Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
On this page
INVALID_FIELD
A field failed validation.
A field failed validation.
HTTP 400 · gRPC INVALID_ARGUMENT · the error body
#Returned by
| Method | Scope | What it does |
|---|---|---|
access.orgs.list | access:read | Lists orgs the caller can see. |
access.orgs.create | access:admin | Creates an org. Access assigns the id. |
access.orgs.update | access:admin | Updates an org. |
access.projects.list | access:read | Lists projects in an org. |
access.projects.create | access:admin | Creates a project. Access assigns the id. |
access.projects.update | access:admin | Updates a project. |
access.envs.list | access:read | Lists environments in a project. |
access.envs.create | access:admin | Creates an environment. Access assigns the id. |
access.envs.update | access:admin | Updates an environment. |
access.api_keys.list | access:read | Lists API keys in an environment, or the org-wide keys of an org. |
access.api_keys.create | access:keys:write | Creates an API key. Access assigns the id. |
access.api_keys.update | access:keys:write | Updates an API key. |
ai.ai_models.list | ai:read | Lists the admitted catalog; filter by brand, modality, or model. |
artifacts.artifacts.list | artifacts:read | Lists a project's artifacts; filter by digest, kind, or subject. |
artifacts.artifacts.create | artifacts:write | Registers an artifact whose bytes were pushed by digest; verification runs after. |
assets.assets.list | assets:read | Lists assets. The filter is limited to kind, state, and review_state. |
assets.assets.generate | assets:write | Records the recipes as assets and generates the variants that are missing. Each call is idempotent and works within a bounded time; call again until pending is 0. |
assets.assets.lock | assets:read | Returns the assets.lock entries and canonical text for the keys the call names, and only those. A read with a request body, like a query. |
assets.assets.approve_variant | assets:write | Approves one variant and records who approved it. |
assets.assets.reject_variant | assets:write | Rejects one variant. Its slot is freed and the next :generate fills it; the rejected file keeps serving at its URL. |
assets.assets.retire_variant | assets:write | Retires one variant. Its URL answers 404 from then on and its slot is freed. |
auth.auth_configs.update | auth:write | Updates an auth config. |
auth.end_users.list | auth:read | Lists end users. |
auth.end_users.create | auth:write | Creates an end user. |
auth.end_users.update | auth:write | Updates an end user. |
auth.end_users.suspend | auth:write | Suspends an end user: sessions are revoked and sign-in is refused. |
auth.end_users.reactivate | auth:write | Reactivates a suspended end user. |
auth.end_users.unlock | auth:write | Clears an end user's sign-in lock (repeated failed sign-ins) now. |
auth.end_users.revoke_sessions | auth:write | Revokes every session of an end user. |
auth.sessions.list | auth:read | Lists sessions. |
auth.sessions.revoke | auth:write | Revokes a session. |
auth.customer_organizations.list | auth:read | Lists customer organizations. |
auth.customer_organizations.create | auth:write | Creates a customer organization. |
auth.customer_organizations.update | auth:write | Updates a customer organization. |
auth.memberships.list | auth:read | Lists memberships. |
auth.memberships.create | auth:write | Creates a membership. |
auth.memberships.update | auth:write | Updates a membership. |
auth.organization_roles.list | auth:read | Lists organization roles. |
auth.organization_roles.create | auth:write | Creates an organization role. |
auth.organization_roles.update | auth:write | Updates an organization role. |
auth.invitations.list | auth:read | Lists invitations. |
auth.invitations.create | auth:write | Creates an invitation. |
auth.invitations.revoke | auth:write | Revokes a pending invitation. |
auth.invitations.accept | auth:write | Accepts a pending invitation for an end user whose verified email is the invited address, and creates the membership. |
auth.email_domains.list | auth:read | Lists email domains. |
auth.email_domains.create | auth:write | Creates an email domain; the answer names the TXT record to publish. |
auth.email_domains.verify | auth:write | Looks up the domain's TXT record now; found, the domain is verified. |
auth.oauth_clients.list | auth:read | Lists OAuth clients. |
auth.oauth_clients.create | auth:write | Creates an OAuth client. |
auth.oauth_clients.update | auth:write | Updates an OAuth client. |
auth.oauth_clients.roll_secret | auth:write | Issues a new client secret, returned once; the old one verifies until grace_period ends. |
billing.meters.list | billing:read | Lists meters. Anonymous-readable: the pricing page renders from it. |
billing.plans.list | billing:read | Lists the plans the caller can see. Anonymous-readable: the pricing page renders from it. |
billing.billing_accounts.list | billing:read | Lists an org's billing accounts: exactly one, default. |
billing.billing_accounts.update | billing:admin | Updates a billing account: changes plan, spend limit, or billing email. |
billing.invoices.list | billing:read | Lists an org's invoices. |
billing.usage_reports.list | billing:read | Lists an org's usage reports, one per billing period. |
billing.usage_reports.query | billing:read | Queries usage over any time range, bucketed and grouped: the usage summary the console charts. Reads rollups; never raw events. |
billing.budget_leases.list | billing:read | Lists an org's budget leases. |
broker.trust_policies.list | broker:read | Lists an org's trust policies. |
broker.trust_policies.create | broker:admin | Creates a trust policy. |
broker.trust_policies.update | broker:admin | Updates a trust policy. |
broker.trust_policies.exchange_token | broker:exchange | Exchanges the caller's workload identity for a short-lived provider credential under a trust policy (RFC 8693 token exchange). The credential is narrowed to the request and cached per installation and permission set; a permission the Connection lacks is PERMISSION_DENIED with reason CapabilityMissing, never an outage. |
build.builds.list | build:read | Lists builds in a project. |
build.builds.create | build:write | Creates a build. The Operation is done when the controller settles it. |
build.build_caches.list | build:read | Lists build caches in a project. |
build.build_caches.update | build:write | Updates a build cache. |
config.config_flags.list | config:read | Lists config flags in an environment. |
config.config_flags.create | config:write | Creates a config flag; the Operation is done when every cell serves it. |
config.config_flags.update | config:write | Updates a config flag; the change rolls out in waves and the Operation is done when every cell serves it. |
config.config_flags.evaluate | config:evaluate | Evaluates config flags of an environment for one evaluation context: each flag's value, and why. Browsers and mobile apps call it with a publishable key holding config:evaluate, which reads values, never rules. |
config.config_segments.list | config:read | Lists config segments in an environment. |
config.config_segments.create | config:write | Creates a config segment. |
config.config_segments.update | config:write | Updates a config segment; every flag naming it follows. |
config.config_changes.list | config:read | Lists config changes in an environment. |
connections.connection_providers.list | connections:read | Lists an org's connection providers. |
connections.connection_providers.create | connections:admin | Creates a connection provider. |
connections.connection_providers.update | connections:admin | Updates a connection provider. |
connections.connections.list | connections:read | Lists an org's connections. |
connections.connections.create | connections:write | Records an installation; the controller confirms it with the provider. |
connections.connections.update | connections:write | Updates a connection's metadata. |
data.objects.put | data:write | Writes an object's bytes, replacing the current version. body is the base64 of the bytes. |
data.objects.list | data:read | Lists a bucket's objects in key order. |
data.kv.put | data:write | Writes a value. Without ttl_seconds the namespace default applies; zero means no expiry. |
data.kv.list | data:read | Lists a namespace's values in key order. |
data.kv.increment | data:write | Adds delta (default 1) to an integer value, creating it at zero. |
data.kv.get_many | data:read | Reads up to 1000 keys at once (MGET). Answers one entry per key, in order; an absent or expired key keeps its key and has no value. |
data.kv.hash_set | data:write | Sets fields of a hash (HSET), creating it. |
data.kv.hash_get | data:read | Reads one field of a hash (HGET); an absent field has no value. |
data.kv.hash_get_all | data:read | Reads every field of a hash (HGETALL). |
data.kv.hash_get_many | data:read | Reads several fields of a hash (HMGET), one per field, in order; an absent field has no value. |
data.kv.list_push | data:write | Pushes values onto the head of a list (LPUSH), creating it. |
data.kv.list_range | data:read | Reads a range of a list (LRANGE); negative indexes count from the end. |
data.kv.list_pop | data:write | Pops values from the head of a list (LPOP); an emptied list is removed. |
data.kv.list_length | data:read | Reads the length of a list (LLEN); an absent key has length zero. |
data.kv.zset_add | data:write | Adds members to a sorted set or updates their scores (ZADD), creating it. |
data.kv.zset_range | data:read | Reads a range of a sorted set by rank, lowest score first (ZRANGE); negative indexes count from the end. |
data.kv.zset_score | data:read | Reads a member's score (ZSCORE); an absent member has no score. |
data.kv.zset_length | data:read | Reads the size of a sorted set (ZCARD); an absent key has size zero. |
data.kv.scan | data:read | Walks a namespace's keys that match a glob (SCAN). Call again with the returned cursor until it is empty. |
data.kv.expire | data:write | Sets a key's time to live (EXPIRE) without rewriting its value; zero makes it persistent. |
data.documents.put | data:write | Writes a document to a search index, replacing the current version. |
data.search.query | data:read | Searches an index by text, by vector, or both, best match first, with filters and paging. |
data.databases.list | data:read | Lists databases in a environment. |
data.databases.create | data:write | Creates a database. The Operation is done when the controller settles it. |
data.databases.update | data:write | Updates a database. |
data.kv_namespaces.list | data:read | Lists kv namespaces in a environment. |
data.kv_namespaces.create | data:write | Creates a kv namespace. The Operation is done when the controller settles it. |
data.kv_namespaces.update | data:write | Updates a kv namespace. |
data.buckets.list | data:read | Lists buckets in a environment. |
data.buckets.create | data:write | Creates a bucket. The Operation is done when the controller settles it. |
data.buckets.update | data:write | Updates a bucket. |
data.search_indexes.list | data:read | Lists search indexs in a environment. |
data.search_indexes.create | data:write | Creates a search index. The Operation is done when the controller settles it. |
data.search_indexes.update | data:write | Updates a search index. |
entitlement.entitlements.list | entitlement:read | Lists an org's entitlements: exactly one, default. |
events.topics.list | events:read | Lists topics. |
events.topics.create | events:write | Creates a topic. |
events.topics.update | events:write | Updates a topic. |
events.topics.publish | events:publish | Publishes CloudEvents into a Topic, atomically. Replaying the same source + id with the same payload returns the stored event; a different payload fails with RESOURCE_ALREADY_EXISTS. |
events.events.list | events:read | Lists events. |
events.connectors.list | events:read | Lists connectors. |
events.subscriptions.list | events:read | Lists subscriptions. |
events.subscriptions.create | events:write | Creates a subscription. |
events.subscriptions.update | events:write | Updates a subscription. |
events.queues.list | events:read | Lists queues. |
events.queues.create | events:write | Creates a queue. |
events.queues.update | events:write | Updates a queue. |
events.queues.send | events:publish | Enqueues messages directly, without a Subscription. |
events.queues.lease | events:write | Leases up to max_messages ready messages for the visibility timeout. |
events.queues.ack | events:write | Acknowledges leased messages; each is removed. A lease that is stale (expired or superseded) is reported, not applied. |
events.queues.nack | events:write | Returns leased messages to the Queue after delay; each nack counts as a delivery. |
events.queues.replay | events:write | Moves dead-lettered messages, optionally bounded by dead-letter time, back to ready. |
events.webhook_endpoints.list | events:read | Lists webhook endpoints. |
events.webhook_endpoints.create | events:write | Creates a webhook endpoint. |
events.webhook_endpoints.update | events:write | Updates a webhook endpoint. |
events.webhook_endpoints.replay | events:write | Redelivers every dead-lettered delivery to the endpoint created in a time range, each as a new attempt. |
events.webhook_deliveries.list | events:read | Lists webhook deliveries. |
events.webhook_deliveries.replay | events:write | Redelivers one delivery now, as a new attempt. |
events.inbound_endpoints.list | events:read | Lists inbound endpoints. |
events.inbound_endpoints.create | events:write | Creates an inbound endpoint. |
events.inbound_endpoints.update | events:write | Updates an inbound endpoint. |
events.realtime_channels.list | events:read | Lists realtime channels. |
events.realtime_channels.create | events:write | Creates a realtime channel. |
events.realtime_channels.update | events:write | Updates a realtime channel. |
events.realtime_channels.publish | events:publish | Publishes one message to the channel: it is appended to the channel's history and pushed to every connected client. A retry with the same Idempotency-Key returns the first message. |
events.realtime_channels.issue_token | events:publish | Mints a subscribe token (rtt_…) for this channel alone, at most an hour long, for a browser or device that holds no key. A token that names a client id enters the channel's presence while it is connected. |
events.realtime_messages.list | events:read | Lists a channel's retained messages, oldest first. |
events.realtime_members.list | events:read | Lists the clients present in a channel now. |
hosting.services.list | hosting:read | Lists services in a environment. |
hosting.services.create | hosting:write | Creates a service. The Operation is done when the controller settles it. |
hosting.services.update | hosting:write | Updates a service. |
hosting.service_rollouts.list | hosting:read | Lists rollouts in a service. |
hosting.service_rollouts.create | hosting:write | Creates a rollout. |
hosting.previews.list | hosting:read | Lists previews in a environment. |
hosting.previews.create | hosting:write | Creates a preview. The Operation is done when the controller settles it. |
hosting.source_links.list | hosting:read | Lists source links in a project. |
hosting.source_links.create | hosting:write | Creates a source link. The Operation is done when the controller settles it. |
hosting.source_links.update | hosting:write | Updates a source link. |
keys.keys.list | keys:read | Lists keys in an environment. |
keys.keys.create | keys:write | Creates a key; the signer generates its first version. |
keys.keys.update | keys:write | Updates a key's rotation period, deletion protection, or metadata. |
keys.keys.sign | keys:sign | Signs data or a digest with a SIGN key. Every use is audited. |
keys.keys.verify | keys:verify | Verifies a signature made by a SIGN key. |
keys.keys.encrypt | keys:encrypt | Encrypts data with an ENCRYPT key. |
keys.keys.decrypt | keys:decrypt | Decrypts a ciphertext made by Encrypt with this key. |
keys.keys.mac_sign | keys:sign | Computes a MAC of data with a MAC key. |
keys.keys.mac_verify | keys:verify | Verifies a MAC made by a MAC key, in constant time. |
keys.key_versions.list | keys:read | Lists a key's versions. |
localization.catalogs.list | localization:read | Lists catalogs. |
localization.catalogs.create | localization:write | Creates a catalog. |
localization.catalogs.update | localization:write | Updates a catalog. |
localization.catalogs.sync | localization:write | Reads the source files and the committed translations into the catalog, then translates what is new or stale. Each call is idempotent and works within a bounded time; call again until pending is 0. |
localization.catalogs.export | localization:read | Returns the catalog's files per locale in the requested format, with the QA report. A read with a request body, like a query. |
localization.entries.list | localization:read | Lists catalog entries. The filter is limited to state, locale, and qa_state. |
localization.entries.pin_translation | localization:write | Sets the text of one locale as a human override that AI never overwrites. QA runs on the text first; a text with a QA error is rejected with INVALID_FIELD, and the problem lists the findings. |
localization.entries.unpin_translation | localization:write | Removes the human override of one locale; the next sync may translate it again. |
localization.glossaries.list | localization:read | Lists glossarys. |
localization.glossaries.create | localization:write | Creates a glossary. |
localization.glossaries.update | localization:write | Updates a glossary. |
money.price_catalogs.update | billing:write | Updates the environment's catalog: its features and products, whole. |
money.store_connections.list | billing:read | Lists store connections. |
money.store_connections.create | billing:write | Creates a store connection; its credential is sealed and never returned. |
money.store_connections.update | billing:write | Updates a store connection; a new credential replaces the stored one. |
money.store_purchases.verify | billing:write | Verifies a store purchase with the store, binds it to the subject, and returns its record and a signed grant. Re-verifying returns the same record and grant. Called from the app's server with a secret key that holds billing:write; a publishable key cannot call it. |
money.store_purchases.list | billing:read | Lists store purchases, newest first. |
money.customer_subscriptions.list | billing:read | Lists customer subscriptions, newest first. |
money.customer_subscriptions.update_quantity | billing:write | Changes the seat quantity of a web subscription, now, and syncs the processor's subscription item to it. A retry with the same Idempotency-Key (required) and the same request changes nothing twice. |
money.entitlement_grants.list | billing:read | Lists entitlement grants. |
money.entitlement_grants.check | billing:read | Answers whether a subject holds a feature now, and how much of it. |
money.merchant_accounts.list | billing:read | Lists merchant accounts. |
money.merchant_accounts.connect | billing:write | Starts connecting a Stripe account: returns the processor's authorisation URL for an org owner to open, which the processor's redirect completes. With a restricted key in the request the account connects at once instead, and the connected merchant account comes back in the response. |
money.checkout_sessions.create | billing:write | Creates a hosted checkout for a subject. |
money.portal_sessions.create | billing:write | Creates a customer portal session for a subject. |
network.domains.list | network:read | Lists domains in a project. |
network.domains.create | network:write | Creates a domain. The Operation is done when the controller settles it. |
network.domains.update | network:write | Updates a domain. |
network.certificates.list | network:read | Lists certificates in a project. |
network.routes.list | network:read | Lists routes in a environment. |
network.routes.create | network:write | Creates a route. The Operation is done when the controller settles it. |
network.routes.update | network:write | Updates a route. |
network.egress_identities.list | network:read | Lists egress identitys in a project. |
network.egress_identities.create | network:write | Creates an egress identity. The Operation is done when the controller settles it. |
network.egress_identities.update | network:write | Updates an egress identity. |
network.private_links.list | network:read | Lists private links in a environment. |
network.private_links.create | network:write | Creates a private link. The Operation is done when the controller settles it. |
network.private_links.update | network:write | Updates a private link. |
notify.mail_domains.list | notify:read | Lists email domains. |
notify.mail_domains.create | notify:write | Creates an email domain. |
notify.mail_domains.update | notify:write | Updates an email domain. |
notify.mail_routes.list | notify:read | Lists an email domain's routes. |
notify.mail_routes.create | notify:write | Creates a route. |
notify.mail_routes.update | notify:write | Updates a route. |
notify.senders.list | notify:read | Lists senders. |
notify.senders.create | notify:write | Creates a sender. |
notify.senders.update | notify:write | Updates a sender. |
notify.recipients.list | notify:read | Lists recipients. |
notify.recipients.create | notify:write | Creates a recipient. |
notify.recipients.update | notify:write | Updates a recipient. |
notify.preferences.list | notify:read | Lists preferences. |
notify.preferences.update | notify:write | Updates a preference. |
notify.suppressions.list | notify:read | Lists suppressions. |
notify.suppressions.create | notify:write | Creates a suppression. |
notify.templates.list | notify:read | Lists templates. |
notify.templates.create | notify:write | Creates a template. |
notify.templates.update | notify:write | Updates a template. |
notify.messages.list | notify:read | Lists messages. |
notify.messages.create | notify:send | Sends a Message. |
notify.messages.cancel | notify:send | Cancels a Message whose deliveries have not been handed off. |
notify.mailboxes.list | notify:read | Lists mailboxes. |
notify.mailboxes.create | notify:write | Creates a mailbox. |
notify.mailboxes.update | notify:write | Updates a mailbox. |
notify.mailboxes.erase_address | notify:write | Removes an address's personal data from every inbound email of the mailbox that it sent or that names it, keeping the dedupe keys so a poll never brings the mail back. |
notify.inbound_emails.list | notify:read | Lists a mailbox's inbound email in feed order, oldest first. |
notify.inbox_items.list | notify:read | Lists inbox items. |
notify.inbox_items.mark_read | notify:write | Marks an inbox item read. |
notify.inbox_items.mark_unread | notify:write | Marks an inbox item unread. |
notify.inbox_items.archive | notify:write | Archives an inbox item. |
notify.broadcasts.list | notify:read | Lists broadcasts. |
notify.broadcasts.create | notify:write | Creates a broadcast. |
notify.broadcasts.update | notify:write | Updates a broadcast. |
notify.broadcasts.send | notify:send | Sends a Broadcast now. |
notify.broadcasts.cancel | notify:send | Cancels a Broadcast; messages already admitted still deliver. |
observability.log_entries.write | observability:ingest | Ingests a batch of log entries atomically. The same Idempotency-Key and digest replays the same batch; a different digest under the key conflicts. |
observability.log_entries.query | observability:read | Queries the environment's log entries over a bounded interval; follow a trace with trace_id = "...". |
observability.traces.write_spans | observability:ingest | Ingests a batch of spans atomically; a span's parent and time invariants are validated. Replay rules are those of WriteLogEntries. |
observability.traces.query | observability:read | Queries the environment's traces over a bounded interval, returning summaries without spans. |
observability.error_groups.list | observability:read | Lists error groups; filter by state, service_name, and last_seen_time. |
observability.error_groups.capture | observability:ingest | Captures one error occurrence. It is grouped by fingerprint when the caller sets one, else by exception type and the symbolicated in-app stack; release is never part of the group. A new occurrence reopens a resolved group. Secrets and personal data are scrubbed by the environment's Scrubbing Policy before storage. A fingerprint-equal replay bills no second new-error unit. Under quota pressure the response says what to sample. Browsers call it with a publishable key that holds observability:ingest (CORS allowed, rate-limited per environment). |
observability.error_groups.acknowledge | observability:write | Acknowledges an error group. |
observability.error_groups.resolve | observability:write | Resolves an error group; a new occurrence reopens it. |
observability.error_groups.reopen | observability:write | Reopens a resolved or acknowledged error group. |
observability.error_events.list | observability:read | Lists error events. |
observability.source_maps.create | observability:write | Uploads a source map for one release and minified file. Uploading the same release and file again replaces it. |
observability.source_maps.list | observability:read | Lists source maps, newest first; filter by release. |
observability.scrubbing_policies.update | observability:write | Updates the environment's scrubbing policy. |
release.releases.list | release:read | Lists releases in an environment, newest first by default. |
release.releases.create | release:write | Creates a release: admits it and rolls it out in waves. The Operation is done when the release is live or halted. |
release.rollouts.list | release:read | Lists rollouts in an environment. |
runners.scale_sets.list | runners:read | Lists scale sets in a org. |
runners.scale_sets.create | runners:write | Creates a scale set. The Operation is done when the controller settles it. |
runners.scale_sets.update | runners:write | Updates a scale set. |
runners.runners.list | runners:read | Lists runners in a scale set. |
sandboxes.sandbox_shapes.list | sandboxes:read | Lists shapes. |
sandboxes.pools.list | sandboxes:read | Lists pools in a environment. |
sandboxes.pools.create | sandboxes:write | Creates a pool. The Operation is done when the controller settles it. |
sandboxes.pools.update | sandboxes:write | Updates a pool. |
sandboxes.leases.list | sandboxes:read | Lists leases in a environment. Filter on meta.labels (for example labels.agent = "a_123"), status.state, and spec.kind. |
sandboxes.leases.create | sandboxes:write | Creates a lease: granted now and returned READY (or GRANTED when wait_ready is false), or refused with a typed error. There is no queue. |
sandboxes.leases.set_network | sandboxes:write | Replaces a running lease's outbound policy. The generation does not change; the new policy applies before the call returns. |
sandboxes.leases.act | sandboxes:exec | Performs computer actions on a DESKTOP, BROWSER, or ANDROID lease, in order, and returns each action's result and, when screenshot is set, the screenshot taken after the last action. The actions are the Anthropic computer tool's and OpenAI computer use's, one-to-one. Refused CONTROL_HELD_BY_HUMAN while a human holds control. |
sandboxes.leases.acquire_control | sandboxes:exec | Takes exclusive input control of a lease's display. A HUMAN acquire preempts an AGENT holder and returns a controller stream; an AGENT acquire is refused CONTROL_HELD_BY_HUMAN while a human holds control. Control lapses at ttl, which the platform caps at 30 minutes. |
sandboxes.lease_events.list | sandboxes:read | Lists a lease's events in order. With wait, blocks up to that long for an event after page_token (long poll). |
sandboxes.volumes.list | sandboxes:read | Lists volumes in a environment. |
sandboxes.volumes.create | sandboxes:write | Creates a volume. |
sandboxes.volumes.update | sandboxes:write | Updates a volume: grows spec.size_gib and edits metadata. |
sandboxes.snapshots.list | sandboxes:read | Lists snapshots in a environment. |
sandboxes.snapshots.create | sandboxes:write | Captures a running lease's disk as a snapshot. |
secrets.secrets.list | secrets:read | Lists secrets in an environment. |
secrets.secrets.create | secrets:write | Creates a secret, without a value; add one with CreateSecretVersion. |
secrets.secrets.update | secrets:write | Updates a secret. |
secrets.secret_versions.list | secrets:read | Lists a secret's versions. |
secrets.secret_versions.create | secrets:write | Adds a value to a secret as its newest version. The value is never returned. |
secrets.secret_bindings.list | secrets:read | Lists secret bindings in an environment. |
secrets.secret_bindings.create | secrets:write | Creates a secret binding. |
secrets.secret_bindings.update | secrets:write | Updates a secret binding. |
workflows.workflows.list | workflows:read | Lists workflows. |
workflows.workflows.create | workflows:write | Creates a workflow. |
workflows.workflows.update | workflows:write | Updates a workflow. |
workflows.schedules.list | workflows:read | Lists schedules. |
workflows.schedules.create | workflows:write | Creates a schedule. |
workflows.schedules.update | workflows:write | Updates a schedule. |
workflows.schedules.pause | workflows:write | Pauses a Schedule: no fire starts a Run until it is resumed. |
workflows.schedules.resume | workflows:write | Resumes a paused Schedule; missed fires follow catchup_window. |
workflows.runs.list | workflows:read | Lists runs. |
workflows.runs.create | workflows:run | Starts a Run of a Workflow. |
workflows.runs.start_batch | workflows:run | Starts a batch: a parent Run that fans out one child Run per item, each with a stable index and count. |
workflows.runs.signal | workflows:run | Sends a named signal to a running Run; a wait op for that name resumes with its payload. A signal to a closed Run fails with INVALID_STATE. |
workflows.runs.cancel | workflows:run | Requests cancellation. Timers and waits stop; a running invocation is not interrupted: the handler receives one final invocation with cancel: true, and the Run ends cancelled when it answers. |
workflows.runs.read_history | workflows:read | Reads a page of the Run's immutable history, projected to Sylphx events. |
workflows.jobs.list | workflows:read | Lists jobs. |
workflows.jobs.create | workflows:write | Creates a job. |
workflows.jobs.update | workflows:write | Updates a job. Runs already started keep the generation they pinned. |
workflows.job_runs.create | workflows:run | Starts a run of a Job now. The same Idempotency-Key returns the same run for 24h; a Schedule fire uses {job}:{intended time}. With concurrency forbid, a start while a run is active fails with INVALID_STATE. |
workflows.job_runs.list | workflows:read | Lists a job's runs, newest first. |
workflows.distributed_jobs.list | workflows:read | Lists distributed jobs. |
workflows.distributed_jobs.create | workflows:write | Creates a distributed job. |
workflows.distributed_jobs.update | workflows:write | Updates a distributed job. Runs already started keep the generation they pinned. |
workflows.distributed_runs.create | workflows:run | Starts a run of a distributed job. The same Idempotency-Key returns the same run for 24h. |
workflows.distributed_runs.list | workflows:read | Lists a distributed job's runs, newest first. |
workflows.distributed_runs.add_shards | workflows:run | Appends shards to a run started with an open manifest; close ends the manifest, and the run ends once those shards are done. |
workflows.distributed_runs.read_shards | workflows:read | Reads a page of the run's shards, in queue order. |
workflows.distributed_runs.read_workers | workflows:read | Reads a page of the run's workers. |