Access Control

Who can do what?
You decide.

Granular access control for your APIs. Define roles, manage teams, and control permissions — at every level, in every environment.

app.api-portal.io/settings/permissions
Berechtigung
Admin
Editor
Viewer
APIs anzeigen
APIs bearbeiten
APIs deployen
Mitglieder verwalten
Billing & Settings
GDPR-compliant SOC 2 ready EU Hosting SSO/SAML

// Features

What Access Control delivers.

Roles & Permissions (RBAC)

Granular permissions at every level. Define roles like Admin, Editor, or Viewer and control exactly who can view, edit, or deploy.

Role-based Fine-grained

Business Groups

Organize teams and departments with dedicated policies. Each business group gets separate access rules and permission sets for maximum control.

Teams Departments

Environment Policies

Separate access rules per environment. Define different permissions for DEV, TEST, STAGING, and PROD — independently.

DEV TEST STAGING PROD

// Inheritance Hierarchy

4-level inheritance hierarchy.

Permissions cascade along a clearly defined hierarchy. From the business group down to the capability-environment policy — more specific assignments always win.

  • Automatic inheritance along the hierarchy
  • More specific rules override general ones
  • Transparent audit logs for every change
1
Business Group Rechte
Allgemeine Berechtigungen der Gruppe
2
BG-Environment-Policy
Environment-spezifische Gruppenrechte
3
Capability Rechte
Berechtigungen je API-Capability
4
Capability-Environment-Policy
Hoechste Spezifitaet — gewinnt immer
Hoehere Spezifitaet = hoehere Prioritaet
app.api-portal.io/settings/invite
Neues Mitglied einladen
maria.schmidt@techcorp.de
Editor
Payment Team
Einladung senden

// Team Management

Invitation-based team management.

Invite new members by email, assign a role and business group right away — done. No complicated setup, no manual onboarding.

  • Email-based invitations in seconds
  • Set role and group at invite time
  • Instant access after acceptance
  • Revoke invitations and change roles anytime

// Enterprise Security

Single sign-on for your organization.

Integrate your API Portal seamlessly with existing identity providers. Your team members use their familiar credentials — secure, centralized, and no passwords to remember.

Okta
Azure AD
Google Workspace
Keycloak
SAML 2.0 OpenID Connect SCIM Provisioning MFA
Request Enterprise Plan
“Granular access control elevated our API management to a new level. Every team has exactly the permissions it needs — no more, no less.”
Zero security incidents since launch

// Explore more

You might also like.

Ready for secure API management?

Experience the platform for modern API management.