Class AccessProfileRequest

java.lang.Object
ai.vectros.types.AccessProfileRequest

public final class AccessProfileRequest extends Object
  • Method Details

    • getPrincipalId

      public String getPrincipalId()
      Returns:
      Principal this profile applies to. Must start with usr_ (an authenticated user — the suffix is the user id) or key_ (a scoped API key acting as its own principal — the suffix is the key id). The suffix may contain only letters, digits, underscores, and hyphens. Required when creating (POST); ignored when updating (PUT), where it is taken from the path.
    • getScopes

      public Optional<List<ScopeClause>> getScopes()
      Returns:
      Inline scope clauses to grant the principal. Provide exactly one of scopes or roleIds — setting both, or neither, returns a 400.
    • getRoleIds

      public Optional<List<String>> getRoleIds()
      Returns:
      References to one or more roles within the same context that together supply this principal's scopes. The effective grant is each named role's own clauses, concatenated in the order you list them — roles are composed additively, never merged, so each clause keeps meaning exactly what its own author wrote. Provide exactly one of scopes or roleIds — setting both, or neither, returns a 400. Every id must name a role that exists in this same app context, and no id may repeat. Changes to a role's scopes take effect for all referencing profiles.

      Composition also decides what POST /v1/auth/token/assume will let this principal become: that check is made against ONE role's own assumable grant at a time, never against the combination, so listing two roles never creates an entitlement neither role granted on its own.

    • getRoleId

      public Optional<String> getRoleId()
      Returns:
      Deprecated single-role form of roleIds, accepted for backward compatibility and equivalent to roleIds: ["<value>"]. Setting both is a 400 — send roleIds alone. Reads always return roleIds; roleId is also returned, but only when exactly one role composes.
    • getIdentityOverrides

      public Optional<Map<String,Object>> getIdentityOverrides()
      Returns:
      Optional per-context identity overrides, keyed by ownership namespace in scope:<namespace> form — scope:org and scope:client for the reserved namespaces, or any namespace you have registered (for example scope:group). At most two namespaces may be overridden; any other key is rejected. Each value is 1-128 characters: a letter or digit first, then letters, digits, _ or -. Omitting the field leaves any existing overrides unchanged; sending an empty map clears them, and sending a populated map replaces them wholesale — a namespace absent from the map you send is removed. If you use a scoped credential, two bounds apply and either returns 403: you may only set a value your own identity holds, and you may only change or clear a value the profile already holds if that value is yours as well — so clearing or repointing another principal's established identity is refused. A root API key (sk_) is exempt from both.
    • getAssumable

      public Optional<Map<String,Object>> getAssumable()
      Returns:
      The POST /v1/auth/token/assume entitlement grant: which values, per scope:<namespace>, a holder of THIS profile may assume via /assume. Only meaningful (and only accepted) alongside inline scopes — a roleId-referencing profile has no clause list of its own to pair a grant with; author the grant on the referenced Role instead, where every profile referencing that role picks it up uniformly. The principal (userId) can never be named — it is never assumable. Each value list accepts a plain literal, ${{ under.self.userId }}, or ${{ member.scope.<namespace>[:level] }} — never ${{ under.self.scope.<namespace> }} (it resolves against the caller's CURRENT value for a namespace /assume can itself change, so what it admitted would depend on what was last assumed; that form stays valid in data_scope, where it's re-derived per write), a bare ${{ self.<dim> }}, or ${{ any }}, all rejected at authoring time. Omitting the field grants no assumption of anything, the safe default.
    • getStatus

      public Optional<AccessProfileRequestStatus> getStatus()
      Returns:
      Profile lifecycle status. active permits token minting; suspended denies it (minting returns a uniform 403). Defaults to active when omitted.
    • equals

      public boolean equals(Object other)
      Overrides:
      equals in class Object
    • getAdditionalProperties

      public Map<String,Object> getAdditionalProperties()
    • hashCode

      public int hashCode()
      Overrides:
      hashCode in class Object
    • toString

      public String toString()
      Overrides:
      toString in class Object
    • builder

      public static AccessProfileRequest.PrincipalIdStage builder()