Skip to main content
Offline Cedar exports of a completed access model. Supplied rows and identities are comparison inputs, never proof of current authority.

Type Aliases

AccessCedarPolicies

Ƭ AccessCedarPolicies: Object A model compiled to Cedar: a schema in Cedar’s schema syntax, one template per role and the static policies, all in Cedar’s policy syntax. They depend on the declaration only.

Type declaration


AccessCedarUid

Ƭ AccessCedarUid: Object A Cedar entity reference in Cedar’s JSON format.

Type declaration


AccessCedarEntities

Ƭ AccessCedarEntities: Object The Cedar data a world of rows determines, in Cedar’s JSON formats: the entities, one template per tenant-defined role and scope, and one template link per live grant or directory row.

Type declaration

Functions

cedarPolicies

▸ cedarPolicies(access): AccessCedarPolicies Serialize the model’s schema, role templates and static policies.

Parameters

Returns

AccessCedarPolicies

cedarEntities

▸ cedarEntities(access, tables, now, coverage?): AccessCedarEntities Serialize the entities and live grant links implied by rows at now. Source-backed directory rows require their explicit coverage evidence. Export does not authenticate the inputs or read deployment state.

Parameters

Returns

AccessCedarEntities

cedarContext

▸ cedarContext(access, identity): Record<string, unknown> Encode the model’s declared claims and request narrowing for an identity. The model is required: claim defaults and resource scopes depend on it. This transformation never authenticates or impersonates the identity.

Parameters

Returns

Record<string, unknown>