# CESNET Authz Resolver API

**Canonical:** https://apis.io/apis/cesnet/cesnet-authzresolver-api/  
**Provider:** CESNET — https://apis.io/providers/cesnet/  
**Base URL:** https://api-dev.perun-aai.org/ba/rpc  
**Documentation:** https://perun-aai.org/documentation/

CESNET Authz Resolver API is one of 27 APIs that [CESNET](https://apis.io/providers/cesnet/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. This API exposes 6 JSON Schema definitions. Tagged areas include AuthzResolver. The published artifact set on APIs.io includes an OpenAPI specification, a GitHub repository, and 6 JSON Schemas.

AuthzResolver RPC API in Perun

## Operations (44)

| Method | Path | Summary |
|---|---|---|
| GET | `/json/authzResolver/getPrincipalRoleNames` | Returns list of caller's role names. |
| GET | `/json/authzResolver/getPerunPrincipal` | Gets current user |
| GET | `/json/authzResolver/getRichAdmins` | Gets all valid rich admins |
| GET | `/json/authzResolver/getAdmins` | Gets all valid admins |
| GET | `/json/authzResolver/someAdminExists` | Checks if some valid admin exists |
| GET | `/json/authzResolver/getAdminGroups` | Get all groups of managers (authorizedGroups) for complementaryObject and role |
| POST | `/json/authzResolver/setRole/u` | Set role for user |
| POST | `/json/authzResolver/unsetRole/u` | Unset role for user |
| POST | `/json/authzResolver/setRole/u-co` | Set role for user and complementaryObject |
| POST | `/json/authzResolver/setRole/u-cos` | Set role for user and complementaryObjects |
| POST | `/json/authzResolver/unsetRole/u-co` | Unset role for user and complementaryObject |
| POST | `/json/authzResolver/unsetRole/u-cos` | Unset role for user and complementaryObjects |
| POST | `/json/authzResolver/setRole/g` | Set role for authorizedGroup |
| POST | `/json/authzResolver/unsetRole/g` | Unset role for authorizedGroup |
| POST | `/json/authzResolver/setRole/g-co` | Set role for authorizedGroup and complementaryObject |
| POST | `/json/authzResolver/setRole/g-cos` | Set role for authorizedGroup and complementaryObjects |
| POST | `/json/authzResolver/unsetRole/g-co` | Unset role for authorizedGroup and complementaryObject |
| POST | `/json/authzResolver/unsetRole/g-cos` | Unset role for authorizedGroup and complementaryObjects |
| GET | `/json/authzResolver/getUserRoles` | Returns all roles accessible to the principal as an AuthzRoles object for a… |
| GET | `/json/authzResolver/getRegistrarUserRoles` | Returns all new Registrar roles for the user derived from roles in Perun |
| GET | `/json/authzResolver/getUserDirectRoles` | Returns all roles accessible to the principal except for those obtained from… |
| GET | `/json/authzResolver/getUserRolesObtainedFromAuthorizedGroupMemberships` | Returns roles resulting from membership in authorized groups as an AuthzRoles… |
| GET | `/json/authzResolver/getRoleComplementaryObjectsWithAuthorizedGroups` | Returns map of role names with map of corresponding complementary objects… |
| GET | `/json/authzResolver/getUserRoleNames` | Returns list of user's role names. |
| GET | `/json/authzResolver/getGroupRoleNames` | Returns list of group's role names. |
| GET | `/urlinjsonout/authzResolver/getGroupRoles` | Returns all roles as an AuthzRoles object for a given group |
| GET | `/urlinjsonout/authzResolver/isVoAdmin` | Returns 1 if User has VO manager role (VOADMIN) or for specific VO defined by id |
| GET | `/urlinjsonout/authzResolver/isGroupAdmin` | Returns 1 if User has Group manager role (GROUPADMIN) or for specific Group… |
| GET | `/urlinjsonout/authzResolver/isFacilityAdmin` | Returns 1 if User has Facility manager role (FACILITYADMIN) or for specific… |
| GET | `/json/authzResolver/isPerunAdmin` | Returns 1 if User has Perun admin role (perunadmin) |
| GET | `/json/authzResolver/isGroupLastAdminInFacilities` | Checks whether groups is the last admin the facilities and returns those in… |
| GET | `/json/authzResolver/isGroupLastAdminInVos` | Checks whether groups is the last admin the vos and returns those in which it is |
| GET | `/json/authzResolver/isUserLastAdminInFacilities` | Checks whether user is the last admin the facilities and returns those in which… |
| GET | `/json/authzResolver/isUserLastAdminInVos` | Checks whether user is the last admin the vos and returns those in which it is |
| GET | `/json/authzResolver/getLoggedUser` | Returns User which is associated with credentials used to log-in to Perun |
| GET | `/json/authzResolver/keepAlive` | Returns "OK" string. Helper method for GUI check if connection is alive |
| GET | `/json/authzResolver/getAllPolicies` | Return all loaded perun policies |
| GET | `/json/authzResolver/getAllRolesManagementRules` | Return all loaded roles management rules |
| GET | `/json/authzResolver/loadAuthorizationComponents` | Load perun roles and policies from the configuration file perun-roles.yml. |
| GET | `/json/authzResolver/getVosWhereUserIsInRoles` | Get all Vos where the given user (principal if user not sent) has set one of… |
| GET | `/json/authzResolver/getFacilitiesWhereUserIsInRoles` | Get all Facilities where the given user (principal if user not sent) has set… |
| GET | `/json/authzResolver/getResourcesWhereUserIsInRoles` | Get all Resources where the given user (principal if user not sent) has set one… |
| GET | `/json/authzResolver/getGroupsWhereUserIsInRoles` | Get all Groups where the given user (principal if user not sent) has set one of… |
| GET | `/json/authzResolver/getMembersWhereUserIsInRoles` | Get all Members where the given user (principal if user not sent) has set one… |

## Machine-readable artifacts (9)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/cesnet/refs/heads/main/openapi/cesnet-authzresolver-api-openapi.yml
- **GitHubRepository** — https://github.com/CESNET/perun
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/cesnet/refs/heads/main/json-schema/cesnet-application-form-item-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/cesnet/refs/heads/main/json-schema/cesnet-perun-notif-template-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/cesnet/refs/heads/main/json-schema/cesnet-application-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/cesnet/refs/heads/main/json-schema/cesnet-registrar-application-input-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/cesnet/refs/heads/main/json-schema/cesnet-applications-page-query-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/cesnet/refs/heads/main/json-schema/cesnet-publication-schema.json
- **GitHubRepository** — https://github.com/CESNET/exafs

## Other CESNET APIs (12)

- [CESNET Attributes Manager API](https://apis.io/apis/cesnet/cesnet-attributesmanager-api/)
- [CESNET Audit Messages Manager API](https://apis.io/apis/cesnet/cesnet-auditmessagesmanager-api/)
- [CESNET Authorization API](https://apis.io/apis/cesnet/cesnet-authorization-api/)
- [CESNET Cabinet Manager API](https://apis.io/apis/cesnet/cesnet-cabinetmanager-api/)
- [CESNET Choices API](https://apis.io/apis/cesnet/cesnet-choices-api/)
- [CESNET Config Manager API](https://apis.io/apis/cesnet/cesnet-configmanager-api/)
- [CESNET Consents Manager API](https://apis.io/apis/cesnet/cesnet-consentsmanager-api/)
- [CESNET Database Manager API](https://apis.io/apis/cesnet/cesnet-databasemanager-api/)
- [CESNET Ext Sources Manager API](https://apis.io/apis/cesnet/cesnet-extsourcesmanager-api/)
- [CESNET Facilities Manager API](https://apis.io/apis/cesnet/cesnet-facilitiesmanager-api/)
- [CESNET Groups Manager API](https://apis.io/apis/cesnet/cesnet-groupsmanager-api/)
- [CESNET Integration Manager API](https://apis.io/apis/cesnet/cesnet-integrationmanager-api/)

## Tags

AuthzResolver

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/cesnet/cesnet-authzresolver-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/cesnet/.
