Benchling Policy API

Defines a named set of permissions that can be assigned to users or groups through collaborations. Policies contain PolicyStatements that specify allowed actions on different item types. When a user is granted a collaboration with a specific policy, they receive all permissions defined in that policy's statements. Common policies include viewer (read-only access), editor (read and write), and admin (full control). Policies are reusable and can be applied across many collaborations.

Operations 2

GET /policy/items List Policy items #
GET /policy/{policy_id} Get Policy by ID #

Documentation

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/benchling-policy-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

benchling-policy-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  license:
    name: Apache 2.0
    url: http://www.apache.org/licenses/LICENSE-2.0.html
  title: Benchling Policy API
  version: 2.0.0
  description: 'Defines a named set of permissions that can be assigned to users or groups through

    collaborations. Policies contain PolicyStatements that specify allowed actions on

    different item types. When a user is granted a collaboration with a specific policy,

    they receive all permissions defined in that policy''s statements. Common policies

    include viewer (read-only access), editor (read and write), and admin (full control).

    Policies are reusable and can be applied across many collaborations.'
servers:
- url: /api/v3
security:
- oAuth: []
- basicApiKeyAuth: []
tags:
- description: 'Defines a named set of permissions that can be assigned to users or groups through

    collaborations. Policies contain PolicyStatements that specify allowed actions on

    different item types. When a user is granted a collaboration with a specific policy,

    they receive all permissions defined in that policy''s statements. Common policies

    include viewer (read-only access), editor (read and write), and admin (full control).

    Policies are reusable and can be applied across many collaborations.'
  name: Policy
  x-bnch-organization: Benchling
paths:
  /policy/items:
    get:
      description: List Policy items.
      operationId: Policy.List
      parameters:
      - $ref: '#/components/parameters/createdAt.gt'
      - $ref: '#/components/parameters/createdAt.gte'
      - $ref: '#/components/parameters/createdAt.lt'
      - $ref: '#/components/parameters/createdAt.lte'
      - $ref: '#/components/parameters/id.anyOf'
      - $ref: '#/components/parameters/modifiedAt.gt'
      - $ref: '#/components/parameters/modifiedAt.gte'
      - $ref: '#/components/parameters/modifiedAt.lt'
      - $ref: '#/components/parameters/modifiedAt.lte'
      - $ref: '#/components/parameters/name.anyOf'
      - $ref: '#/components/parameters/name.anyOf.caseSensitive'
      - $ref: '#/components/parameters/nextToken'
      - $ref: '#/components/parameters/omit'
      - $ref: '#/components/parameters/pageSize'
      - $ref: '#/components/parameters/returning'
      - description: 'Method by which to order results. Valid sorts are: createdAt (created time, oldest first) and modifiedAt (modified time, oldest first). Use :asc or :desc to specify ascending or descending order. Default is modifiedAt:desc.'
        in: query
        name: sort
        schema:
          default: modifiedAt:desc
          enum:
          - createdAt:asc
          - createdAt:desc
          - modifiedAt:asc
          - modifiedAt:desc
          type: string
      - description: Set to true to access beta operations via /api/v3.
        in: header
        name: EARLY-ACCESS
        required: false
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyPaginatedList'
          description: OK
          headers: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/TooManyRequests'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: List Policy items
      tags:
      - Policy
      x-bnch-rate-limit-tier: 4
  /policy/{policy_id}:
    get:
      description: Get a single Policy by ID.
      operationId: Policy.Get
      parameters:
      - description: ID of the Policy.
        in: path
        name: policy_id
        required: true
        schema:
          type: string
      - $ref: '#/components/parameters/returning'
      - $ref: '#/components/parameters/omit'
      - description: Set to true to access beta operations via /api/v3.
        in: header
        name: EARLY-ACCESS
        required: false
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Policy'
          description: OK
          headers: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/TooManyRequests'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Get Policy by ID
      tags:
      - Policy
      x-bnch-rate-limit-tier: 5
components:
  parameters:
    pageSize:
      description: Number of results to return. Defaults to 50, maximum of 100.
      in: query
      name: pageSize
      schema:
        type: integer
    createdAt.gte:
      description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those created at or after the specified time. e.g. >= 2017-04-30.
      in: query
      name: createdAt.gte
      schema:
        format: datetime
        type: string
    modifiedAt.gt:
      description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those modified after the specified time. e.g. > 2017-04-30.
      in: query
      name: modifiedAt.gt
      schema:
        format: datetime
        type: string
    modifiedAt.lte:
      description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those modified at or before the specified time. e.g. <= 2017-04-30.
      in: query
      name: modifiedAt.lte
      schema:
        format: datetime
        type: string
    id.anyOf:
      description: Restricts results to those matching any of the specified IDs. Comma-separated list.
      explode: false
      in: query
      name: id.anyOf
      schema:
        items:
          type: string
        maxItems: 100
        type: array
    omit:
      description: Comma-separated list of top-level fields to omit from each returned item. Cannot overlap with returning.
      explode: false
      in: query
      name: omit
      schema:
        items:
          type: string
        type: array
    modifiedAt.lt:
      description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those modified before the specified time. e.g. < 2017-04-30.
      in: query
      name: modifiedAt.lt
      schema:
        format: datetime
        type: string
    createdAt.gt:
      description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those created after the specified time. e.g. > 2017-04-30.
      in: query
      name: createdAt.gt
      schema:
        format: datetime
        type: string
    createdAt.lt:
      description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those created before the specified time. e.g. < 2017-04-30.
      in: query
      name: createdAt.lt
      schema:
        format: datetime
        type: string
    returning:
      description: Comma-separated list of top-level fields to include in each returned item. Cannot overlap with omit.
      explode: false
      in: query
      name: returning
      schema:
        items:
          type: string
        type: array
    nextToken:
      description: Token for pagination
      in: query
      name: nextToken
      schema:
        type: string
    name.anyOf:
      description: Restricts results to those that match any of the specified names. Case insensitive. Warning - this filter can be non-performant due to case insensitivity. Ensure only one name filter is used at a time. Comma-separated list.
      explode: false
      in: query
      name: name.anyOf
      schema:
        items:
          type: string
        maxItems: 100
        type: array
    name.anyOf.caseSensitive:
      description: Restricts results to those that match any of the specified names. Case sensitive. Ensure only one name filter is used at a time. Comma-separated list.
      explode: false
      in: query
      name: name.anyOf.caseSensitive
      schema:
        items:
          type: string
        maxItems: 100
        type: array
    modifiedAt.gte:
      description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those modified at or after the specified time. e.g. >= 2017-04-30.
      in: query
      name: modifiedAt.gte
      schema:
        format: datetime
        type: string
    createdAt.lte:
      description: Datetime, in RFC 3339 format. Time zone defaults to UTC. Restricts results to those created at or before the specified time. e.g. <= 2017-04-30.
      in: query
      name: createdAt.lte
      schema:
        format: datetime
        type: string
  responses:
    NotFound:
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/GeneralError'
      description: Not Found
    TooManyRequests:
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/GeneralError'
      description: Too Many Requests
    BadRequest:
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/GeneralError'
      description: Bad Request
    Forbidden:
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/GeneralError'
      description: Forbidden
    InternalServerError:
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/InternalServerError'
      description: Internal Server Error
  schemas:
    PolicyStatement:
      description: 'A single permission rule within a Policy. Combines an ItemType (what kind of object),

        an Action (what operation), and a Condition (when it applies) to define a specific

        permission grant. Multiple PolicyStatements together form a complete Policy that

        determines what actions a user can perform.'
      properties:
        __typename:
          type: string
        action:
          enum:
          - READ
          - APPEND
          - WRITE
          - ADMIN
          - ARCHIVE
          - CHANGE_ASSIGNMENT_OF_OBJECTS
          - CHANGE_REGISTRY_IDENTIFIER
          - CREATE
          - CREATE_LOCATION
          - CREATE_REQUEST
          - CREATE_RESULT
          - CREATE_SUBFOLDER
          - CREATE_TEST_ORDERS
          - EDIT_BARCODES
          - EDIT_CHEMICAL_STRUCTURE
          - EDIT_CONTAINER
          - EDIT_FIELDS_IF_PENDING_INVALID
          - EDIT_FIELDS_IF_IN_PROGRESS
          - EDIT_FIELDS_IF_TERMINAL
          - EDIT_NAMES_AND_ALIASES
          - EDIT_NAMES_AND_BARCODES
          - EDIT_POLYMER_FEATURES
          - EDIT_RESIDUES
          - EDIT_RESTRICTED_SAMPLE_USERS
          - EDIT_RESULT
          - EDIT_SCHEMA_AND_FIELDS
          - EDIT_STATUS
          - EDIT_USER_EMAIL
          - EXECUTE_REQUEST
          - LIST_DEFINITION
          - MANAGE_COLLABORATORS
          - MANAGE_CAPABILITIES
          - READ_APP_CONFIG
          - READ_APP_SESSION
          - REGISTER
          - RETRACT_REVIEW
          - RESTRICT_SAMPLES
          - REVOKE_USER_CREDENTIALS
          - SUSPEND_USER
          - UNREGISTER
          - UNRESTRICT_SAMPLES
          - WRITE_APP_CONFIG
          - WRITE_APP_SESSION
          - UNKNOWN
          type: string
        condition:
          enum:
          - ALWAYS
          - IS_AUTHOR
          - IS_ASSIGNEE
          - UNKNOWN
          type: string
        itemType:
          enum:
          - AA_MONOMER
          - AGENT_SKILL
          - AI_MODEL
          - ANALYSIS
          - ANALYTICS_DASHBOARD
          - ANTIBODY_FORMAT
          - APP_DEFINITION
          - ASYNC_TASK
          - AV_SCAN_RECORD
          - BATCH
          - BENCHLING_APP
          - BENCHLING_APP_SESSION
          - BIOENTITY
          - BOX
          - BUSINESS_RULE
          - ASSEMBLY
          - CHAT_SESSION
          - CHEMICAL_COUNTERPART
          - CONFIG_MIGRATION_HISTORY
          - CONNECTION
          - CONTAINER
          - EVENT_SUBSCRIPTION
          - EXTENSION_DEFINITION
          - FOLDER_OR_PROJECT
          - FILE
          - INSTRUMENT
          - NON_LOCATION_STORABLE
          - LEGACY_DATA_IMPORT_RUN
          - LIBRARY_PARAMETER_DEFINITION
          - LOCATION
          - MCP_SERVER_INSTALLATION
          - MCP_SERVER_USER_CONFIG
          - MODEL_RUN
          - MONOMER
          - NOTEBOOK
          - ORGANIZATION
          - PLATE
          - PROCEDURE
          - PROCESS_TASK_GROUP
          - PROCESS_TASK
          - PROCESS_OUTPUT
          - PROTOCOL
          - REGISTRY
          - REVIEW_PROCESS
          - REQUEST
          - REQUEST_V2_DEFINITION
          - REQUEST_V2_SUBMISSION
          - RESULT
          - ROUTINE
          - SAMPLE_TYPE
          - SCHEMA
          - STUDY
          - TEAM
          - TEMPLATE_COLLECTION
          - TENANT
          - TEST_ORDER
          - USER
          - WAREHOUSE_LOGIN
          - WAREHOUSE_USER_DEFINED_VIEW
          - WORKFLOW
          - WORKLIST
          - WORKSHEET
          - OTHER
          - UNIT_TYPE
          - UNKNOWN
          type: string
      type: object
    InternalServerError:
      properties:
        detail:
          type:
          - 'null'
          - string
          - object
        errorId:
          type: string
        instance:
          type: string
        status:
          type: integer
        title:
          type:
          - 'null'
          - string
        type:
          type: string
      required:
      - type
      - title
      - detail
      - status
      - instance
      type: object
    Policy:
      description: 'Defines a named set of permissions that can be assigned to users or groups through

        collaborations. Policies contain PolicyStatements that specify allowed actions on

        different item types. When a user is granted a collaboration with a specific policy,

        they receive all permissions defined in that policy''s statements. Common policies

        include viewer (read-only access), editor (read and write), and admin (full control).

        Policies are reusable and can be applied across many collaborations.'
      properties:
        __typename:
          type: string
        createdAt:
          format: datetime
          type: string
        description:
          type:
          - 'null'
          - string
        id:
          type: string
        modifiedAt:
          format: datetime
          type: string
        name:
          type: string
        policyStatements:
          items:
            $ref: '#/components/schemas/PolicyStatement'
          type: array
        policyType:
          enum:
          - DATA_POLICY
          - SCHEMA_POLICY
          - POLICY
          type: string
      type: object
    PolicyPaginatedList:
      additionalProperties: false
      properties:
        items:
          items:
            $ref: '#/components/schemas/Policy'
          type: array
        nextToken:
          type: string
      type: object
    GeneralError:
      properties:
        detail:
          type:
          - 'null'
          - string
          - object
        instance:
          type: string
        status:
          type: integer
        title:
          type:
          - 'null'
          - string
        type:
          type: string
      required:
      - type
      - title
      - detail
      - status
      - instance
      type: object
  securitySchemes:
    basicApiKeyAuth:
      description: Use issued API key for standard access to the API
      scheme: basic
      type: http
    basicClientIdSecretAuth:
      description: Auth used as part of client credentials OAuth flow prior to receiving a bearer token.
      scheme: basic
      type: http
    oAuth:
      description: OAuth2 Client Credentials flow intended for service access
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /oauth/token
      type: oauth2