Intron Connect

Roles

Developer, Operator, Admin — mapped from IdP groups.

Connect authorizes with three roles. Authentik (or any OIDC IdP) groups are mapped by CONNECT_OIDC_ROLE_MAP. Unmapped groups grant nothing.

RoleTypical groupsCan
Developerintron-developersRead catalog, runs, hops. Call Experience GETs
Operatorintron-operatorsStart, Review, Cancel, register webhooks and consumers, publish
Adminintron-administratorsStop, restart, rollback, redrive, rotate keys, retire, delete

Unauthorized callers receive 401. Authenticated callers lacking a role receive 403.

Policy (short)

ResourceDeveloperOperatorAdmin
GET /api/**yesyesyes
POST/PUT/PATCH product APIsnoyesyes
DELETEnonoyes
/api/v1/ops/**readoperateadminister

HMAC webhook ingest is not role-based. Portal groups map the same roles.

If this fails

SymptomCause
Logged in, 403 everywhereGroup not in CONNECT_OIDC_ROLE_MAP
admin group does nothingBare admin is ignored unless mapped as a source

Next: Open the portal · Security

On this page