Azure Integration built-in role

API Management Workspace API Developer

Reads workspace entities and creates or changes workspace API development resources, including APIs, policies, schemas, products, fragments, named values, backends, certificates, diagnostics, and loggers. Its named-value and backend wildcards include direct secret retrieval; the role has control-plane Actions only and requires a companion service-scoped workspace role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 56328988-075d-4c6a-8766-d93edd6725b6

Control-plane actions (17)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the API Management workspace where the developer edits APIs. The workspace assignment limits administrative access to that workspace, but the collaborator also needs API Management Service Workspace API Developer on the containing service.

Common use cases (2)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign API Management Workspace API Developer on one workspace and the matching Service Workspace API Developer role on the containing service. Use Workspace Reader for observation or Workspace API Product Manager when duties are limited to publishing and productization.

Related roles (3)

Common questions

When should I assign the API Management Workspace API Developer Azure role?

Assign API Management Workspace API Developer when you need to: Let an API development team create and maintain APIs and API-development entities inside its own workspace.; and Delegate API implementation while the central platform team retains service infrastructure administration.. Practical scope: Assign directly on the API Management workspace where the developer edits APIs. The workspace assignment limits administrative access to that workspace, but the collaborator also needs API Management Service Workspace API Developer on the containing service.

What permissions does the API Management Workspace API Developer Azure role grant?

The role definition grants 17 combined control-plane and data-plane actions. Representative operations include: Microsoft.ApiManagement/service/workspaces/*/read; Microsoft.ApiManagement/service/workspaces/apis/*; Microsoft.ApiManagement/service/workspaces/apiVersionSets/*; Microsoft.ApiManagement/service/workspaces/policies/*; Microsoft.ApiManagement/service/workspaces/schemas/*; and Microsoft.ApiManagement/service/workspaces/products/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the API Management Workspace API Developer Azure role?

Key considerations when assigning API Management Workspace API Developer: The role can change API behavior, policies, backends, certificates, logging, and other workspace entities. It directly includes named-value secret and backend-secret retrieval, and writes can reveal additional credentials in responses.; and Workspace isolation prevents references to resources in other workspaces, but selected service-level references still depend on the companion service role.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (8)

Official Microsoft Learn documentation →