Azure Integration built-in role

API Management Service Workspace API Developer

Provides the service-level half of an API Management workspace API developer assignment: it reads service tags, products, and authorization servers and can link workspace APIs and tags to service products. The role uses control-plane Actions only and must be paired with a workspace-scoped role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 9565a273-41b9-4368-97d2-aeb0c976a9b3

Control-plane actions (9)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the API Management service that contains the collaborator's workspace. This service-scoped assignment does not replace the required workspace-scoped API Management Workspace API Developer role; parent assignments are inherited by all contained services.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign API Management Service Workspace API Developer on the containing service and API Management Workspace API Developer on the specific workspace to the same collaborator or group. Add a gateway role only when the collaborator manages or views a dedicated workspace gateway.

Related roles (2)

Common questions

When should I assign the API Management Service Workspace API Developer Azure role?

Assign API Management Service Workspace API Developer when you need to: Allow a workspace API developer to associate workspace APIs with service-level products and tags.; and Enable a federated workspace team to reference the documented service-level resources needed by its API editing workflow.. Practical scope: Assign on the API Management service that contains the collaborator's workspace. This service-scoped assignment does not replace the required workspace-scoped API Management Workspace API Developer role; parent assignments are inherited by all contained services.

What permissions does the API Management Service Workspace API Developer Azure role grant?

The role definition grants 9 combined control-plane and data-plane actions. Representative operations include: Microsoft.ApiManagement/service/tags/read; Microsoft.ApiManagement/service/tags/apiLinks/*; Microsoft.ApiManagement/service/tags/operationLinks/*; Microsoft.ApiManagement/service/tags/productLinks/*; Microsoft.ApiManagement/service/products/read; and Microsoft.ApiManagement/service/products/apiLinks/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the API Management Service Workspace API Developer Azure role?

Key considerations when assigning API Management Service Workspace API Developer: The role can change API-to-product and tag relationships at service level, affecting API organization and product exposure.; and It does not by itself grant permission to edit workspace APIs or manage the service infrastructure, and it has no DataActions.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →