Azure Integration built-in role

Azure API Center Service Reader

Reads API Center service resources, exports API specifications, and reads supporting authorization, deployment, and health metadata through the control plane. The published definition also includes classic alert-rule management, so it is read-only for API Center service assets rather than globally read-only. It has no DataActions and does not provide the portal search data path.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 6cba8790-29c5-48e5-bab1-c7541b01cb04

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual API center for resource-specific observation. Parent-scope assignments are inherited by every API center below them and broaden service metadata and specification visibility.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (2)

Assignment guidance

Assign Azure API Center Service Reader to resource observers on the individual API center. Add Data Reader only for approved portal consumers and use Service Contributor only for resource administration.

Related roles (2)

Editorial sources (6)

Official Microsoft Learn documentation →