Skip to main content

Access Management

View as Markdown

List workspace permissions GA

GET /api/2.0/accounts/{account_id}/workspaces/{workspace_id}/permissionassignments/permissions

Get an array of workspace permissions for the specified account and workspace.

API scopes: access-management

Parameters

account_idstringRequiredpath

The account ID.

workspace_idint64Requiredpath

The workspace ID.

Response

permissionsarray of object

Array of permissions defined for a workspace.

Show child attributesHide child attributes
permission_levelstring

Values:

  • UNKNOWN
  • USER
  • ADMIN
descriptionstring

The results of a permissions query.

Get assignable roles for a resource Public Preview

GET /api/2.0/preview/accounts/{account_id}/access-control/assignable-roles

Gets all the roles that can be granted on an account level resource. A role is grantable if the rule set on the resource can contain an access rule of the role.

API scopes: access-management

Parameters

account_idstringRequiredpath

<Databricks> account ID.

resourcestringRequiredquery

The resource name for which assignable roles will be listed.

ExamplesSummary
resource=accounts/<ACCOUNT_ID>A resource name for the account.
resource=accounts/<ACCOUNT_ID>/groups/<GROUP_ID>A resource name for the group.
resource=accounts/<ACCOUNT_ID>/servicePrincipals/<SP_ID>A resource name for the service principal.
resource=accounts/<ACCOUNT_ID>/tagPolicies/<TAG_POLICY_ID>A resource name for the tag policy.

Response

rolesarray of object
Show child attributesHide child attributes
namestringRequired

Role to assign to a principal or a list of principals on a resource.

Get assignable roles for a resource Public Preview

GET /api/2.0/preview/accounts/access-control/assignable-roles

Gets all the roles that can be granted on an account level resource. A role is grantable if the rule set on the resource can contain an access rule of the role.

API scopes: access-management

Parameters

account_idstringquery

<Databricks> account ID.

resourcestringRequiredquery

The resource name for which assignable roles will be listed.

ExamplesSummary
resource=accounts/<ACCOUNT_ID>A resource name for the account.
resource=accounts/<ACCOUNT_ID>/groups/<GROUP_ID>A resource name for the group.
resource=accounts/<ACCOUNT_ID>/servicePrincipals/<SP_ID>A resource name for the service principal.
resource=accounts/<ACCOUNT_ID>/tagPolicies/<TAG_POLICY_ID>A resource name for the tag policy.

Response

rolesarray of object
Show child attributesHide child attributes
namestringRequired

Role to assign to a principal or a list of principals on a resource.