bijection permissions.
Permissions
A user is named by their token identifier, the
tokenIdentifier field of
their identity: the issuer and subject joined by |, as in
https://auth.example.com|user_123. See
Auth in Functions. It is not a
JWT.
Granting and revoking
true activates the permission and false revokes it.
set is sent once and not retried. If the command fails without confirming
the change, check the permission with bijection permissions status before
trying again.Checking a permission
Options
Each permission names exactly one kind of resource:
--operation for read,
invoke and preview, and --approval-resource for approve and
use_approval. Identifiers must be non-empty, at most 1024 bytes and free of
control characters.