Roles
Developer, Operator, Admin — mapped from IdP groups.
Connect authorizes with three roles. Authentik (or any OIDC IdP) groups are mapped by CONNECT_OIDC_ROLE_MAP. Unmapped groups grant nothing.
| Role | Typical groups | Can |
|---|---|---|
| Developer | intron-developers | Read catalog, runs, hops. Call Experience GETs |
| Operator | intron-operators | Start, Review, Cancel, register webhooks and consumers, publish |
| Admin | intron-administrators | Stop, restart, rollback, redrive, rotate keys, retire, delete |
Unauthorized callers receive 401. Authenticated callers lacking a role receive 403.
Policy (short)
| Resource | Developer | Operator | Admin |
|---|---|---|---|
GET /api/** | yes | yes | yes |
| POST/PUT/PATCH product APIs | no | yes | yes |
| DELETE | no | no | yes |
/api/v1/ops/** | read | operate | administer |
HMAC webhook ingest is not role-based. Portal groups map the same roles.
If this fails
| Symptom | Cause |
|---|---|
| Logged in, 403 everywhere | Group not in CONNECT_OIDC_ROLE_MAP |
admin group does nothing | Bare admin is ignored unless mapped as a source |
Next: Open the portal · Security