Skip to content

Evaluates an example request against a CANDIDATE source and returns the three-valued decision chain: a matched permit GRANTS within scope, a matched forbid RESTRICTS, neither abstains (the RBAC decision stands).

POST
/v1/m/governance/pdp/explain
curl --request POST \
--url https://example.com/v1/m/governance/pdp/explain \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "engine": "example", "request": { "permission": "example", "principal": { "id": "example", "kind": "example" }, "resource": { "extra": { "additionalProperty": "example" }, "id": "example", "kind": "example", "sensitivity": "example" }, "tenant": "example" }, "source": "example" }'

Evaluates an example request against a CANDIDATE source and returns the three-valued decision chain: a matched permit GRANTS within scope, a matched forbid RESTRICTS, neither abstains (the RBAC decision stands).

X-Olivares-Tenant
string format: uuid

Target tenant id; required when the principal can act in more than one tenant.

Media type application/json
object
engine
required

Case-insensitive after trimming: cedar or opa.

string
request
Any of:
object
permission
Any of:

Whitespace is trimmed before evaluation.

string
principal
Any of:
object
id
Any of:

Optional credential identifier for the example principal.

string
kind
Any of:

After trimming, user remains user; every other value is evaluated as token.

string
resource
Any of:
object
extra
Any of:
object
key
additional properties
Any of:
string
id
Any of:

Example resource identifier.

string
kind
Any of:

Example resource kind.

string
sensitivity
Any of:

Example sensitivity attribute.

string
tenant
Any of:

A valid non-zero tenant overrides the authenticated tenant; invalid input falls back to it.

string
source
Any of:

Cedar must compile; OPA candidates are not evaluated in-process.

string
Example generated
{
"engine": "example",
"request": {
"permission": "example",
"principal": {
"id": "example",
"kind": "example"
},
"resource": {
"extra": {
"additionalProperty": "example"
},
"id": "example",
"kind": "example",
"sensitivity": "example"
},
"tenant": "example"
},
"source": "example"
}

OK

Media type application/json
object
Example generated
{}

Bad request

Media type application/json
object
Example generated
{}

Unauthenticated

Media type application/json
object
Example generated
{}

Forbidden

Media type application/json
object
Example generated
{}

Not found

Media type application/json
object
Example generated
{}

Conflict / setup required

Media type application/json
object
Example generated
{}

Rate limited

Media type application/json
object
Example generated
{}