openapi: 3.0.1 info: title: Bytebase Auth Roles API description: Bytebase exposes a Connect/gRPC API that is also served as a RESTful HTTP API via gRPC transcoding (google.api.http annotations). Every action in the Bytebase web console is backed by this API. This document models the core RESTful HTTP surface - instances, databases, projects, issues (schema change / migration), plans, rollouts, sheets, users, roles, groups, and project webhooks. Authentication uses a short-lived access token obtained by logging in with a service account; the token is supplied as a Bearer token in the Authorization header. The server URL is the base of your own self-hosted or cloud Bytebase deployment (the public demo is shown). termsOfService: https://www.bytebase.com/terms contact: name: Bytebase Support url: https://www.bytebase.com/docs/ version: v1 servers: - url: https://demo.bytebase.com/v1 description: Bytebase public demo (replace with your own deployment host) security: - bearerAuth: [] tags: - name: Roles paths: /roles: get: operationId: listRoles tags: - Roles summary: List custom and predefined roles. responses: '200': description: A list of roles. content: application/json: schema: $ref: '#/components/schemas/ListRolesResponse' components: schemas: Role: type: object properties: name: type: string description: Resource name, e.g. roles/tester. title: type: string description: type: string permissions: type: array items: type: string ListRolesResponse: type: object properties: roles: type: array items: $ref: '#/components/schemas/Role' securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: 'Access token obtained from POST /v1/auth/login using a service-account email and service key. Supplied as `Authorization: Bearer `.'