API-Level Permissions for Endpoints

This page provides access and authorization information for the OCI Generative AI endpoint resource type.

For specific permissions for this resource type, review this page. For a list of all resource types available in OCI Generative AI, see User Access to Individual Resources.

Resource Type

Resource Type for IAM Permissions Documentation Reference API Reference
generative-ai-endpoint Managing Model Endpoints Endpoint

Inspect Permission

Grant user groups inspect permission to run the following operations:

  • GET ListEndpoints

Read Permission

Grant user groups read permission to run the following operations:

  • GET ListEndpoints
  • GET GetEndpoint

Use Permission

Grant user groups use permission to run the following operations:

  • GET ListEndpoints
  • GET GetEndpoint
  • PUT UpdateEndpoint

Manage Permission

Grant user groups manage permission to run the following operations:

  • GET ListEndpoints
  • GET GetEndpoint
  • PUT UpdateEndpoint
  • POST ChangeEndpointCompartment
  • POST CreateEndpoint
  • DELETE DeleteEndpoint
Note

  • The manage permission includes all actions allowed by use, read, and inspect.
  • The use permission includes all actions allowed by read and inspect.
  • The read permission includes all actions allowed by inspect.
Tip

The generative-ai-endpoint resource type is part of generative-ai-family. If you have permission to the family, you have the same permission for this resource type. For example:
allow group <your-group-name> to manage generative-ai-family
in compartment <your-compartment-name>

1-1 Permissions for APIs

Note

We recommend using the higher-level IAM verbs, manage, use, read, and inspect, for a better user experience. For example, you might grant a user group permission to delete a resource, but if you don't also grant permission to list that resource, users might not find it.

If a use case requires access to only a specific API operation, you can use the individual permissions listed here.

generative-ai-endpoint

Permission API Operation Operation Type Verb
GENERATIVE_AI_ENDPOINT_INSPECT ListEndpoints GET inspect
GENERATIVE_AI_ENDPOINT_READ GetEndpoint GET read
GENERATIVE_AI_ENDPOINT_UPDATE UpdateEndpoint PUT use
GENERATIVE_AI_ENDPOINT_MOVE ChangeEndpointCompartment POST manage
GENERATIVE_AI_ENDPOINT_CREATE CreateEndpoint POST manage
GENERATIVE_AI_ENDPOINT_DELETE DeleteEndpoint DELETE manage

For example, the following two policies are equivalent:

allow group <your-user-group> to manage generative-ai-endpoint
in compartment <your-compartment-name>
allow group <your-user-group> to
{GENERATIVE_AI_ENDPOINT_INSPECT, GENERATIVE_AI_ENDPOINT_READ, GENERATIVE_AI_ENDPOINT_UPDATE, GENERATIVE_AI_ENDPOINT_MOVE, GENERATIVE_AI_ENDPOINT_CREATE, GENERATIVE_AI_ENDPOINT_DELETE}
in compartment <your-compartment-name>