Class ScopeRequest.Builder
- Enclosing class:
ScopeRequest
-
Method Summary
Modifier and TypeMethodDescriptionadditionalProperties(Map<String, Object> additionalProperties) additionalProperty(String key, Object value) allowedActions(List<String> allowedActions) allowedActions(Optional<List<String>> allowedActions) The actions this token may perform.build()Restricts which records the token can access.from(ScopeRequest other) Ownership fields automatically stamped onto resources created with this token.
-
Method Details
-
from
-
allowedActions
The actions this token may perform. Each entry has the form
resource:operations, whereoperationsis one ofr(read),c(create),u(update),d(delete),crud(all four), or a colon-separated combination. For records you may append a type qualifier, e.g.records:r:intake_form. For identity entities the grammar isentities:<verb>:<namespace>, e.g.entities:r:orgorentities:c:client(reserved namespacesorgandclient). Valid resources are:entities,users,documents,folders,records,schemas, andsearch.namespacesis deliberately not among them: reading the namespace registry is open to any credential, and registering, updating, or deleting a namespace requires a root API key — so anamespaces:<verb>entry would neither grant nor withhold anything. -
allowedActions
-
identity
Ownership fields automatically stamped onto resources created with this token. Optional. Keys are ownership dimensions:
userId, or any scope namespace in canonicalscope:<namespace>form (e.g.scope:org,scope:client,scope:group). Entity values must be Vectros UUIDs — look them up withGET /v1/usersorGET /v1/entities/{namespace}; custom-scope values are identifiers you define. The token holder cannot override these values when creating resources, but may narrow which of them stamp per create via thescopesrequest field. -
identity
-
dataScope
Restricts which records the token can access. Optional. Keys are ownership dimensions:
userId, or any scope namespace in canonicalscope:<namespace>form (e.g.scope:org,scope:client,scope:group); values are arrays of permitted values — the token can only access records whose dimension matches one of these values. Every non-null entity UUID must be a real entity in your account, and each dimension may be named only once. Include a JSONnullin the array (e.g.["uuid", null]) to ALSO grant access to records with no value in THAT dimension — an explicit per-dimension sentinel, NOT a wildcard. To grant access regardless of value, omit the key from the data scope entirely. -
dataScope
-
build
-
additionalProperty
-
additionalProperties
-