{resource}.{id}.{action}: one of the nine resource types below, a resource ID or * for all of them, and an action from the tables. Root key permissions explains how to choose permissions and read a permission error.
The tables are grouped by product. The Scoped column says whether the dashboard lets you limit the action to one resource ID. Actions that aren’t scoped are always granted with *.
API Management
api (keyspaces and their keys)
The api resource is a keyspace, identified by its api_ ID. Key actions are granted on the keyspace the keys belong to.
ratelimit (namespaces and overrides)
The ratelimit resource is a namespace. The dashboard grants these with * only.
No API endpoint uses
read_namespace, update_namespace, or delete_namespace. The first ratelimit.limit call with a new name creates the namespace, and you manage namespaces in the dashboard.
rbac (permissions and roles for your keys)
These govern the permissions and roles you define for your own users’ keys, not root key permissions. All are granted with *.
identity
All granted with *.
portal (developer portals)
Creating an end-user session is separate from managing portals, so a key can create sessions for your users without being able to change the portal. All granted with *.
Compute
project
The project resource is identified by its proj_ ID. Some deployment actions can be granted on the whole project, so a CI key doesn’t need to know environment IDs.
app
The app resource is identified by its app_ ID.
environment
The environment resource is identified by its env_ ID. Deployment, domain, and gateway policy actions are granted here because those belong to an .
Platform
workspace
Actions for the whole workspace. A root key belongs to one workspace, so the id is always *.
Examples
api.*.verify_keyverifies keys in every keyspace.api.api_1234abcd.verify_keyverifies keys in one keyspace.environment.env_1234abcd.promote_deploymentpromotes deployments in one environment.project.proj_1234abcd.create_deploymentcreates deployments in any environment of that project.