OpenMetadata Roles API
A `Role` is a collection of `Policies` that provides access control. A user or a team can be assigned one or multiple roles that provide privileges to a user and members of a team to perform the job function.
A `Role` is a collection of `Policies` that provides access control. A user or a team can be assigned one or multiple roles that provide privileges to a user and members of a team to perform the job function.
openapi: 3.0.1
info:
title: OpenMetadata APIs Agent Executions Roles API
description: Common types and API definition for OpenMetadata
contact:
name: OpenMetadata
url: https://open-metadata.org
email: openmetadata-dev@googlegroups.com
license:
name: Apache 2.0
url: https://www.apache.org/licenses/LICENSE-2.0
version: '1.13'
servers:
- url: /api
description: Current Host
- url: http://localhost:8585/api
description: Endpoint URL
security:
- BearerAuth: []
tags:
- name: Roles
description: A `Role` is a collection of `Policies` that provides access control. A user or a team can be assigned one or multiple roles that provide privileges to a user and members of a team to perform the job function.
paths:
/v1/roles:
get:
tags:
- Roles
summary: List roles
description: Get a list of roles. Use cursor-based pagination to limit the number of entries in the list using `limit` and `before` or `after` query params.
operationId: listRoles
parameters:
- name: default
in: query
description: List only default role(s)
schema:
type: boolean
example: true
- name: fields
in: query
description: Fields requested in the returned resource
schema:
type: string
example: policies,teams,users
- name: limit
in: query
description: Limit the number tables returned. (1 to 1000000, default = 10)
schema:
maximum: 1000000
minimum: 0
type: integer
format: int32
default: 10
- name: before
in: query
description: Returns list of tables before this cursor
schema:
type: string
- name: after
in: query
description: Returns list of tables after this cursor
schema:
type: string
- name: include
in: query
description: Include all, deleted, or non-deleted entities.
schema:
type: string
default: non-deleted
enum:
- all
- deleted
- non-deleted
responses:
'200':
description: List of roles
content:
application/json:
schema:
$ref: '#/components/schemas/RoleList'
put:
tags:
- Roles
summary: Update role
description: Create or Update a role.
operationId: createOrUpdateRole
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CreateRole'
responses:
'200':
description: 'The role '
content:
application/json:
schema:
$ref: '#/components/schemas/Role'
'400':
description: Bad request
post:
tags:
- Roles
summary: Create a role
description: Create a new role.
operationId: createRole
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CreateRole'
responses:
'200':
description: The role
content:
application/json:
schema:
$ref: '#/components/schemas/Role'
'400':
description: Bad request
/v1/roles/name/{name}:
get:
tags:
- Roles
summary: Get a role by name
description: Get a role by `name`.
operationId: getRoleByFQN
parameters:
- name: name
in: path
description: Name of the role
required: true
schema:
type: string
- name: fields
in: query
description: Fields requested in the returned resource
schema:
type: string
example: policies,teams,users
- name: include
in: query
description: Include all, deleted, or non-deleted entities.
schema:
type: string
default: non-deleted
enum:
- all
- deleted
- non-deleted
responses:
'200':
description: The role
content:
application/json:
schema:
$ref: '#/components/schemas/Role'
'404':
description: Role for instance {name} is not found
delete:
tags:
- Roles
summary: Delete a role
description: Delete a role by given `name`.
operationId: deleteRoleByName
parameters:
- name: hardDelete
in: query
description: Hard delete the entity. (Default = `false`)
schema:
type: boolean
default: false
- name: name
in: path
description: Name of the role
required: true
schema:
type: string
responses:
'200':
description: OK
'404':
description: Role for instance {name} is not found
/v1/roles/{id}:
get:
tags:
- Roles
summary: Get a role by id
description: Get a role by `id`.
operationId: getRoleByID
parameters:
- name: id
in: path
description: Id of the role
required: true
schema:
type: string
format: uuid
- name: fields
in: query
description: Fields requested in the returned resource
schema:
type: string
example: policies,teams,users
- name: include
in: query
description: Include all, deleted, or non-deleted entities.
schema:
type: string
default: non-deleted
enum:
- all
- deleted
- non-deleted
- name: includeRelations
in: query
description: 'Per-relation include control. Format: field:value,field2:value2. Example: owners:non-deleted,followers:all. Valid values: all, deleted, non-deleted. If not specified for a field, uses the entity''s include value.'
schema:
type: string
example: owners:non-deleted,followers:all
responses:
'200':
description: The role
content:
application/json:
schema:
$ref: '#/components/schemas/Role'
'404':
description: Role for instance {id} is not found
delete:
tags:
- Roles
summary: Delete a role
description: Delete a role by given `id`.
operationId: deleteRole
parameters:
- name: hardDelete
in: query
description: Hard delete the entity. (Default = `false`)
schema:
type: boolean
default: false
- name: id
in: path
description: Id of the role
required: true
schema:
type: string
format: uuid
responses:
'200':
description: OK
'404':
description: Role for instance {id} is not found
patch:
tags:
- Roles
summary: Update a role
description: Update an existing role with JsonPatch.
externalDocs:
description: JsonPatch RFC
url: https://tools.ietf.org/html/rfc6902
operationId: patchRole_1
parameters:
- name: id
in: path
description: Id of the role
required: true
schema:
type: string
format: uuid
requestBody:
description: JsonPatch with array of operations
content:
application/json-patch+json:
schema:
$ref: '#/components/schemas/JsonPatch'
example: '[{op:remove, path:/a},{op:add, path: /b, value: val}]'
responses:
default:
description: default response
content:
application/json: {}
/v1/roles/async/{id}:
delete:
tags:
- Roles
summary: Asynchronously delete a role
description: Asynchronously delete a role by given `id`.
operationId: deleteRoleAsync
parameters:
- name: hardDelete
in: query
description: Hard delete the entity. (Default = `false`)
schema:
type: boolean
default: false
- name: id
in: path
description: Id of the role
required: true
schema:
type: string
format: uuid
responses:
'200':
description: OK
'404':
description: Role for instance {id} is not found
/v1/roles/{id}/versions/{version}:
get:
tags:
- Roles
summary: Get a version of the role
description: Get a version of the role by given `id`
operationId: getSpecificRoleVersion
parameters:
- name: id
in: path
description: Id of the role
required: true
schema:
type: string
format: uuid
- name: version
in: path
description: Role version number in the form `major`.`minor`
required: true
schema:
type: string
example: 0.1 or 1.1
responses:
'200':
description: role
content:
application/json:
schema:
$ref: '#/components/schemas/Role'
'404':
description: Role for instance {id} and version {version} is not found
/v1/roles/history:
get:
tags:
- Roles
summary: List all entity versions within a time range
description: 'Get a paginated list of all entity versions within a given time range specified by `startTs` and `endTs` in milliseconds since epoch. '
operationId: listAllEntityVersionsByTimestamp_58
parameters:
- name: startTs
in: query
description: Start timestamp in milliseconds since epoch
required: true
schema:
type: integer
format: int64
- name: endTs
in: query
description: End timestamp in milliseconds since epoch
required: true
schema:
type: integer
format: int64
- name: limit
in: query
description: Limit the number of entity returned (1 to 1000000, default = 10)
schema:
maximum: 500
minimum: 1
type: integer
format: int32
default: 10
- name: before
in: query
description: Returns list of entity versions before this cursor
schema:
type: string
- name: after
in: query
description: Returns list of entity versions after this cursor
schema:
type: string
responses:
'200':
description: List of all versions
content:
application/json:
schema:
$ref: '#/components/schemas/ResultList'
/v1/roles/{id}/versions:
get:
tags:
- Roles
summary: List role versions
description: Get a list of all the versions of a role identified by `id`
operationId: listAllRoleVersion
parameters:
- name: id
in: path
description: Id of the role
required: true
schema:
type: string
format: uuid
responses:
'200':
description: List of role versions
content:
application/json:
schema:
$ref: '#/components/schemas/EntityHistory'
/v1/roles/name/{fqn}:
patch:
tags:
- Roles
summary: Update a role using name.
description: Update an existing role with JsonPatch.
externalDocs:
description: JsonPatch RFC
url: https://tools.ietf.org/html/rfc6902
operationId: patchRole
parameters:
- name: fqn
in: path
description: Name of the role
required: true
schema:
type: string
requestBody:
description: JsonPatch with array of operations
content:
application/json-patch+json:
schema:
$ref: '#/components/schemas/JsonPatch'
example: '[{op:remove, path:/a},{op:add, path: /b, value: val}]'
responses:
default:
description: default response
content:
application/json: {}
/v1/roles/restore:
put:
tags:
- Roles
summary: Restore a soft deleted role
description: Restore a soft deleted role.
operationId: restore_45
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/RestoreEntity'
responses:
'200':
description: 'Successfully restored the Role. '
content:
application/json:
schema:
$ref: '#/components/schemas/Role'
/v1/roles/search:
get:
tags:
- Roles
summary: Search roles
description: Search roles by name or display name. Use `q` parameter to provide the search query.
operationId: searchRoles
parameters:
- name: q
in: query
description: Search query for role names or display names
schema:
type: string
- name: fields
in: query
description: Fields requested in the returned resource
schema:
type: string
example: policies,teams,users
- name: limit
in: query
description: Limit the number of roles returned. (1 to 1000, default = 10)
schema:
maximum: 1000
minimum: 1
type: integer
format: int32
default: 10
- name: offset
in: query
description: Offset for pagination (default = 0)
schema:
minimum: 0
type: integer
format: int32
default: 0
- name: include
in: query
description: Include all, deleted, or non-deleted entities.
schema:
type: string
default: non-deleted
enum:
- all
- deleted
- non-deleted
responses:
'200':
description: List of matching roles
content:
application/json:
schema:
$ref: '#/components/schemas/RoleList'
components:
schemas:
TagLabelRecognizerMetadata:
required:
- recognizerId
- recognizerName
- score
type: object
properties:
recognizerId:
type: string
format: uuid
recognizerName:
type: string
score:
type: number
format: double
target:
type: string
enum:
- content
- column_name
patterns:
type: array
items:
$ref: '#/components/schemas/PatternMatch'
ChangeSummaryMap:
type: object
AccessDetails:
required:
- timestamp
type: object
properties:
timestamp:
type: integer
format: int64
accessedBy:
$ref: '#/components/schemas/EntityReference'
accessedByAProcess:
type: string
FieldChange:
type: object
properties:
name:
type: string
oldValue:
type: object
newValue:
type: object
CoverImage:
type: object
properties:
url:
type: string
position:
type: string
RestoreEntity:
required:
- id
type: object
properties:
id:
type: string
format: uuid
LifeCycle:
type: object
properties:
created:
$ref: '#/components/schemas/AccessDetails'
updated:
$ref: '#/components/schemas/AccessDetails'
accessed:
$ref: '#/components/schemas/AccessDetails'
EntityHistory:
required:
- entityType
- versions
type: object
properties:
entityType:
type: string
versions:
type: array
items:
type: object
AssetCertification:
required:
- appliedDate
- expiryDate
- tagLabel
type: object
properties:
tagLabel:
$ref: '#/components/schemas/TagLabel'
appliedDate:
type: integer
format: int64
expiryDate:
type: integer
format: int64
ResultList:
required:
- data
type: object
properties:
data:
type: array
items:
type: object
paging:
$ref: '#/components/schemas/Paging'
errors:
type: array
items:
$ref: '#/components/schemas/EntityError'
warningsCount:
type: integer
format: int32
warnings:
type: array
items:
$ref: '#/components/schemas/EntityError'
Paging:
required:
- total
type: object
properties:
before:
type: string
after:
type: string
offset:
type: integer
format: int32
limit:
type: integer
format: int32
total:
type: integer
format: int32
CreateRole:
required:
- name
- policies
type: object
properties:
name:
maxLength: 256
minLength: 1
pattern: ^((?!::).)*$
type: string
displayName:
type: string
description:
type: string
policies:
type: array
items:
type: string
domains:
type: array
items:
type: string
owners:
type: array
items:
$ref: '#/components/schemas/EntityReference'
extension:
type: object
tags:
type: array
items:
$ref: '#/components/schemas/TagLabel'
reviewers:
type: array
items:
$ref: '#/components/schemas/EntityReference'
dataProducts:
type: array
items:
type: string
lifeCycle:
$ref: '#/components/schemas/LifeCycle'
JsonPatch:
type: object
ChangeDescription:
type: object
properties:
fieldsAdded:
type: array
items:
$ref: '#/components/schemas/FieldChange'
fieldsUpdated:
type: array
items:
$ref: '#/components/schemas/FieldChange'
fieldsDeleted:
type: array
items:
$ref: '#/components/schemas/FieldChange'
previousVersion:
type: number
format: double
changeSummary:
$ref: '#/components/schemas/ChangeSummaryMap'
Role:
required:
- id
- name
type: object
properties:
id:
type: string
format: uuid
name:
maxLength: 256
minLength: 1
pattern: ^((?!::).)*$
type: string
fullyQualifiedName:
maxLength: 3072
minLength: 1
type: string
displayName:
type: string
description:
type: string
version:
type: number
format: double
updatedAt:
type: integer
format: int64
updatedBy:
type: string
impersonatedBy:
type: string
href:
type: string
format: uri
changeDescription:
$ref: '#/components/schemas/ChangeDescription'
incrementalChangeDescription:
$ref: '#/components/schemas/ChangeDescription'
allowDelete:
type: boolean
allowEdit:
type: boolean
deleted:
type: boolean
policies:
type: array
items:
$ref: '#/components/schemas/EntityReference'
users:
type: array
items:
$ref: '#/components/schemas/EntityReference'
teams:
type: array
items:
$ref: '#/components/schemas/EntityReference'
provider:
type: string
enum:
- system
- user
- automation
disabled:
type: boolean
domains:
type: array
items:
$ref: '#/components/schemas/EntityReference'
owners:
type: array
items:
$ref: '#/components/schemas/EntityReference'
extension:
type: object
children:
type: array
items:
$ref: '#/components/schemas/EntityReference'
service:
$ref: '#/components/schemas/EntityReference'
style:
$ref: '#/components/schemas/Style'
tags:
type: array
items:
$ref: '#/components/schemas/TagLabel'
followers:
type: array
items:
$ref: '#/components/schemas/EntityReference'
experts:
type: array
items:
$ref: '#/components/schemas/EntityReference'
reviewers:
type: array
items:
$ref: '#/components/schemas/EntityReference'
dataProducts:
type: array
items:
$ref: '#/components/schemas/EntityReference'
dataContract:
$ref: '#/components/schemas/EntityReference'
usageSummary:
$ref: '#/components/schemas/UsageDetails'
entityStatus:
type: string
enum:
- Draft
- In Review
- Approved
- Archived
- Deprecated
- Rejected
- Unprocessed
votes:
$ref: '#/components/schemas/Votes'
lifeCycle:
$ref: '#/components/schemas/LifeCycle'
certification:
$ref: '#/components/schemas/AssetCertification'
UsageStats:
required:
- count
type: object
properties:
count:
minimum: 0
exclusiveMinimum: false
type: integer
format: int32
percentileRank:
type: number
format: double
Style:
type: object
properties:
color:
type: string
iconURL:
type: string
coverImage:
$ref: '#/components/schemas/CoverImage'
RoleList:
required:
- data
type: object
properties:
data:
type: array
items:
$ref: '#/components/schemas/Role'
paging:
$ref: '#/components/schemas/Paging'
errors:
type: array
items:
$ref: '#/components/schemas/EntityError'
warningsCount:
type: integer
format: int32
warnings:
type: array
items:
$ref: '#/components/schemas/EntityError'
Votes:
type: object
properties:
upVotes:
type: integer
format: int32
downVotes:
type: integer
format: int32
upVoters:
type: array
items:
$ref: '#/components/schemas/EntityReference'
downVoters:
type: array
items:
$ref: '#/components/schemas/EntityReference'
TagLabel:
required:
- labelType
- source
- state
- tagFQN
type: object
properties:
tagFQN:
type: string
name:
type: string
displayName:
type: string
description:
type: string
style:
$ref: '#/components/schemas/Style'
source:
type: string
enum:
- Classification
- Glossary
labelType:
type: string
enum:
- Manual
- Propagated
- Automated
- Derived
- Generated
state:
type: string
enum:
- Suggested
- Confirmed
href:
type: string
format: uri
reason:
type: string
appliedAt:
type: string
format: date-time
appliedBy:
type: string
metadata:
$ref: '#/components/schemas/TagLabelMetadata'
PatternMatch:
required:
- name
- score
type: object
properties:
name:
type: string
regex:
type: string
score:
type: number
format: double
TagLabelMetadata:
type: object
properties:
recognizer:
$ref: '#/components/schemas/TagLabelRecognizerMetadata'
expiryDate:
type: integer
format: int64
EntityError:
type: object
properties:
message:
type: string
entity:
type: object
EntityReference:
required:
- id
- type
type: object
properties:
id:
type: string
format: uuid
type:
type: string
name:
type: string
fullyQualifiedName:
type: string
description:
type: string
displayName:
type: string
deleted:
type: boolean
inherited:
type: boolean
href:
type: string
format: uri
UsageDetails:
required:
- dailyStats
- date
type: object
properties:
dailyStats:
$ref: '#/components/schemas/UsageStats'
weeklyStats:
$ref: '#/components/schemas/UsageStats'
monthlyStats:
$ref: '#/components/schemas/UsageStats'
date:
type: string
securitySchemes:
BearerAuth:
type: http
scheme: bearer
bearerFormat: JWT