API

Use tenant and access context

Select the tenant and confirm the exact resource action before API work.

Separate identity, tenant and access

Authentication identifies the actor. Tenant context selects the boundary. Permission checks decide whether that actor can perform the exact action on the exact resource. None of these steps replaces another.

Use this sequence

  1. Sign in using a supported Product mechanism.
  2. Select the intended tenant through the authenticated session or documented tenant header.
  3. Find the resource through its customer operation.
  4. Ask an authorised administrator to confirm the exact access through the approved Product action.
  5. Perform the business operation.
  6. Keep the returned request ID.

Handle a denied request

A resource identifier does not grant access. A matching explicit Deny wins over an Allow. Confirm the tenant, resource type, resource ID, and action before an authorised administrator changes access.

Do not automate Product administration without approval

Tenant, user, licence, node, and Product interface administration routes are not included in the customer contract. Use the approved Product action unless a later release explicitly classifies an administration operation for integration.

Reference

Read the access model. Authorization administration is not in the customer API contract.

Pūnaha Docs

Search the guides

Enter at least two characters.

    Product screen

    View the full screenshot