Cerbos
- CerbosService
- postCheck
- postCheck resources
- postCheck resource batch
- postPlan resources
- getGet server information
- CerbosAdminService
- getList audit log entries
- getList policies
- getInspect policies
- getGet policy
- delDisable policy
- postAdd or update policies
- putAdd or update policies
- postDisable policy
- putDisable policy
- postEnable policy
- putEnable policy
- getGet schema
- delDelete schema
- postAdd or update schema
- putAdd or update schema
- getList schemas
- getReload store
Cerbos (latest)
CerbosService
Cerbos Policy Decision Point
Check Deprecated
[Deprecated: Use CheckResources API instead] Check whether a principal has permissions to perform the given actions on a set of resource instances.
Request Body schema: application/json required
| requestId | string Optional application-specific ID useful for correlating logs for analysis. |
| actions required |
Array of strings non-empty unique List of actions being performed on the set of resources. |
| principal required |
object (enginev1Principal) A person or application attempting to perform the actions on the set of resources. |
| resource required |
object (v1ResourceSet) Set of resources to check |
| includeMeta | boolean Opt to receive request processing metadata in the response. |
| auxData | object (cerbosrequestv1AuxData) Structured auxiliary data useful for evaluating the request |
Responses
200
A successful response.
default
An unexpected error response.
Request samples
- Payload
Content type
application/json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",
"actions": ["view:public",
"comment"
],
"principal": {"id": "bugs_bunny",
"policyVersion": "default",
"roles": ["user"
],
"attr": {"beta_tester": true
},
"scope": "acme.corp"
},
"resource": {"kind": "album:object",
"policyVersion": "default",
"instances": {"XX125": {"attr": {"owner": "bugs_bunny",
"public": false,
"flagged": false
}
},
"XX225": {"attr": {"owner": "daffy_duck",
"public": true,
"flagged": false
}
}
},
"scope": "^(^$|\.|0(\.\w)*)$"
},
"includeMeta": true,
"auxData": {"jwt": {"token": "eyJhbGciOiJFUzM4NCIsImtpZCI6IjE5TGZaYXRFZGc4M1lOYzVyMjNndU1KcXJuND0iLCJ0eXAiOiJKV1QifQ.eyJhdWQiOlsiY2VyYm9zLWp3dC10ZXN0cyJdLCJjdXN0b21BcnJheSI6WyJBIiwiQiIsIkMiXSwiY3VzdG9tSW50Ijo0MiwiY3VzdG9tTWFwIjp7IkEiOiJBQSIsIkIiOiJCQiIsIkMiOiJDQyJ9LCJjdXN0b21TdHJpbmciOiJmb29iYXIiLCJleHAiOjE5NDk5MzQwMzksImlzcyI6ImNlcmJvcy10ZXN0LXN1aXRlIn0.WN_tOScSpd_EI-P5EI1YlagxEgExSfBjAtcrgcF6lyWj1lGpR_GKx9goZEp2p_t5AVWXN_bjz_sMUmJdJa4cVd55Qm1miR-FKu6oNRHnSEWdMFmnArwPw-YDJWfylLFX",
"keySetId": "my-keyset"
}
}
}`
### Response samples
- 200
- default
Content type
application/json
```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",
"resourceInstances": {"XX125": {"actions": {"view:*": "EFFECT_ALLOW",
"comment": "EFFECT_ALLOW"
},
},
"XX225": {"actions": {"view:*": "EFFECT_DENY",
"comment": "EFFECT_DENY"
},
}
},
"meta": {"resourceInstances": {"XX125": {"actions": {"view:*": {"matched_policy": "album:object:default"
},
"comment": {"matched_policy": "album:object:default"
}
},
"effective_derived_roles": ["owner"
]
},
"XX225": {"actions": {"view:*": {"matched_policy": "album:object:default"
},
"comment": {"matched_policy": "album:object:default"
}
}
}
}
}
}`
### Check resources
Check a principal's permissions to a batch of heterogeneous resources and actions.
##### Request Body schema: application/json required
| | |
| --- | --- |
| requestId | string<br>Optional application-specific ID useful for correlating logs for analysis. |
| includeMeta | boolean<br>Add request processing metadata to the response. |
| principal<br>required | object (enginev1Principal) <br>A person or application attempting to perform the actions on the set of resources. |
| resources<br>required | Array of objects (CheckResourcesRequestResourceEntry) non-empty unique <br>List of resources and actions. |
| auxData | object (cerbosrequestv1AuxData) <br>Structured auxiliary data useful for evaluating the request |
### Responses
**200**
A successful response.
**default**
An unexpected error response.
### Request samples
- Payload
Content type
application/json
```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",
"includeMeta": true,
"principal": {"id": "bugs_bunny",
"policyVersion": "default",
"roles": ["user"
],
"attr": {"beta_tester": true
},
"scope": "acme.corp"
},
"resources": [{"actions": ["view",
"comment"
],
"resource": {"kind": "album:object",
"policyVersion": "default",
"id": "XX125",
"attr": {"owner": "bugs_bunny",
"public": false,
"flagged": false
}
}
}],
"keySetId": "my-keyset"
}
}
}`
### Response samples
- 200
- default
Content type
application/json
```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",
"results": [{"resource": {"Id": "XX125",
"kind": "album:object"
},
"actions": {"view": "EFFECT_ALLOW",
"comment": "EFFECT_DENY"
}
}],
"cerbosCallId": "string"
}`
### Check resource batch Deprecated
[Deprecated: Use CheckResources API instead] Check a principal's permissions to a batch of heterogeneous resources and actions.
##### Request Body schema: application/json required
| | |
| --- | --- |
| requestId | string<br>Optional application-specific ID useful for correlating logs for analysis. |
| principal<br>required | object (enginev1Principal) <br>A person or application attempting to perform the actions on the set of resources. |
| resources<br>required | Array of objects (CheckResourceBatchRequestBatchEntry) non-empty unique <br>List of resources and actions. |
| auxData | object (cerbosrequestv1AuxData) <br>Structured auxiliary data useful for evaluating the request |
### Responses
**200**
A successful response.
**default**
An unexpected error response.
### Request samples
- Payload
Content type
application/json
```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",
"principal": {"id": "bugs_bunny",
"policyVersion": "default",
"roles": ["user"
],
"attr": {"beta_tester": true
},
"scope": "acme.corp"
},
"resources": [{"actions": ["view",
"comment"
],
"resource": {"kind": "album:object",
"policyVersion": "default",
"id": "XX125",
"attr": {"owner": "bugs_bunny",
"public": false,
"flagged": false
}
}
}],
"keySetId": "my-keyset"
}
}
}`
### Response samples
- 200
- default
Content type
application/json
```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",
"results": [{"resourceId": "XX125",
"actions": {"view": "EFFECT_ALLOW"
}
}],
"cerbosCallId": "string"
}`
### Plan resources
Produce a query plan with conditions that must be satisfied for accessing a set of instances of a resource.
##### Request Body schema: application/json required
| | |
| --- | --- |
| requestId | string<br>Optional application-specific ID useful for correlating logs for analysis. |
| action | string<br>Action to be applied to each resource in the list. |
| actions | Array of strings unique <br>List of actions to generate the query plan for. Mutually exclusive with the singular action field. Must contain at least one action and all actions must be unique. |
| principal<br>required | object (enginev1Principal) <br>A person or application attempting to perform the actions on the set of resources. |
| resource<br>required | object (v1PlanResourcesInputResource) |
| auxData | object (cerbosrequestv1AuxData) <br>Structured auxiliary data useful for evaluating the request |
| includeMeta | boolean<br>Opt to receive request processing metadata in the response. |
### Responses
**200**
A successful response.
**default**
An unexpected error response.
### Request samples
- Payload
Content type
application/json
```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",
"action": "view:public",
"actions": ["view:public",
"edit:profile"
],
"principal": {"id": "bugs_bunny",
"policyVersion": "default",
"roles": ["user"
],
"attr": {"beta_tester": true
},
"scope": "acme.corp"
},
"resource": {"kind": "album:object",
"attr": {"property1": null,
"property2": null
},
"policyVersion": "default",
"scope": "^(^$|\.|0(\.\w)*)$"
},
"keySetId": "my-keyset"
}
},
"includeMeta": true
}
}`
### Response samples
- 200
- default
Content type
application/json
```json
{"requestId": "c2db17b8-4f9f-4fb1-acfd-9162a02be42b",
"action": "string",
"actions": ["view:public",
"edit:profile"
],
"resourceKind": "album:object",
"policyVersion": "default",
"filter": {"kind": "KIND_UNSPECIFIED",
"condition": {"value": null,
"expression": {"operator": "string",
"operands": [{}]
},
"variable": "string"
}
},
"meta": {"filterDebug": "string",
"matchedScope": "string",
"matchedScopes": {"property1": "string",
"property2": "string"
}
},
"validationErrors": [{"path": "string",
"message": "string",
"source": "SOURCE_UNSPECIFIED"
}],
"cerbosCallId": "string"
}`
### Get server information
Get information about the server e.g. server version
### Responses
**200**
A successful response.
**default**
An unexpected error response.
### Response samples
- 200
- default
Content type
application/json
```json
{"version": "string",
"commit": "string",
"buildDate": "string"
}`
### CerbosAdminService
Cerbos administration service
### List audit log entries
##### Authorizations:
_BasicAuth_
##### path Parameters
| | |
| --- | --- |
| kind<br>required | string<br>Enum:"KIND_UNSPECIFIED"KIND_ACCESS"KIND_DECISION"<br>Kind of log entry |
##### query Parameters
| | |
| --- | --- |
| tail | integer <int64> <br>Last N entries. |
| between.start<br>required | string <date-time> <br>Start date in ISO 8601 format. |
| between.end<br>required | string <date-time> <br>End date in ISO 8601 format. |
| since | string<br>Entries since N hours/minutes ago |
| lookup | string^[0123456789ABCDEFGHJKMNPQRSTVWXYZ]{26}$<br>By Call ID |
### Responses
**200**
A successful response.(streaming responses)
**default**
An unexpected error response.
### Response samples
- 200
- default
Content type
application/json
```json
{"result": {"accessLogEntry": {"callId": "string",
"timestamp": "2019-08-24T14:15:22Z",
"peer": {"address": "string",
"authInfo": "string",
"userAgent": "string",
"forwardedFor": "string"
},
"metadata": {"property1": {"values": ["string"]
},
"property2": {"values": ["string"]
}
},
"method": "string",
"statusCode": 0,
"oversized": true,
"policySource": {"blob": {"bucketUrl": "string",
"prefix": "string"
},
"database": {"driver": "DRIVER_UNSPECIFIED"
},
"disk": {"directory": "string"
},
"git": {"repositoryUrl": "string",
"branch": "string",
"subdirectory": "string"
},
"hub": {"label": "string",
"deploymentId": "string",
"playgroundId": "string",
"localBundle": {"path": "string"
},
"embeddedBundle": {"ruleId": "string",
"scopes": ["string"]
}
},
"embeddedPdp": {"url": "string",
"commitHash": "string",
"builtAt": "2019-08-24T14:15:22Z"
}
}
},
"decisionLogEntry": {"callId": "string",
"timestamp": "2019-08-24T14:15:22Z",
"peer": {"address": "string",
"authInfo": "string",
"userAgent": "string",
"forwardedFor": "string"
},
"inputs": [{"requestId": "string",
"resource": {"kind": "album:photo",
"policyVersion": "default",
"id": "XX125",
"attr": {"owner": "bugs_bunny"
},
"scope": "acme.corp"
},
"principal": {"id": "bugs_bunny",
"policyVersion": "default",
"roles": ["user"
],
"attr": {"beta_tester": true
},
"scope": "acme.corp"
},
"actions": ["string"],
"auxData": {"jwt": {"property1": null,
"property2": null
}
}
}],
"outputs": [{"requestId": "string",
"resourceId": "string",
"actions": {"property1": {"effect": "EFFECT_UNSPECIFIED",
"policy": "string",
"scope": "string"
},
"property2": {"effect": "EFFECT_UNSPECIFIED",
"policy": "string",
"scope": "string"
}
},
"effectiveDerivedRoles": ["string"],
"validationErrors": [{"path": "string",
"message": "string",
"source": "SOURCE_UNSPECIFIED"
}],
"outputs": [{"src": "resource.expense.v1/acme#rule-001",
"val": "some_string"}]
}],
"error": "string",
"checkResources": {"inputs": [{"requestId": "string",
"resource": {"kind": "album:photo",
"policyVersion": "default",
"id": "XX125",
"attr": {"owner": "bugs_bunny"},
"scope": "acme.corp"},
"principal": {"id": "bugs_bunny",
"policyVersion": "default",
"roles": ["user"],
"attr": {"beta_tester": true},
"scope": "acme.corp"},
"actions": ["string"],
"auxData": {"jwt": {"property1": null,"property2": null}}}],
"outputs": [{"requestId": "string",
"resourceId": "string",
"actions": {"property1": {"effect": "EFFECT_UNSPECIFIED",
"policy": "string",
"scope": "string"},
"property2": {"effect": "EFFECT_UNSPECIFIED",
"policy": "string",
"scope": "string"}},
"effectiveDerivedRoles": ["string"],
"validationErrors": [{"path": "string",
"message": "string",
"source": "SOURCE_UNSPECIFIED"}],
"outputs": [{"src": "resource.expense.v1/acme#rule-001","val": "some_string"}]}},
"error": {"code": 0,
"message": "string",
"details": [{"@type": "string","property1": null,"property2": null}]}
}
}