Azure Integration built-in role

Azure API Center Data Reader

Provides API Center data-plane reads, workspace search, and API specification export for the API Center portal. It has DataActions only and does not manage the API Center resource through Azure Resource Manager.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: c7244dfb-f447-457d-b2ba-3999044d1706

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (3)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the API center whose catalog the principal may search. Resource-group and subscription assignments are inherited by all API centers below them and expose each inherited catalog through the data plane.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure API Center Data Reader to the approved portal-user group directly on the API center. Keep API Center resource administration and analysis-state updates on separate roles.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →