Skip to main content
Use this page to find the exact permission a root key needs. A permission is {resource}.{id}.{action}: one of the nine resource types below, a resource ID or * for all of them, and an action from the tables. Root key permissions explains how to choose permissions and read a permission error. The tables are grouped by product. The Scoped column says whether the dashboard lets you limit the action to one resource ID. Actions that aren’t scoped are always granted with *.

API Management

api (keyspaces and their keys)

The api resource is a keyspace, identified by its api_ ID. Key actions are granted on the keyspace the keys belong to.

ratelimit (namespaces and overrides)

The ratelimit resource is a namespace. The dashboard grants these with * only. No API endpoint uses read_namespace, update_namespace, or delete_namespace. The first ratelimit.limit call with a new name creates the namespace, and you manage namespaces in the dashboard.

rbac (permissions and roles for your keys)

These govern the permissions and roles you define for your own users’ keys, not root key permissions. All are granted with *.

identity

All granted with *.

portal (developer portals)

Creating an end-user session is separate from managing portals, so a key can create sessions for your users without being able to change the portal. All granted with *.

Compute

project

The project resource is identified by its proj_ ID. Some deployment actions can be granted on the whole project, so a CI key doesn’t need to know environment IDs.

app

The app resource is identified by its app_ ID.

environment

The environment resource is identified by its env_ ID. Deployment, domain, and gateway policy actions are granted here because those belong to an .

Platform

workspace

Actions for the whole workspace. A root key belongs to one workspace, so the id is always *.

Examples

  • api.*.verify_key verifies keys in every keyspace.
  • api.api_1234abcd.verify_key verifies keys in one keyspace.
  • environment.env_1234abcd.promote_deployment promotes deployments in one environment.
  • project.proj_1234abcd.create_deployment creates deployments in any environment of that project.
There’s no partial wildcard. To cover some keyspaces but not all, grant one permission per keyspace.
Last modified on September 29, 2026