Azure Integration built-in role

Azure API Center Data Reader

Provides API Center data-plane reads, workspace search, and API specification export for the API Center portal. It has DataActions only and does not manage the API Center resource through Azure Resource Manager.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: c7244dfb-f447-457d-b2ba-3999044d1706

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (3)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the API center whose catalog the principal may search. Resource-group and subscription assignments are inherited by all API centers below them and expose each inherited catalog through the data plane.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign Azure API Center Data Reader to the approved portal-user group directly on the API center. Keep API Center resource administration and analysis-state updates on separate roles.

Related roles (2)

Common questions

When should I assign the Azure API Center Data Reader Azure role?

Assign Azure API Center Data Reader when you need to: Allow an authenticated developer or stakeholder to sign in to the API Center portal and discover APIs in one catalog.; and Let an API Center administrator use the portal data path without granting service write access.. Practical scope: Assign directly on the API center whose catalog the principal may search. Resource-group and subscription assignments are inherited by all API centers below them and expose each inherited catalog through the data plane.

What permissions does the Azure API Center Data Reader Azure role grant?

The role definition grants 3 combined control-plane and data-plane actions. Representative operations include: Microsoft.ApiCenter/services/*/read; Microsoft.ApiCenter/services/workspaces/apis/versions/definitions/exportSpecification/action; and Microsoft.ApiCenter/services/workspaces/search/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure API Center Data Reader Azure role?

Key considerations when assigning Azure API Center Data Reader: The role exposes API catalog records, search results, and exportable API specifications through the data plane.; and It does not create or modify API Center resources and has no control-plane Actions.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →