How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Optimizely Permission Service API

Granular roles and permissions for Feature Experimentation — per-entity permissions for users and teams, plus team management. Introduced 2025-03-18. Harvested verbatim from the provider's published OpenAPI 2026-08-13.

Optimizely Permission Service API is one of 50 APIs that Optimizely publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Permissions and Identity. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 9 operations across 5 paths, organized into 2 resource areas, and defines 21 schemas. It is described by OpenAPI 3.1.0, at version 0.0.1.

Requests are made against a single base URL, https://api.optimizely.com/permissions.

9 operations 5 paths 21 schemas 1 DELETE5 GET2 PATCH1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.0
API Version
0.0.1
Base URL
https://api.optimizely.com/permissions
Authentication
HTTP Bearer
Resource Areas
2

Authentication & Security 1

Optimizely Permission Service API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (BearerAuth). By default, every request must be authenticated.

  • BearerAuth — To get an API token, see https://docs.developers.optimizely.com/web/docs/personal-token

Paths & Operations 9

Across 5 paths, the API surfaces 9 operations — 1 DELETE, 5 GET, 2 PATCH, 1 POST. They span 2 resource areas: Entity, Team Management. Each is listed below with its method, path, parameters, and response codes.

Entity 4
GET
/users/{user_id}/projects/{project_id}/{entity_type}
Get User Permissions For Project Entity Type
get_user_permissions_for_project_entity_type_users__user_id__projects__project_id___entity_type__get 6 params → 200422
GET
/teams/{team_id}/projects/{project_id}/{entity_type}
Get Team Permissions For Project Entity Type
get_team_permissions_for_project_entity_type_teams__team_id__projects__project_id___entity_type__get 6 params → 200422
GET
/projects/{project_id}/{entity_type}/{entity_id}
Get Entity Permissions
get_entity_permissions_projects__project_id___entity_type___entity_id__get 3 params → 200422
PATCH
/projects/{project_id}/{entity_type}/{entity_id}
Change Permissions
change_permissions_projects__project_id___entity_type___entity_id__patch 3 params body → 200422
Team Management 5
GET
/accounts/{account_id}/teams
Get Teams
get_teams_accounts__account_id__teams_get 1 param → 200422
POST
/accounts/{account_id}/teams
Create Team
create_team_accounts__account_id__teams_post 1 param body → 200422
DELETE
/accounts/{account_id}/teams/{team_id}
Delete Team
delete_team_accounts__account_id__teams__team_id__delete 2 params → 200422
GET
/accounts/{account_id}/teams/{team_id}
Get Team Info
get_team_info_accounts__account_id__teams__team_id__get 2 params → 200422
PATCH
/accounts/{account_id}/teams/{team_id}
Update Team
update_team_info_accounts__account_id__teams__team_id__patch 2 params body → 200422

Schemas 21

The contract defines 21 schemas that model the data the API accepts and returns. The most detailed are TeamInfoResponse (9 properties), TeamInfo (8 properties), TeamPermissionsForEntityTypeResponse (8 properties), UserPermissionsForEntityTypeResponse (8 properties). Each schema is shown below with its type and property counts.

AccountRole
string
EntityPermission
string
EntityPermissionsResponse
object
2 properties 2 required
EntityTypeInPath
string
HTTPValidationError
object
1 property
OperationType
string
PatchOperation
object
3 properties 2 required
TeamCreateRequest
object
4 properties 1 required
TeamCreateResponse
object
2 properties 2 required
TeamInfo
object
8 properties 8 required
TeamInfoResponse
object
9 properties 9 required
TeamPermission
object
4 properties 4 required
TeamPermissionsForEntityTypeResponse
object
8 properties 4 required
TeamUpdateRequest
object
5 properties 1 required
TeamUpdateResponse
object
1 property 1 required
TeamUser
object
6 properties 6 required
UserPermission
object
6 properties 6 required
UserPermissionsForEntityTypeResponse
object
8 properties 4 required
ValidationError
object
3 properties 3 required
src__api__dtos__permissions__TeamPermissionsForEntityTypeResponse__ItemInfo
object
4 properties 3 required
src__api__dtos__permissions__UserPermissionsForEntityTypeResponse__ItemInfo
object
5 properties 4 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

optimizely-feature-experimentation-permission-service-openapi.json Raw ↑

Other APIs Optimizely publishes across the network.

Optimizely Experimentation REST API v2
Optimizely Feature Experimentation Flags API v1
Optimizely Flags Scheduling API
Optimizely Agent API
Optimizely Event API
Optimizely Edge Decider API
Optimizely Data Platform (ODP) API v3
Optimizely Graph API
Optimizely Content Marketing Platform (CMP) API v3
Optimizely Campaign REST API
Optimizely Configured Commerce API
Optimizely CMS Content Delivery API v3.0
Where this information came from

This is an independent, third-party profile of Optimizely Permission Service API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.