Permissions

Beta

Almost every request to the emnify API is authorized against a single permission. A few endpoints need none: public ones such as authentication, and a handful that only require a signed-in user. If your role doesn’t include the permission an endpoint requires, the API responds with 403 Forbidden.

Each endpoint’s required permission is shown in a callout at the top of its reference page. For endpoints that require no permission, such as authentication, the callout says so. For every permission at once, and the roles that include it, see the permission reference.

Permissions are in beta. To request access, contact your Customer Success Manager.

How permissions work

A permission is a pair of a resource (the thing you act on) and an action (what you do to it). In these docs it’s written as Resource + Action, for example Endpoint + List. You always need the exact pair.

Permissions are grouped into roles, and every user is assigned a role:

  • System roles are built in and can’t be edited: Administrator, User, and Observer. Each includes a fixed set of permissions.
  • Custom roles let you grant an exact set of permissions that you choose.

To call an endpoint, your role must include that endpoint’s required permission.

Roles and permissions documents what each system role includes in the emnify Portal. A custom role grants whatever combination you choose.

The permission model

ConceptDescription
ResourceThe domain you act on, in PascalCase with dots for hierarchy, such as Endpoint, Endpoint.Tag, or User.Mfa.
ActionThe operation, such as List, Get, Create, Update, Delete, Add, Remove, or a specific verb like Transfer or Cancel.
PairA permission is always a resource and an action together. Neither half grants access on its own.
Own dataSome resources have a .My variant for acting on your own data, such as your own user, separate from acting on others’.
Bulk endpointsA bulk endpoint uses the same permission as its single-resource version. For example, DELETE /api/v1/endpoint/multi and DELETE /api/v1/endpoint/{endpoint_id} both require Endpoint + Delete.
Public endpointsA few endpoints, such as authentication, require no permission.

System roles

RoleAccess
AdministratorFull access to every permission.
UserDay-to-day access: all read actions, plus write actions that are safe to grant broadly.
ObserverRead-only access.

To grant a different combination, create a custom role from the permissions in the reference below. For ready-made permission sets covering three common jobs, see Role templates.

Permission reference

This reference covers the emnify REST API. Permissions for pre-release APIs are added when those APIs become generally available.

The table lists each API permission and which system roles include it.

ResourceActionAdministratorUserObserver
ApplicationTokenListYesYesYes
CreateYesNoNo
UpdateYesNoNo
Authenticate.WorkspaceGetYesYesYes
BreakoutRegionListYesYesYes
CallbackSecretListYesYesYes
GetYesYesYes
CreateYesYesNo
DeleteYesYesNo
CallbackUrlListYesYesYes
GetYesYesYes
CreateYesYesNo
DeleteYesYesNo
CloudConnect.BreakoutListYesYesYes
GetYesYesYes
CreateYesYesNo
DeleteYesNoNo
CloudConnect.Breakout.TgwCreateYesYesNo
CloudConnect.Breakout.VpnCreateYesYesNo
CloudConnect.BreakoutTypeListYesYesYes
CloudConnect.BreakoutType.RegionListYesYesYes
CloudConnect.PricingListYesYesYes
CountryListYesYesYes
CurrencyListYesYesYes
DataBlocksizeListYesYesYes
DataStreamListYesYesYes
GetYesYesYes
CreateYesYesNo
UpdateYesYesNo
DeleteYesYesNo
RestartYesYesNo
DataStream.FilterFieldTypeListYesYesYes
DataStream.StatusListYesYesYes
DataStream.TypeListYesYesYes
DataThrottleListYesYesYes
DnsListYesYesNo
CreateYesYesNo
DeleteYesYesNo
DnsFirewallProfileListYesNoNo
GetYesNoNo
CreateYesNoNo
UpdateYesNoNo
DeleteYesNoNo
EndpointListYesYesYes
GetYesYesYes
CreateYesYesNo
UpdateYesYesNo
DeleteYesYesNo
Endpoint.ConnectivityGetYesYesYes
UpdateYesYesNo
Endpoint.EventListYesYesYes
Endpoint.FlowLogs.DestinationListYesNoNo
Endpoint.FlowLogs.DetailListYesNoNo
Endpoint.OperatorBlacklistListYesYesYes
DeleteYesYesNo
AddYesYesNo
Endpoint.Quota.DataGetYesYesYes
CreateYesYesNo
DeleteYesYesNo
Endpoint.Quota.SmsGetYesYesYes
CreateYesYesNo
DeleteYesYesNo
Endpoint.SmsListYesYesYes
GetYesYesYes
CreateYesYesNo
CancelYesYesNo
Endpoint.StatsGetYesYesYes
Endpoint.StatusListYesYesYes
Endpoint.TagListYesYesYes
AddYesYesNo
RemoveYesYesNo
Endpoint.TrafficLimitExtensionListYesYesYes
CreateYesYesNo
DeleteYesYesNo
EsmeInterfaceTypeListYesYesYes
EventListYesYesYes
Event.TypeListYesYesYes
IpAddressSpaceListYesYesYes
CreateYesNoNo
AddYesNoNo
RemoveYesNoNo
IpFirewallProfileListYesNoNo
CreateYesNoNo
OperatorListYesYesYes
Organisation.InclusiveVolumeListYesYesYes
AddYesYesNo
Organisation.MyGetYesYesYes
Organisation.PermissionListYesNoNo
Organisation.RoleListYesYesNo
GetYesYesNo
CreateYesNoNo
UpdateYesNoNo
DeleteYesNoNo
Organisation.StatsGetYesYesYes
Organisation.StatusListYesYesYes
Organisation.TariffUpdateYesYesNo
Organisation.TariffPlanListYesYesYes
RatTypeListYesYesYes
ServiceListYesYesYes
Service.TrafficLimitListYesYesYes
ServiceProfileListYesYesYes
GetYesYesYes
CreateYesYesNo
UpdateYesYesNo
DeleteYesYesNo
ServiceProfile.DnsFirewallRuleSetUpdateYesNoNo
ServiceProfile.QuotaRemoveYesYesNo
ServiceProfile.ServiceAddYesYesNo
RemoveYesYesNo
ServiceProfile.Service.TrafficLimitDeleteYesYesNo
AddYesYesNo
ServiceProfile.TrafficLimitListYesYesYes
CreateYesYesNo
DeleteYesYesNo
SimListYesYesYes
GetYesYesYes
UpdateYesYesNo
DeleteYesYesNo
Sim.EventListYesYesYes
Sim.StatsGetYesYesYes
Sim.StatusListYesYesYes
Sim.WorkspaceTransferYesNoNo
SimBatch.BicGetYesYesYes
AddYesYesNo
TagListYesYesYes
CreateYesYesNo
UpdateYesYesNo
DeleteYesYesNo
Tag.ColorListYesYesYes
TariffPlanListYesYesYes
TariffProfileListYesYesYes
GetYesYesYes
CreateYesYesNo
UpdateYesYesNo
DeleteYesYesNo
TariffProfile.CoverageListYesYesYes
TariffProfile.InclusiveVolumeAddYesYesNo
RemoveYesYesNo
TariffProfile.OperatorBlocklist.OperatorListYesYesYes
GetYesYesYes
AddYesYesNo
RemoveYesYesNo
TariffProfile.OperatorBlocklist.Operator.RatTypeAddYesYesNo
RemoveYesYesNo
TariffProfile.RatezoneSelectionAddYesYesNo
RemoveYesYesNo
TrafficLimitListYesYesYes
UserListYesNoNo
GetYesNoNo
CreateYesNoNo
UpdateYesNoNo
DeleteYesNoNo
User.DefaultOrganisationUpdateYesNoNo
User.EventListYesNoNo
User.InvitationCreateYesNoNo
User.MfaDeleteYesYesYes
User.Mfa.StatusListYesYesYes
User.Mfa.TrustedDeviceListYesNoNo
DeleteYesNoNo
User.Mfa.TypeListYesYesYes
User.My.RoleListYesYesNo
User.RoleAddYesNoNo
RemoveYesNoNo
User.Role.PermissionListYesNoNo
User.StatusListYesYesYes
User.WorkspaceListYesYesYes
UpdateYesNoNo
RemoveYesNoNo
User.Workspace.RoleAddYesNoNo
RemoveYesNoNo