{"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"rbac","__idx":0},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["rbac"]}]},{"$$mdtype":"Tag","name":"ConfigOptionRequirements","attributes":{"products":["Redoc","Revel","Reef","Realm"],"plans":["Enterprise","Enterprise+"]},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use team-based access controls to assign permissions required to files and project access."," ","Access control is done using ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/access/rbac"},"children":["RBAC (role-based access control)"]},"."," ","By default, all authenticated users are assigned to the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authenticated"]}," team, and unauthenticated users are automatically assigned to the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["anonymous"]}," team."," ","All other configuration is done through team-role mapping."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"options","__idx":1},"children":["Options"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"configuration-map","__idx":2},"children":["Configuration map"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Option"},"children":["Option"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["reunite"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#team-to-role-map"},"children":["Map[string, string]"]},"]"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Map of teams to roles."," ","Use this option when needs to manage project access to a specific team, like allowing the team to manage branches or builds."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["content"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["[",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#content-configuration"},"children":["Content configuration"]},"]"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Describes file access for the given team."," ","Use this option when needs to manage file access to a specific team."," ","This option is used for page access as well."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["features"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["[",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#features-configuration"},"children":["Features configuration"]},"]"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Describes feature access by team."," ","Use this option when you need to manage access for specific features."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["teamFolders"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["[",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#team-folder"},"children":["Team folder"]},"]"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Use with pattern-based access to describe the folders that can be accessed in this way."," ","Only folders listed here can have access granted through pattern-based access."," ","This option is used in combination with the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["teamNamePatterns"]}," option."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["teamFoldersBaseRoles"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["[",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#team-to-role-map"},"children":["Team to role map"]},"]"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Default access for named teams to the folders defined in the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["teamFolders"]}," list."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["teamNamePatterns"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["[",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#team-name-pattern"},"children":["Team name pattern"]},"]"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Team name pattern for giving pattern-based access to the folders in ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["teamFolders"]},"."," ","This option is used in combination with the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["teamFolders"]}," option."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"team-to-role-map","__idx":3},"children":["Team to role map"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Option"},"children":["Option"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"em","attributes":{},"children":["team name"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["none"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["read"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["write"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["triage"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["maintain"]},", or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["admin"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Map of teams to project roles."," ","The team names include ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["anonymous"]}," (meaning all users who are not logged in) and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authenticated"]}," (meaning any user who is logged in)."," ","Team names can also come from the identity provider through the ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/access/sso"},"children":["single-sign-on (SSO) configuration"]},"."," ","In addition, the team name ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["*"]}," represents the rest of the teams not defined in sibling properties including ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["anonymous"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authenticated"]},"."," ","Possible values for project roles are: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["none"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["read"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["write"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["triage"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["maintain"]},", or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["admin"]},".",{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["rbac"]}," option also supports page-level configuration using front matter."]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"content-configuration","__idx":4},"children":["Content configuration"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Option"},"children":["Option"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"em","attributes":{},"children":["{glob pattern}*"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#team-to-role-map"},"children":["Map[string, string]"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Use a glob pattern linked to a map of teams and roles to define specific page access."," ","Use the unique key ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["**"]}," to describe all pages."]}]}]}]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Wildcard key"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When describing team to project role relations, you can use a special key ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["*"]},"."," ","A project role assigned to that key is applied to the rest of the teams that are not described for the given glob pattern."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the following example, only users assigned to the Admin team can view the content on the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["secrets.md"]}," file:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","header":{"controls":{"copy":{}}},"source":"rbac:\n  content:\n    secrets.md:\n      'Admin': read\n","lang":"yaml"},"children":[]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"features-configuration","__idx":5},"children":["Features configuration"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Option"},"children":["Option"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["aiSearch"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Map",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#team-to-role-map"},"children":["string, string"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Map of teams to roles to define the team and role for AI search feature access."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["mcp"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Map",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#team-to-role-map"},"children":["string, string"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Map of teams to roles to define the team and role for MCP server access."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"team-folder","__idx":6},"children":["Team folder"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Option"},"children":["Option"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["teamPathSegment"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Team folder pattern."," ","The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["{teamPathSegment}"]}," segment is used as the path segment."," ","Example: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/some/path/_{teamPathSegment}_"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"team-name-pattern","__idx":7},"children":["Team name pattern"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Option"},"children":["Option"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["PREFIX-",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["{teamPathSegment}-{projectRole}"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["string"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The format that the team name follows."," ","The prefix is optional but can be useful if you have many teams."," ","The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["{teamPathSegment}"]}," is used as the path segment where the role access is applied,"," ","and the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["{projectRole}"]}," part sets the access level."," ","The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["{teamPathSegment}"]}," segments are transformed to lower case."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"examples","__idx":8},"children":["Examples"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"use-the-access-object-recommended","__idx":9},"children":["Use the access object (recommended)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The recommended way to configure ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["rbac"]}," is within the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["access"]}," object:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","data-title":"redocly.yaml","header":{"title":"redocly.yaml","controls":{"copy":{}}},"source":"access:\n  rbac:\n    content:\n      '**':\n        authenticated: read\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"root-level-configuration-deprecated","__idx":10},"children":["Root-level configuration (deprecated)"]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Deprecated configuration"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Root-level ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["rbac"]}," configuration displays warnings when the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["access"]}," object is present."," ","Migrate to the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["access"]}," object format."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"file-access","__idx":11},"children":["File access"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the following example, default team permissions are assigned"," ","to all pages that do not match any other glob patterns."," ","Different permissions are assigned to the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["developer-keys.md"]}," page,"," ","the pages in the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/secret/chapter"]}," folder, and any TypeScript (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":[".tsx"]},") pages:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","data-title":"redocly.yaml","header":{"title":"redocly.yaml","controls":{"copy":{}}},"source":"access:\n  rbac:\n    content:\n      '**':\n        Admin: admin\n        Developer: maintain\n        Employee: read\n        authenticated: read\n      developer-keys.md:\n        Developer: read\n      '/secret/chapter':\n        Admin: write\n        Developer: read\n        Employee: read\n      '**/*.tsx':\n        Developer: write\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"project-access","__idx":12},"children":["Project access"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the following example, only the Developer team can create a branch, create a pull request, or create a deployment."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","data-title":"redocly.yaml","header":{"title":"redocly.yaml","controls":{"copy":{}}},"source":"access:\n  rbac:\n    reunite:\n      Developer: write\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"complete-rbac-setup","__idx":13},"children":["Complete RBAC setup"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following example shows a comprehensive RBAC configuration with project access, content access, environment variables, and authentication requirements:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","data-title":"redocly.yaml","header":{"title":"redocly.yaml","controls":{"copy":{}}},"source":"access:\n  rbac:\n    # Project administration access\n    reunite:\n      Developers: write\n      Writers: read\n      Admin: admin\n    \n    # File and content access\n    content:\n    # Default permissions for all files\n    '**':\n      Developers: maintain\n      Writers: write\n      authenticated: read\n    \n    # Specific permissions for sensitive files\n    'security/*.md':\n      Admin: admin\n      Developers: read\n    \n    # API documentation access\n    'apis/**':\n      Developers: write\n      Writers: read\n\n  # Feature access\n  features:\n    aiSearch:\n      authenticated: read\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"use-environment-variables","__idx":14},"children":["Use environment variables"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Environment variables can be used for role assignments, useful for different deployment environments:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","data-title":"redocly.yaml","header":{"title":"redocly.yaml","controls":{"copy":{}}},"source":"access:\n  rbac:\n    reunite:\n      Writers: '{{process.env.RBAC_WRITERS_ROLE}}'\n      Developers: '{{process.env.RBAC_DEVELOPERS_ROLE}}'\n    content:\n      '**':\n        Developers: '{{process.env.RBAC_DEFAULT_ROLE}}'\n        authenticated: read\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"require-authentication","__idx":15},"children":["Require authentication"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To require users to log in before viewing any content:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","data-title":"redocly.yaml","header":{"title":"redocly.yaml","controls":{"copy":{}}},"source":"access:\n  rbac:\n    content:\n      '**':\n        authenticated: read\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This configuration directs users to a login page where they can authenticate using configured identity providers."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"pattern-based-access","__idx":16},"children":["Pattern-based access"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Define the folders and the patterns that the team names match."," ","The following is an example configuration; the curly braces ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["{"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["}"]}," and the placeholder names are shown as they should be used in a configuration file."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","header":{"controls":{"copy":{}}},"source":"  teamFolders:\n    - /docs/{teamPathSegment}\n    - /apis/{teamPathSegment}\n  teamNamePatterns:\n    - REDOCLY-{teamPathSegment}-{projectRole}\n    - BUSINESS-{teamPathSegment}-{projectRole}\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Given the above configuration and the following list of team names:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["REDOCLY-PEARL-triage"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["REDOCLY-PEARL-admin"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["BUSINESS-AMETHYST-maintain"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The effective access control settings would be like the following example configuration:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","data-title":"redocly.yaml","header":{"title":"redocly.yaml","controls":{"copy":{}}},"source":"access:\n  rbac:\n    reunite:\n      REDOCLY-PEARL-triage: triage\n      REDOCLY-PEARL-admin: admin\n      BUSINESS-AMETHYST-maintain: maintain\n    content:\n      '/docs/pearl/**':\n        REDOCLY-PEARL-triage: triage\n        REDOCLY-PEARL-admin: admin\n        authenticated: read\n      '/apis/pearl/**':\n        REDOCLY-PEARL-triage: triage\n        REDOCLY-PEARL-admin: admin\n        authenticated: read\n      '/docs/amethyst/**':\n        BUSINESS-AMETHYST-maintain: maintain\n        authenticated: read\n      '/apis/amethyst/**':\n        BUSINESS-AMETHYST-maintain: maintain\n        authenticated: read\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"feature-access","__idx":17},"children":["Feature access"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the following example, anonymous users have no access to the AI search feature,"," ","while authenticated users can access the AI search feature."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","data-title":"redocly.yaml","header":{"title":"redocly.yaml","controls":{"copy":{}}},"source":"access:\n  rbac:\n    features:\n      aiSearch:\n        authenticated: read\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Access to the MCP server is controlled the same way through the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mcp"]}," feature."," ","In the following example, only members of the Developers team can access the MCP server, while all other users are denied access."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","data-title":"redocly.yaml","header":{"title":"redocly.yaml","controls":{"copy":{}}},"source":"access:\n  rbac:\n    features:\n      mcp:\n        Developers: read\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When a team-based role is set for the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mcp"]}," feature, only teams with a role other than ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["none"]}," can access the MCP server."," ","Users must sign in unless the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["anonymous"]}," team is granted such a role, either directly or through the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["*"]}," wildcard."," ","The wildcard covers all teams that are not listed explicitly, including ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["anonymous"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"disallow-access-to-one-specific-page","__idx":18},"children":["Disallow access to one specific page"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the following example, members of the Developers team can access Markdown files in the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/security"]}," folder, except ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["top-secret.md"]},"."," ","That file has the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["none"]}," value for Developers in its front matter."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","data-title":"redocly.yaml","header":{"title":"redocly.yaml","controls":{"copy":{}}},"source":"access:\n  rbac:\n    content:\n      'security/*.md':\n          Admin: admin\n        Developers: read\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"md","data-title":"security/top-secret.md","header":{"title":"security/top-secret.md","controls":{"copy":{}}},"source":"---\nrbac:\n  Admin: admin\n  Developers: none\n---\n","lang":"md"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"resources","__idx":19},"children":["Resources"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/access/rbac"},"children":["Role-based access control"]}]}," - Understand the fundamentals and components of RBAC systems for comprehensive access management"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/access"},"children":["Control site access"]}]}," - Complete implementation guide with examples for projects, pages, and navigation access control"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/front-matter-config"},"children":["Front matter configuration options"]}]}," - Configure role-based access on individual pages using front matter for granular permission control"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config"},"children":["Configuration options"]}]}," - Explore other project configuration options for comprehensive documentation and platform customization"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/access/sso"},"children":["SSO configuration"]}]}," - Configure single sign-on to identify users and integrate with RBAC for comprehensive authentication and authorization"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/ssodirect"},"children":["SSO Direct configuration"]}]}," - Configure direct SSO integration for streamlined user identification and RBAC implementation"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/access/requires-login"},"children":["Requires login configuration"]}]}," - Set up login requirements to enforce authentication before accessing RBAC-protected content"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/customization/mcp-server#restrict-access-to-the-mcp-server"},"children":["Restrict access to the MCP server"]}]}," - Grant MCP server access only to specific teams with the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mcp"]}," feature role"]}]}]},"frontmatter":{"products":["Redoc","Revel","Reef","Realm"],"plans":["Enterprise","Enterprise+"],"description":"Use team-based access controls to assign permissions required to files and project access."},"tagList":["admonition","configOptionRequirements","html","partial","table"],"title":"rbac","lastModified":"2026-10-01T23:00:57.000Z"}