Azure Integration built-in role

API Management Developer Portal Content Editor

Customizes, edits, and publishes API Management developer portal content through Azure Resource Manager. The published role contains control-plane Actions only and no DataActions; it does not provide general API, policy, or service-infrastructure administration.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: c031e6a8-4391-4de0-8d69-4706a7ed3729

Control-plane actions (8)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the individual API Management service whose developer portal the editor maintains. A resource-group or subscription assignment is inherited by every API Management service below it and broadens portal publishing authority accordingly.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign API Management Developer Portal Content Editor to the portal content group on the specific API Management service. Use Service Reader for service-wide observation and Service Contributor only when the same principal genuinely administers APIs and service infrastructure.

Related roles (2)

Common questions

When should I assign the API Management Developer Portal Content Editor Azure role?

Assign API Management Developer Portal Content Editor when you need to: Let a web-content team maintain and publish developer portal pages without granting API Management Service Contributor.; and Manage developer portal revisions and content items for one approved API Management instance.. Practical scope: Assign on the individual API Management service whose developer portal the editor maintains. A resource-group or subscription assignment is inherited by every API Management service below it and broadens portal publishing authority accordingly.

What permissions does the API Management Developer Portal Content Editor Azure role grant?

The role definition grants 8 combined control-plane and data-plane actions. Representative operations include: Microsoft.ApiManagement/service/portalRevisions/read; Microsoft.ApiManagement/service/portalRevisions/write; Microsoft.ApiManagement/service/contentTypes/read; Microsoft.ApiManagement/service/contentTypes/delete; Microsoft.ApiManagement/service/contentTypes/write; and Microsoft.ApiManagement/service/contentTypes/contentItems/read. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the API Management Developer Portal Content Editor Azure role?

Key considerations when assigning API Management Developer Portal Content Editor: Published portal content is customer- or developer-facing and can change how API consumers discover and use APIs.; and The role does not grant runtime API access or general API Management service administration, and it has no data-plane permissions.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →