Azure Integration built-in role
Azure API Center Service Reader
Reads API Center service resources, exports API specifications, and reads supporting authorization, deployment, and health metadata through the control plane. The published definition also includes classic alert-rule management, so it is read-only for API Center service assets rather than globally read-only. It has no DataActions and does not provide the portal search data path.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 6cba8790-29c5-48e5-bab1-c7541b01cb04
Control-plane actions (7)
Microsoft.ApiCenter/services/*/readMicrosoft.ApiCenter/services/workspaces/apis/versions/definitions/exportSpecification/actionMicrosoft.Authorization/*/readMicrosoft.Insights/alertRules/*Microsoft.ResourceHealth/availabilityStatuses/readMicrosoft.Resources/deployments/*/readMicrosoft.Resources/subscriptions/resourceGroups/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign on the individual API center for resource-specific observation. Parent-scope assignments are inherited by every API center below them and broaden service metadata and specification visibility.
Common use cases (2)
- Let an auditor or platform observer inspect an API Center resource and its catalog metadata without changing it.
- Support API Center troubleshooting that requires control-plane service and deployment visibility.
Prerequisites (2)
- The API center to inspect must already exist.
- Assign Data Reader separately if the principal must sign in to the API Center portal and use its data-plane search experience.
Best practices (3)
- Assign directly on one API center and use Service Contributor only when changes are required.
- Keep portal data-plane access separate so control-plane observers do not automatically receive catalog search access.
- Avoid parent scope when the reader should not manage classic alert rules for unrelated resources.
Security considerations (2)
- The role can expose API specifications and API Center resource, deployment, alert, and availability metadata.
- It cannot modify API Center service assets or use API Center DataActions, but its supporting classic alert-rule wildcard is a write-capable control-plane permission.
Assignment guidance
Assign Azure API Center Service Reader to resource observers on the individual API center. Add Data Reader only for approved portal consumers and use Service Contributor only for resource administration.
Related roles (2)
- Azure API Center Service Contributor: Adds API Center service changes while retaining the separate data-plane and analysis-state boundaries described for this role family.
- Azure API Center Data Reader: Provides portal search and API catalog reads through the data plane.
Editorial sources (6)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations, Related roles. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Set up and customize your API Center portal →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.