API-Level Permissions for Endpoints
This page provides access and authorization information for the OCI Generative AI endpoint resource type.
For specific permissions for this resource type, review this page. For a list of all resource types available in OCI Generative AI, see User Access to Individual Resources.
Resource Type
| Resource Type for IAM Permissions | Documentation Reference | API Reference |
|---|---|---|
generative-ai-endpoint |
Managing Model Endpoints | Endpoint |
Inspect Permission
Grant user groups inspect permission to run the following operations:
- GET
ListEndpoints
Read Permission
Grant user groups read permission to run the following operations:
- GET
ListEndpoints - GET
GetEndpoint
Use Permission
Grant user groups use permission to run the following operations:
- GET
ListEndpoints - GET
GetEndpoint - PUT
UpdateEndpoint
Manage Permission
Grant user groups manage permission to run the following operations:
- GET
ListEndpoints - GET
GetEndpoint - PUT
UpdateEndpoint - POST
ChangeEndpointCompartment - POST
CreateEndpoint - DELETE
DeleteEndpoint
- The manage permission includes all actions allowed by use, read, and inspect.
- The use permission includes all actions allowed by read and inspect.
- The read permission includes all actions allowed by inspect.
The
generative-ai-endpoint resource type is part of generative-ai-family. If you have permission to the family, you have the same permission for this resource type. For example:
allow group <your-group-name> to manage generative-ai-family
in compartment <your-compartment-name>1-1 Permissions for APIs
We recommend using the higher-level IAM verbs, manage, use, read, and inspect, for a better user experience. For example, you might grant a user group permission to delete a resource, but if you don't also grant permission to list that resource, users might not find it.
If a use case requires access to only a specific API operation, you can use the individual permissions listed here.
generative-ai-endpoint
| Permission | API Operation | Operation Type | Verb |
|---|---|---|---|
GENERATIVE_AI_ENDPOINT_INSPECT |
ListEndpoints |
GET |
inspect |
GENERATIVE_AI_ENDPOINT_READ |
GetEndpoint |
GET |
read |
GENERATIVE_AI_ENDPOINT_UPDATE |
UpdateEndpoint |
PUT |
use |
GENERATIVE_AI_ENDPOINT_MOVE |
ChangeEndpointCompartment |
POST |
manage |
GENERATIVE_AI_ENDPOINT_CREATE |
CreateEndpoint |
POST |
manage |
GENERATIVE_AI_ENDPOINT_DELETE |
DeleteEndpoint |
DELETE |
manage |
For example, the following two policies are equivalent:
allow group <your-user-group> to manage generative-ai-endpoint
in compartment <your-compartment-name>allow group <your-user-group> to
{GENERATIVE_AI_ENDPOINT_INSPECT, GENERATIVE_AI_ENDPOINT_READ, GENERATIVE_AI_ENDPOINT_UPDATE, GENERATIVE_AI_ENDPOINT_MOVE, GENERATIVE_AI_ENDPOINT_CREATE, GENERATIVE_AI_ENDPOINT_DELETE}
in compartment <your-compartment-name>