CESNET Authz Resolver API

AuthzResolver RPC API in Perun

Operations 44

GET /json/authzResolver/getPrincipalRoleNames Returns list of caller's role names. #
GET /json/authzResolver/getPerunPrincipal Gets current user #
GET /json/authzResolver/getRichAdmins Gets all valid rich admins #
GET /json/authzResolver/getAdmins Gets all valid admins #
GET /json/authzResolver/someAdminExists Checks if some valid admin exists #
GET /json/authzResolver/getAdminGroups Get all groups of managers (authorizedGroups) for complementaryObject and role #
POST /json/authzResolver/setRole/u Set role for user #
POST /json/authzResolver/unsetRole/u Unset role for user #
POST /json/authzResolver/setRole/u-co Set role for user and complementaryObject #
POST /json/authzResolver/setRole/u-cos Set role for user and complementaryObjects #
POST /json/authzResolver/unsetRole/u-co Unset role for user and complementaryObject #
POST /json/authzResolver/unsetRole/u-cos Unset role for user and complementaryObjects #
POST /json/authzResolver/setRole/g Set role for authorizedGroup #
POST /json/authzResolver/unsetRole/g Unset role for authorizedGroup #
POST /json/authzResolver/setRole/g-co Set role for authorizedGroup and complementaryObject #
POST /json/authzResolver/setRole/g-cos Set role for authorizedGroup and complementaryObjects #
POST /json/authzResolver/unsetRole/g-co Unset role for authorizedGroup and complementaryObject #
POST /json/authzResolver/unsetRole/g-cos Unset role for authorizedGroup and complementaryObjects #
GET /json/authzResolver/getUserRoles Returns all roles accessible to the principal as an AuthzRoles object for a… #
GET /json/authzResolver/getRegistrarUserRoles Returns all new Registrar roles for the user derived from roles in Perun #
GET /json/authzResolver/getUserDirectRoles Returns all roles accessible to the principal except for those obtained from… #
GET /json/authzResolver/getUserRolesObtainedFromAuthorizedGroupMemberships Returns roles resulting from membership in authorized groups as an AuthzRoles… #
GET /json/authzResolver/getRoleComplementaryObjectsWithAuthorizedGroups Returns map of role names with map of corresponding complementary objects… #
GET /json/authzResolver/getUserRoleNames Returns list of user's role names. #
GET /json/authzResolver/getGroupRoleNames Returns list of group's role names. #
GET /urlinjsonout/authzResolver/getGroupRoles Returns all roles as an AuthzRoles object for a given group #
GET /urlinjsonout/authzResolver/isVoAdmin Returns 1 if User has VO manager role (VOADMIN) or for specific VO defined by id #
GET /urlinjsonout/authzResolver/isGroupAdmin Returns 1 if User has Group manager role (GROUPADMIN) or for specific Group… #
GET /urlinjsonout/authzResolver/isFacilityAdmin Returns 1 if User has Facility manager role (FACILITYADMIN) or for specific… #
GET /json/authzResolver/isPerunAdmin Returns 1 if User has Perun admin role (perunadmin) #
GET /json/authzResolver/isGroupLastAdminInFacilities Checks whether groups is the last admin the facilities and returns those in… #
GET /json/authzResolver/isGroupLastAdminInVos Checks whether groups is the last admin the vos and returns those in which it is #
GET /json/authzResolver/isUserLastAdminInFacilities Checks whether user is the last admin the facilities and returns those in which… #
GET /json/authzResolver/isUserLastAdminInVos Checks whether user is the last admin the vos and returns those in which it is #
GET /json/authzResolver/getLoggedUser Returns User which is associated with credentials used to log-in to Perun #
GET /json/authzResolver/keepAlive Returns "OK" string. Helper method for GUI check if connection is alive #
GET /json/authzResolver/getAllPolicies Return all loaded perun policies #
GET /json/authzResolver/getAllRolesManagementRules Return all loaded roles management rules #
GET /json/authzResolver/loadAuthorizationComponents Load perun roles and policies from the configuration file perun-roles.yml. #
GET /json/authzResolver/getVosWhereUserIsInRoles Get all Vos where the given user (principal if user not sent) has set one of… #
GET /json/authzResolver/getFacilitiesWhereUserIsInRoles Get all Facilities where the given user (principal if user not sent) has set… #
GET /json/authzResolver/getResourcesWhereUserIsInRoles Get all Resources where the given user (principal if user not sent) has set one… #
GET /json/authzResolver/getGroupsWhereUserIsInRoles Get all Groups where the given user (principal if user not sent) has set one of… #
GET /json/authzResolver/getMembersWhereUserIsInRoles Get all Members where the given user (principal if user not sent) has set one… #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cesnet:cesnet-authzresolver-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cesnet-authzresolver-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Cesnet Authz Resolver API
  version: 0.0.0
  contact:
    url: https://perun-aai.org
    email: perun@cesnet.cz
  description: 'Operations tagged AuthzResolver across 2 of this provider''s published API definitions: cesnet-perun-rpc-openapi.yml, cesnet-perun-rpc-openapi.yml. Each path carries the servers of the definition it was published in.'
servers:
- url: https://{server}/{authentication}/rpc
  description: Perun RPC server
  variables:
    server:
      default: api-dev.perun-aai.org
      description: DNS name of a Perun server
    authentication:
      default: ba
      description: 'way of authentication:

        ba - HTTP Basic Auth

        krb - Kerberos

        non - no authentication

        cert - X509 client certificate

        oauth - OAuth 2.0 bearer access token

        fed - SAML federation

        '
      enum:
      - ba
      - krb
      - non
      - cert
      - oauth
      - fed
security:
- BasicAuth: []
- BearerAuth: []
tags:


# --- truncated at 32 KB (73 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cesnet/refs/heads/main/openapi/cesnet-authzresolver-api-openapi.yml