DECISION"
Kind of log entry

query Parameters

tail integer
Last N entries.
between.start
required
string
Start date in ISO 8601 format.
between.end
required
string
End date in ISO 8601 format.
since string
Entries since N hours/minutes ago
lookup string^[0123456789ABCDEFGHJKMNPQRSTVWXYZ]{26}$
By Call ID

Responses

200

A successful response.(streaming responses)

default

An unexpected error response.

Request samples

List policies

BasicAuth

query Parameters

includeDisabled boolean
Include disabled policies
nameRegexp string
Filter policies by name with regexp
scopeRegexp string
Filter policies by scope with regexp
versionRegexp string
Filter policies by version with regexp
policyId Array of strings
For blob, disk, git stores use file name (.yaml). For mysql, postgres, sqlite3 use id (..) of the policy

Responses

200

A successful response.

default

An unexpected error response.

Inspect policies

BasicAuth

query Parameters

Responses

200

A successful response.

default

An unexpected error response.

Get policy

BasicAuth

query Parameters

id
required
Array of strings
For blob, disk, git stores use file name (.yaml). For mysql, postgres, sqlite3 use id (..) of the policy

Responses

200

A successful response.

default

An unexpected error response.

Disable policy

BasicAuth

query Parameters

id
required
Array of strings
Unique identifier for the policy

Responses

200

A successful response.

default

An unexpected error response.

Add or update policies

BasicAuth

Request Body schema: application/json required

policies
required
Array of objects (v1Policy) [ 1 .. 100 ] items
List of policies.

Responses

200

A successful response.

default

An unexpected error response.

Get schema

BasicAuth

query Parameters

id
required
Array of strings
Unique identifier for the schema

Responses

200

A successful response.

default

An unexpected error response.

Reload store

BasicAuth

query Parameters

wait boolean
Wait until the reloading process finishes

Responses

200

A successful response.

default

An unexpected error response.