Azure Integration built-in role

Azure API Center Service Reader

Reads API Center service resources, exports API specifications, and reads supporting authorization, deployment, and health metadata through the control plane. The published definition also includes classic alert-rule management, so it is read-only for API Center service assets rather than globally read-only. It has no DataActions and does not provide the portal search data path.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 6cba8790-29c5-48e5-bab1-c7541b01cb04

Control-plane actions (7)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual API center for resource-specific observation. Parent-scope assignments are inherited by every API center below them and broaden service metadata and specification visibility.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (2)

Assignment guidance

Assign Azure API Center Service Reader to resource observers on the individual API center. Add Data Reader only for approved portal consumers and use Service Contributor only for resource administration.

Related roles (2)

Common questions

When should I assign the Azure API Center Service Reader Azure role?

Assign Azure API Center Service Reader when you need to: Let an auditor or platform observer inspect an API Center resource and its catalog metadata without changing it.; and Support API Center troubleshooting that requires control-plane service and deployment visibility.. Practical scope: Assign on the individual API center for resource-specific observation. Parent-scope assignments are inherited by every API center below them and broaden service metadata and specification visibility.

What permissions does the Azure API Center Service Reader Azure role grant?

The role definition grants 7 combined control-plane and data-plane actions. Representative operations include: Microsoft.ApiCenter/services/*/read; Microsoft.ApiCenter/services/workspaces/apis/versions/definitions/exportSpecification/action; Microsoft.Authorization/*/read; Microsoft.Insights/alertRules/*; Microsoft.ResourceHealth/availabilityStatuses/read; and Microsoft.Resources/deployments/*/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure API Center Service Reader Azure role?

Key considerations when assigning Azure API Center Service Reader: The role can expose API specifications and API Center resource, deployment, alert, and availability metadata.; and It cannot modify API Center service assets or use API Center DataActions, but its supporting classic alert-rule wildcard is a write-capable control-plane permission.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →