Credentials

Dry-run permission evaluation

Answer "what would the broker do for this request?" without calling upstream.

Unlike the toolkit :test there is no vendor pooling: the direct binding's rules are one ordered first-match-wins list, so the result is exactly this binding's policy. Default-deny when nothing matches.

post/credentials/{credential_id}/agents/{agent_id}/permissions:test

Path parameters

credential_idstring required
agent_idstring required

Request body

methodstring required

HTTP method of the hypothetical request (case-insensitive).

operation_idstring nullable

Optional OpenAPI operation id resolved from the request URL.

pathstring required

Path of the hypothetical request as the broker would see it.

Response

Successful Response

allowedboolean required

Whether the broker would allow this request under the binding's rules.

credential_idstring nullable

The binding whose rule list contributed the matching rule.

effectstring nullable

Effect of the matching rule (allow/deny); null when no match.

is_systemboolean nullable

True when the matching rule was written by the system; null when no match.

matchedboolean required

Whether any rule matched; when false, the outcome is default-deny.

rule_indexinteger nullable

Zero-based index in the binding's ordered rule list; null when no match.

Changes

Changed in 1 of the 114 revisions of this API.1