---
title: "Dry-run permission evaluation"
method: POST
path: "/credentials/{credential_id}/agents/{agent_id}/permissions:test"
tags: ["Credentials"]
---

# Dry-run permission evaluation

`POST /credentials/{credential_id}/agents/{agent_id}/permissions:test`

Answer "what would the broker do for this request?" without calling upstream.

Unlike the toolkit `:test` there is **no vendor pooling**: the direct
binding's rules are one ordered first-match-wins list, so the result is
exactly this binding's policy. Default-deny when nothing matches.

## Path parameters

- `credential_id` string, required
- `agent_id` string, required

## Request body

- PermissionTestRequest — Request body for :test — dry-run a request shape against the binding's rules.
  - `method` string, required — HTTP method of the hypothetical request (case-insensitive).
  - `operation_id` string, nullable — Optional OpenAPI operation id resolved from the request URL.
  - `path` string, required — Path of the hypothetical request as the broker would see it.

## Response `200`

Successful Response

- PermissionTestResponse — Dry-run result matching :class:`PermissionTestResult`.
  - `allowed` boolean, required — Whether the broker would allow this request under the binding's rules.
  - `credential_id` string, nullable — The binding whose rule list contributed the matching rule.
  - `effect` string, nullable — Effect of the matching rule (`allow`/`deny`); null when no match.
  - `is_system` boolean, nullable — True when the matching rule was written by the system; null when no match.
  - `matched` boolean, required — Whether any rule matched; when false, the outcome is default-deny.
  - `rule_index` integer, nullable — Zero-based index in the binding's ordered rule list; null when no match.

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found
- `422` — Unprocessable Entity
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-09-14** `d56864df177c` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/jentic/apis/jentic-control-plane-api/changes/credentials/:credential_id/agents/:agent_id/permissions:test/post.md)

---

[API](https://skmtc.dev/jentic/apis/jentic-control-plane-api.md) · [All operations](https://skmtc.dev/jentic/apis/jentic-control-plane-api/llms.txt) · [OpenAPI document](https://skmtc.dev/jentic/apis/jentic-control-plane-api/revisions/e4688b93dfc7?raw)
