How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Lakekeeper Permissions Cedar API

Cedar Authorization Management. Only available if Cedar authorization is enabled.

Lakekeeper Permissions Cedar API is one of 13 APIs that Lakekeeper publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include permissions-cedar. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, authentication docs, and pricing.

This API exposes 5 operations across 5 paths, and defines 23 schemas. It is described by OpenAPI 3.2.0, at version 0.0.0.

Requests are made against a single base URL, {scheme}://{host}{basePath}.

5 operations 5 paths 23 schemas 3 GET2 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
0.0.0
Base URL
{scheme}://{host}/management/v1
Authentication
HTTP Bearer
License
Vakamo Enterprise License
Resource Areas
1

Authentication & Security 1

Lakekeeper Permissions Cedar API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (JWT) (bearerAuth). By default, every request must be authenticated.

Paths & Operations 5

Across 5 paths, the API surfaces 5 operations — 3 GET, 2 POST. Each is listed below with its method, path, parameters, and response codes.

permissions-cedar 5

Cedar Authorization Management. Only available if Cedar authorization is enabled.

GET
/management/v1/permissions/cedar/entity-sources
Get information about active cedar entity sources
list_cedar_entity_sources → 200
POST
/management/v1/permissions/cedar/policy-list
Get active Cedar policies
list_cedar_policies body → 200
GET
/management/v1/permissions/cedar/policy-sources
Get information about active cedar policy sources
list_cedar_policy_sources → 200
POST
/management/v1/permissions/cedar/resolve-entities
Resolve Cedar entities for a given resource, returning the full entity hierarchy that would be used in an authorization decision.
resolve_cedar_entities body → 2004XX
GET
/management/v1/permissions/cedar/schema
Get the currently active Cedar schema.
get_cedar_schema → 200

Schemas 23

The contract defines 23 schemas that model the data the API accepts and returns. The most detailed are CedarResourceTypeFilter (10 properties), ListCedarPoliciesQuery (6 properties), ErrorModel (4 properties), CedarPrincipalTypeFilter (3 properties). Each schema is shown below with its type and property counts.

ResolveCedarEntitiesRequest
object
Request body for resolving Cedar entities.
2 properties 1 required
CedarEntitySourceInfo
object
3 properties 3 required
CedarResourceConstraintPattern
object
Constraint patterns for filtering policies by resource constraint type. Each field corresponds to a Cedar resource constraint pattern.
3 properties
IcebergErrorResponse
object
JSON wrapper for all error responses (non-2xx)
1 property 1 required
ResolveCedarEntitiesResponse
object
Response from resolving Cedar entities.
2 properties 2 required
CedarEffectFilter
string
UserOrRole
Identifies a user or a role
CedarPrincipalConstraintPattern
object
Constraint patterns for filtering policies by principal constraint type. Each field corresponds to a Cedar principal constraint pattern.
3 properties
ListCedarPoliciesQuery
object
Query parameters for listing Cedar policies. Pagination Consistency When using pagination with pagetoken, list continuation is only consistent if policy source…
6 properties
CedarSourceConfig
GetCedarPoliciesResponse
object
2 properties 1 required
CedarPrincipalTypeFilter
object
Filter for Cedar policy principal constraints. This filter allows fine-grained control over which policies to retrieve based on their principal scope. Each pri…
3 properties
CedarResourceTypeFilter
object
Filter for Cedar policy resource constraints. This filter allows fine-grained control over which policies to retrieve based on their resource scope. Each resou…
10 properties
CedarFileSourceConfig
object
1 property 1 required
ListCedarEntitySourcesResponse
object
1 property 1 required
GetCedarSchemaResponse
object
1 property 1 required
ErrorModel
object
JSON error payload returned in a response with further details on the error
4 properties 3 required
CedarResolveResource
Identifies the resource whose Cedar entity hierarchy should be resolved. Mirrors the shape of CatalogActionCheckOperation used by the batch-check endpoint — ex…
CedarKubernetesConfigMapSourceConfig
object
1 property 1 required
ListCedarPolicySourcesResponse
object
1 property 1 required
CedarPolicySourceInfo
object
3 properties 3 required
TabularIdentOrUuid
Identifier for a tabular (table, view, or generic table) — either a UUID or its name and namespace. Wire format primary names are table-id and table; viewid /…
NamespaceIdentOrUuid
Identifier for a namespace, either a UUID or its name and warehouse ID

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

lakekeeper-permissions-cedar-api-openapi.yml Raw ↑

Other APIs Lakekeeper publishes across the network.

Lakekeeper Generic Table (Data) API
Lakekeeper Authorization API
Lakekeeper Catalog API
Lakekeeper Configuration API
Lakekeeper OAuth2 API
Lakekeeper Permissions Openfga API
Lakekeeper Project API
Lakekeeper Role API
Lakekeeper Server API
Lakekeeper Tasks API
Lakekeeper User API
Lakekeeper Warehouse API
Where this information came from

This is an independent, third-party profile of Lakekeeper Permissions Cedar API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.