Azure Integration built-in role
API Management Workspace API Developer
Reads workspace entities and creates or changes workspace API development resources, including APIs, policies, schemas, products, fragments, named values, backends, certificates, diagnostics, and loggers. Its named-value and backend wildcards include direct secret retrieval; the role has control-plane Actions only and requires a companion service-scoped workspace role.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 56328988-075d-4c6a-8766-d93edd6725b6
Control-plane actions (17)
Microsoft.ApiManagement/service/workspaces/*/readMicrosoft.ApiManagement/service/workspaces/apis/*Microsoft.ApiManagement/service/workspaces/apiVersionSets/*Microsoft.ApiManagement/service/workspaces/policies/*Microsoft.ApiManagement/service/workspaces/schemas/*Microsoft.ApiManagement/service/workspaces/products/*Microsoft.ApiManagement/service/workspaces/policyFragments/*Microsoft.ApiManagement/service/workspaces/namedValues/*Microsoft.ApiManagement/service/workspaces/tags/*Microsoft.ApiManagement/service/workspaces/backends/*Microsoft.ApiManagement/service/workspaces/certificates/*Microsoft.ApiManagement/service/workspaces/diagnostics/*Microsoft.ApiManagement/service/workspaces/loggers/*Microsoft.Authorization/*/readMicrosoft.Insights/diagnosticSettings/*/readMicrosoft.insights/logs/readMicrosoft.insights/logs/ApiManagementGatewayLogs/read
Data-plane actions (0)
None — this role grants no data-plane (data access) actions.
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
Assign directly on the API Management workspace where the developer edits APIs. The workspace assignment limits administrative access to that workspace, but the collaborator also needs API Management Service Workspace API Developer on the containing service.
Common use cases (2)
- Let an API development team create and maintain APIs and API-development entities inside its own workspace.
- Delegate API implementation while the central platform team retains service infrastructure administration.
Prerequisites (2)
- The workspace must exist, and the collaborator must also receive API Management Service Workspace API Developer on the containing service.
- The team must be approved to retrieve named-value and backend secrets and must have a secret-handling process for all credential-bearing workspace entities.
Best practices (2)
- Assign to a workspace-specific Microsoft Entra group and keep central service management with the platform team.
- Protect and rotate named-value and backend secrets returned by the documented list-value and list-secrets operations, and treat other credential-bearing entity writes as sensitive.
Security considerations (2)
- The role can change API behavior, policies, backends, certificates, logging, and other workspace entities. It directly includes named-value secret and backend-secret retrieval, and writes can reveal additional credentials in responses.
- Workspace isolation prevents references to resources in other workspaces, but selected service-level references still depend on the companion service role.
Assignment guidance
Assign API Management Workspace API Developer on one workspace and the matching Service Workspace API Developer role on the containing service. Use Workspace Reader for observation or Workspace API Product Manager when duties are limited to publishing and productization.
Related roles (3)
- API Management Service Workspace API Developer: The required service-scoped companion for service products, tags, and supported service references.
- API Management Workspace API Product Manager: Focuses on publishing and productizing APIs rather than API implementation.
- API Management Workspace Reader: Provides read-only workspace visibility.
Editorial sources (8)
- Azure built-in roles for Integration - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices. Retrieved 2026-07-17.
- Federated API management with workspaces →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- How to use role-based access control in Azure API Management →
Supports: Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Permissions for Integration - Microsoft.ApiManagement →
Supports: Description, Prerequisites, Best practices, Security considerations. Retrieved 2026-07-17.