security
Intended Documentation
Roles and Token Governance
Role matrix and API credential lifecycle for tenant admin operations.
Roles and Token Governance#
Use enterprise admin endpoints for role visibility and API credential operations.
Role Matrix#
GET /admin/roles?tenantId=<tenant>
Returns actor role/permissions and available role matrix for the tenant.
List API Credentials#
GET /admin/api-tokens?tenantId=<tenant>
Create API Credential#
POST /admin/api-tokens
Request body schema:
tenantId(required)name(required)environmentKey(required)scopes(required array)expiresAt(optional ISO datetime)ipAllowlist(optional)
Revoke API Credential#
POST /admin/api-tokens/:id/revoke
Body:
tenantId(required)reason(optional)
Governance Notes#
- Credential events are included in
GET /admin/api-tokensresponse. - Credential creation returns secret once; persist in a secure secret manager.
- Role/token changes are audit-tracked and exportable.