Azure Web and Mobile built-in role

SignalR REST API Owner

Provides full access to the Azure SignalR data-plane REST APIs for hubs, groups, users, and client connections, including client-token generation. It has no control-plane Actions and does not create app-server connections or provide the app-server negotiation workflow.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: fd53cd77-2268-407a-8f46-7e7863d0f521

Control-plane actions (0)

None — this role grants no control-plane management actions.

Data-plane actions (5)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign directly on the Azure SignalR Service resource whose clients and groups the principal manages. A resource-group, subscription, or management-group assignment is inherited by every SignalR resource below it.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign SignalR REST API Owner to the management application identity directly on one SignalR resource. Use REST API Reader for monitoring, App Server for Default-mode server connections, and Service Owner only for the documented Serverless negotiation workflow that needs both REST and authentication APIs.

Related roles (3)

Editorial sources (6)

Official Microsoft Learn documentation →