Skip to main content

Permissions

Every CertHub API key inherits the permissions of the user who created it. The API does not bypass the CertHub permission model.

What that means in practice​

  • If the user can read a product or knowledge topic in the dashboard, the key can usually read it via the API
  • If the user cannot access an object in the UI, the key cannot access it via the API either
  • If you regenerate the key, every integration using the old key stops working immediately

Typical failure mode​

If a request returns 403 Forbidden, the key is valid but the user behind it does not have permission for that operation.

Check:

  1. Which user created the key
  2. Whether that user can perform the same action in CertHub
  3. Whether the user's assigned roles include the right read, create, edit, approve, download, or delete permissions

For more on the role model, see Application Settings & User Management and Permissions Overview.

Authentication reminder​

Authentication and authorization are separate:

  • 401 usually means the key is missing, invalid, or expired
  • 403 usually means the key is valid, but the user does not have access

Next steps​