Roles and permissions

Account Permissions

Different levels of permission are required to access certain queries, mutations and features in the Skylark API.

The permissions in Skylark are:

PermissionExplainer
READThis permission gives access to the Query type except any query that relate to self configuration, such as getObjectConfiguration.
WRITEThis permission gives access to the Mutation type except any mutation that related to self configuration, such as createObjectConfiguration.
SELF_CONFIGThis permission gives access to all queries and mutations that relate to data model self configuration.
IGNORE_AVAILABILITYThis permission, in connection with the READ permission, allows use of the ignore_availability argument when querying.
TIME_TRAVELThis permission, in connection with the READ permission, allows use of the x-time-travel header when querying.
ACCOUNT_SETUPThis permisison is used for reading and writing certain objects that relate to account configuration. This includes setting up playback/DRM providers, playback URL templates, and playback details.

Roles

The roles that are provided each contain a set of different permissions.

RolePermissionsExample Token
READ_ONLYREADskylark-read-only-KujUUrSQZU-PVHIPmLJUX8mtZeDR5t-OF7TuwiEnrQM
READ_WRITEREAD, WRITEskylark-read-write-dU09OM6uRIzGlN-y4Zym1majgnzss26dOJFWKzyT6FI
EDITORREAD, WRITE, IGNORE_AVAILABILITY, TIME_TRAVELskylark-editor-2MiHfUIOjXU3bq3KmwlEGmnso9XXQodioE2tqfsrpWA
ADMINREAD, WRITE, IGNORE_AVAILABILITY, TIME_TRAVEL, SELF_CONFIG, ACCOUNT_SETUPskylark-admin-vwvmMNJBClMLMHCKYF9EhPXPU8sJac9d9dMiOh1f3DI