Permissions changedapi/beta/organization/rbac_roles/permissions
Nearest release: v2.1.287, published 4 hours before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Recorded here
Lines+97added
Lines−12removed
From line
64
where the diff opens
First seen
10 Sep 2026
this site's first read of the page
Recorded edits6to this page, all time
### Beta RBAC All Connectors Permission Resource ### Beta RBAC Connector Permission Resource ### Beta RBAC Connector Scope Permission Resource ### Beta RBAC Connector Tool Permission Resource ### Beta RBAC Organization Permission Resource
The whole hunk
from line 64, old and new numbered
/
from line 64
6464 `all_connectors` grants carry a tool-access action, the scope action, or
6565 an authentication-method action (`interactive` or `managed`).
6666
67 - `resource: Organization or ConnectorTool or ConnectorScope or 2 more`
67 - `resource: BetaRBACOrganizationPermissionResource or BetaRBACConnectorToolPermissionResource or BetaRBACConnectorScopePermissionResource or 2 more`
6868
6969 What the permission applies to.
7070
from line 71
7171 A tagged union: `type` names the kind of resource and determines which
7272 identifier fields are present.
7373
74 - `Organization object`
74 - `BetaRBACOrganizationPermissionResource object`
7575
7676 - `type: "organization"`
7777
from line 83
8383
8484 UUID of the organization the permission applies to.
8585
86 - `ConnectorTool object`
86 - `BetaRBACConnectorToolPermissionResource object`
8787
8888 - `type: "connector_tool"`
8989
from line 104
104104 `{prefix}_{32-hex}` form — a shortened readable prefix of the name plus
105105 a hash — from which the published name is not recoverable.
106106
107 - `ConnectorScope object`
107 - `BetaRBACConnectorScopePermissionResource object`
108108
109109 - `type: "connector_scope"`
110110
from line 126
126126 appears server-encoded in a stable `{prefix}_{32-hex}` form. OAuth
127127 scopes routinely contain `:` and `/`, so most appear encoded.
128128
129 - `Connector object`
129 - `BetaRBACConnectorPermissionResource object`
130130
131131 - `type: "connector"`
132132
from line 138
138138
139139 ID of the connector the permission applies to.
140140
141 - `AllConnectors object`
141 - `BetaRBACAllConnectorsPermissionResource object`
142142
143143 - `type: "all_connectors"`
144144
from line 184
184184
185185## Domain types
186186
187### Beta RBAC All Connectors Permission Resource
188
189- `BetaRBACAllConnectorsPermissionResource object`
190
191 - `type: "all_connectors"`
192
193 Kind of resource the permission applies to.
194
195 default: all_connectors
196
197### Beta RBAC Connector Permission Resource
198
199- `BetaRBACConnectorPermissionResource object`
200
201 - `type: "connector"`
202
203 Kind of resource the permission applies to.
204
205 default: connector
206
207 - `connector_id: string`
208
209 ID of the connector the permission applies to.
210
211### Beta RBAC Connector Scope Permission Resource
212
213- `BetaRBACConnectorScopePermissionResource object`
214
215 - `type: "connector_scope"`
216
217 Kind of resource the permission applies to.
218
219 default: connector_scope
220
221 - `connector_id: string`
222
223 ID of the connector the permission applies to.
224
225 - `scope: string`
226
227 OAuth scope the permission names — the role may receive this scope when
228 tokens are minted for the connector.
229
230 Subject to the same encoding rule as `tool_name`: a scope containing
231 characters outside `[a-zA-Z0-9_-]` (or colliding with a reserved form)
232 appears server-encoded in a stable `{prefix}_{32-hex}` form. OAuth
233 scopes routinely contain `:` and `/`, so most appear encoded.
234
235### Beta RBAC Connector Tool Permission Resource
236
237- `BetaRBACConnectorToolPermissionResource object`
238
239 - `type: "connector_tool"`
240
241 Kind of resource the permission applies to.
242
243 default: connector_tool
244
245 - `connector_id: string`
246
247 ID of the connector the permission applies to.
248
249 - `tool_name: string`
250
251 Published name of the connector tool the permission applies to.
252
253 When the published name contains characters outside `[a-zA-Z0-9_-]` (or
254 collides with a reserved form), it is server-encoded into a stable
255 `{prefix}_{32-hex}` form — a shortened readable prefix of the name plus
256 a hash — from which the published name is not recoverable.
257
258### Beta RBAC Organization Permission Resource
259
260- `BetaRBACOrganizationPermissionResource object`
261
262 - `type: "organization"`
263
264 Kind of resource the permission applies to.
265
266 default: organization
267
268 - `organization_id: string`
269
270 UUID of the organization the permission applies to.
271
187272### Beta RBAC Role Permission
188273
189274- `BetaRBACRolePermission object`
from line 300
215300 `all_connectors` grants carry a tool-access action, the scope action, or
216301 an authentication-method action (`interactive` or `managed`).
217302
218 - `resource: Organization or ConnectorTool or ConnectorScope or 2 more`
303 - `resource: BetaRBACOrganizationPermissionResource or BetaRBACConnectorToolPermissionResource or BetaRBACConnectorScopePermissionResource or 2 more`
219304
220305 What the permission applies to.
221306
from line 307
222307 A tagged union: `type` names the kind of resource and determines which
223308 identifier fields are present.
224309
225 - `Organization object`
310 - `BetaRBACOrganizationPermissionResource object`
226311
227312 - `type: "organization"`
228313
from line 319
234319
235320 UUID of the organization the permission applies to.
236321
237 - `ConnectorTool object`
322 - `BetaRBACConnectorToolPermissionResource object`
238323
239324 - `type: "connector_tool"`
240325
from line 340
255340 `{prefix}_{32-hex}` form — a shortened readable prefix of the name plus
256341 a hash — from which the published name is not recoverable.
257342
258 - `ConnectorScope object`
343 - `BetaRBACConnectorScopePermissionResource object`
259344
260345 - `type: "connector_scope"`
261346
from line 362
277362 appears server-encoded in a stable `{prefix}_{32-hex}` form. OAuth
278363 scopes routinely contain `:` and `/`, so most appear encoded.
279364
280 - `Connector object`
365 - `BetaRBACConnectorPermissionResource object`
281366
282367 - `type: "connector"`
283368
from line 374
289374
290375 ID of the connector the permission applies to.
291376
292 - `AllConnectors object`
377 - `BetaRBACAllConnectorsPermissionResource object`
293378
294379 - `type: "all_connectors"`
295380
No line in this hunk matches that.