/v1/auth/effectiveExplain an effective authorization decision
operation ID: post_v1_auth_effective
Overview
Explain an effective authorization decision. The authentication API establishes identity and manages the roles, grants, sessions, and service credentials used for authorization.
When to use it
- Use it when an application needs to explain an effective authorization decision.
- Use it when a client needs to sign in, inspect its identity, or an administrator needs to manage access.
Quick example
Set the base URL and replace generated identifiers or credentials with values from your installation.
cURL
curl --request POST \
--url "$ORDINATE_URL/v1/auth/effective" \
--header "Authorization: Bearer $ORDINATE_TOKEN" \
--header "Content-Type: application/json" \
--data '{
"capability": "read",
"scope_kind": "site",
"scope_id": "00000000-0000-4000-8000-000000000001"
}'Expected output · 200
Decision from the same evaluator used for enforcement
Example 200 output
{
"allowed": false,
"derivation": [
{}
],
"snapshot_built_at_ns": 0
}The cURL request sends the smallest contract-derived body and asks OrdinateDB to explain an effective authorization decision. The documented 200 response is decision from the same evaluator used for enforcement.
How it works
OrdinateDB resolves a session or bearer credential to a principal, then evaluates roles, capabilities, and resource scope for each protected operation.
Reference
- Required capability
- authenticated
- Authorization scope
- self, or any principal with admin
Parameters
No parameters.
Request body
application/json
as_of_nsintegeroptionalUTC Unix timestamp in nanoseconds
format: int64capabilityCapabilityrequiredCapabilitystringvalues: read · annotate · enter · approve · amend · model-edit · registry-manage · calc-author · display-author · display-publish · episode-manage · redact · admin
principalany ofoptionalany of
option 1
PrincipalStringstringGrant-subject grammar: system, user UUID, service UUID, or an IdP group name.
pattern: ^(system|(user|svc):[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}|group:.+)$option 2
nullscope_idstringrequired- format: uuid
scope_kindstringrequired
Example request body
{
"capability": "read",
"scope_kind": "site",
"scope_id": "00000000-0000-4000-8000-000000000001"
}Responses
200Decision from the same evaluator used for enforcement
application/json
allowedbooleanrequiredderivationarrayrequiredarray
object with arbitrary properties
group_membershipstringoptionalsnapshot_built_at_nsintegerrequiredUTC Unix timestamp in nanoseconds
format: int64
Example 200 output
{
"allowed": false,
"derivation": [
{}
],
"snapshot_built_at_ns": 0
}400Invalid decision request
application/json
ErrorEnvelope
codestringrequiredcorrelation_idstringrequired- format: uuid
detailsobjectoptionalerrorstringrequired
Example 400 output
{
"error": "string",
"code": "account-sealed",
"correlation_id": "00000000-0000-4000-8000-000000000001"
}401Authentication required
application/json
ErrorEnvelope
codestringrequiredcorrelation_idstringrequired- format: uuid
detailsobjectoptionalerrorstringrequired
Example 401 output
{
"error": "string",
"code": "account-sealed",
"correlation_id": "00000000-0000-4000-8000-000000000001"
}403Admin capability required for another principal
application/json
ErrorEnvelope
codestringrequiredcorrelation_idstringrequired- format: uuid
detailsobjectoptionalerrorstringrequired
Example 403 output
{
"error": "string",
"code": "account-sealed",
"correlation_id": "00000000-0000-4000-8000-000000000001"
}503Model database is not configured
application/json
ErrorEnvelope
codestringrequiredcorrelation_idstringrequired- format: uuid
detailsobjectoptionalerrorstringrequired
Example 503 output
{
"error": "string",
"code": "account-sealed",
"correlation_id": "00000000-0000-4000-8000-000000000001"
}Code examples
These examples are generated from the source contract. Replace the base URL, credentials, identifiers, and minimal generated values for your instance.
JavaScript
const ordinateUrl = "http://localhost:8080";
const token = "<bearer-token>";
const response = await fetch(`${ordinateUrl}/v1/auth/effective`, {
method: "POST",
headers: {
Authorization: `Bearer ${token}`,
"Content-Type": "application/json"
},
body: JSON.stringify({
"capability": "read",
"scope_kind": "site",
"scope_id": "00000000-0000-4000-8000-000000000001"
})
});
if (!response.ok) {
throw new Error(`OrdinateDB returned ${response.status}: ${await response.text()}`);
}
const data = await response.json();
console.log(data);Related topics
- Authentication guide — Understand the prerequisite concepts and transport behavior for this operation.
- REST endpoint index — Find other operations in Authentication.