# Venafi Permission APIs API

**Canonical:** https://apis.io/apis/venafi/venafi-permission-apis-api/  
**Provider:** Venafi — https://apis.io/providers/venafi/  
**Base URL:** https://api.venafi.cloud  
**Documentation:** https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview

Venafi Permission APIs API is one of 58 APIs that [Venafi](https://apis.io/providers/venafi/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. Tagged areas include Permission APIs. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.

The Permissions interface enables the management and querying of permissions within CyberArk Trust Protection Foundation™. Permissions grant principals (users and groups) privileges to objects within Trust Protection Foundation. In the Permissions interface, when a HTTP GET retrieves the permissions for a specific principal, both the effective and Implicit Permissions are returned.POST, PUT, or DELETE operations in this interface can successfully apply Effective Permissions parameters to principals in different identity providers. **What is the difference between Credentials, Permissions, and Identity?** * Credentials endpoints manage certificate and other activities. For more information, see Credentials APIs. * Identity endpoints manage CyberArk users. For more information, see Identity APIs. * Permissions endpoints grant principals (users and groups) privileges to objects within Trust Protection Foundation.

## Operations (19)

| Method | Path | Summary |
|---|---|---|
| POST | `/vedsdk/permissions/getprincipals` | Get trustees |
| POST | `/vedsdk/permissions/getpermissions` | Get assigned permissions |
| POST | `/vedsdk/permissions/geteffectivepermissions` | Get effective permissions |
| POST | `/vedsdk/permissions/grantpermissions` | Grant permissions |
| POST | `/vedsdk/permissions/revokepermissions` | Revoke permissions |
| POST | `/vedsdk/permissions/replacepermissions` | Update permissions |
| GET | `/vedsdk/permissions/refresh` | Refresh permissions |
| GET | `/vedsdk/permissions/object/{guid}` | Gets object trustees |
| GET | `/vedsdk/permissions/object/{guid}/local/{identity}` | Get assigned permissions of a local identity |
| GET | `/vedsdk/permissions/object/{guid}/local/{identity}/effective` | Get effective permissions of local identity |
| GET | `/vedsdk/permissions/object/{guid}/{prefix}/{identity}/{principal}` | Get assigned permissions of an identity |
| DELETE | `/vedsdk/permissions/object/{guid}/{prefix}/{identity}/{principal}` | Delete permissions |
| POST | `/vedsdk/permissions/object/{guid}/{prefix}/{identity}/{principal}` | Add permissions |
| PUT | `/vedsdk/permissions/object/{guid}/{prefix}/{identity}/{principal}` | Update permissions |
| GET | `/vedsdk/permissions/object/{guid}/{prefix}/{identity}/{principal}/effective` | Get effective permissions of an identity |
| GET | `/vedsdk/permissions/object/{guid}/myeffective` | Gets the effective permissions of the session's user for the given object |
| DELETE | `/vedsdk/permissions/object/{guid}/local/{principal}` | Delete permissions |
| POST | `/vedsdk/permissions/object/{guid}/local/{principal}` | Add permissions |
| PUT | `/vedsdk/permissions/object/{guid}/local/{principal}` | Update permissions |

## Machine-readable artifacts (4)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/venafi/refs/heads/main/openapi/venafi-permission-apis-api-openapi.yml
- **Documentation** — https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- **Webhooks** — https://raw.githubusercontent.com/api-evangelist/venafi/refs/heads/main/asyncapi/venafi-certificate-manager-saas-webhooks.yml
- **Documentation** — https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php

## Other Venafi APIs (12)

- [Venafi Access Management APIs API](https://apis.io/apis/venafi/venafi-access-management-apis-api/)
- [Venafi AlgorithmSelector APIs API](https://apis.io/apis/venafi/venafi-algorithmselector-apis-api/)
- [Venafi Application API](https://apis.io/apis/venafi/venafi-application-api/)
- [Venafi Authentication Server APIs API](https://apis.io/apis/venafi/venafi-authentication-server-apis-api/)
- [Venafi Certificate Approvals API](https://apis.io/apis/venafi/venafi-certificate-approvals-api/)
- [Venafi Certificate Auto-renewal Monitoring API](https://apis.io/apis/venafi/venafi-certificate-auto-renewal-monitoring-api/)
- [Venafi Certificate Discovery API](https://apis.io/apis/venafi/venafi-certificate-discovery-api/)
- [Venafi Certificate Expiration Reports API](https://apis.io/apis/venafi/venafi-certificate-expiration-reports-api/)
- [Venafi Certificate Import API](https://apis.io/apis/venafi/venafi-certificate-import-api/)
- [Venafi Certificate Installations API](https://apis.io/apis/venafi/venafi-certificate-installations-api/)
- [Venafi Certificate Inventory Monitoring API](https://apis.io/apis/venafi/venafi-certificate-inventory-monitoring-api/)
- [Venafi Certificate Management APIs API](https://apis.io/apis/venafi/venafi-certificate-management-apis-api/)

## Tags

Permission APIs

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/venafi/venafi-permission-apis-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/venafi/.
