Skip to main content

Endpoint

Authentication

Requires a Personal API Access Token.

Request

Headers

Path Parameters

Request Body

Full JSON Body Example - Grant Access to Single API Proxy

Full JSON Body Example - Grant Access to Multiple Resources

Full JSON Body Example - Grant Access with Expiration

Request Body Fields

The request body is an object containing an array of access objects.

Access Object

EnumAccessType

  • API_PROXY - Grant access to a specific API Proxy
  • API_PROXY_GROUP - Grant access to an API Proxy Group

Request Body Object

Notes

  • Request body must be an object with credentialAccessList array (even for single access)
  • Each access object must have name and type
  • name must match an existing API Proxy or API Proxy Group
  • type must be either API_PROXY or API_PROXY_GROUP
  • expireTime is optional. If provided, access expires at the specified time. Use ISO 8601 format (UTC)
  • Cannot grant access that already exists
  • Access is automatically deployed to all environments

Response

Success Response (200 OK)

Error Response (400 Bad Request)

or
or
or

Common Causes

  • Empty access object
  • Missing name or type field
  • API Proxy or API Proxy Group does not exist
  • Access already granted
  • Invalid access type

Error Response (401 Unauthorized)

Error Response (404 Not Found)

cURL Example

Example 1: Grant Access to Single API Proxy

Example 2: Grant Access to Multiple Resources

Example 3: Grant Access with Expiration

Notes and Warnings

  • Request Body Format:
    • Request body must be an object with credentialAccessList array
    • Even for single access, use object format with array inside
  • Access Validation:
    • API Proxy or API Proxy Group must exist
    • Must be within the project scope
  • Duplicate Access:
    • Cannot grant access that already exists
    • Check existing access before granting
  • Automatic Deployment:
    • Access is automatically deployed to all environments
    • Deployment results are returned in the response
  • API Proxy Group:
    • Granting access to API Proxy Group grants access to all APIs in the group
    • More efficient than granting access to individual APIs
  • Expiration Time:
    • expireTime is optional and can be set per access entry
    • Use ISO 8601 format (UTC): “YYYY-MM-DDTHH:mm:ss.sssZ”
    • If not provided or null, access does not expire
    • Expired access is automatically revoked
    • Each access entry can have its own expiration time

Permissions

  • User must have IDENTITY + MANAGE permission in the project
  • For automatic deployment, user must also have IDENTITY + DEPLOY_UNDEPLOY permission