A valid request URL is required to generate request examples{
"users": [
{
"id": "<string>",
"name": "<string>",
"email": "[email protected]",
"role_id": 123,
"role": {
"id": 123,
"name": "<string>",
"description": "<string>",
"is_system_role": true
},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"teams": [
{
"id": "<string>",
"name": "<string>"
}
],
"business_units": [
{
"id": "<string>",
"name": "<string>"
}
],
"access_profiles": [
{
"id": 123,
"user_id": "<string>",
"parent_profile_id": 123,
"name": "<string>",
"is_active": true,
"expires_at": "2023-11-07T05:31:56Z",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
],
"access_profile": {
"id": 123,
"user_id": "<string>",
"parent_profile_id": 123,
"name": "<string>",
"is_active": true,
"expires_at": "2023-11-07T05:31:56Z",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
}
],
"count": 123
}List users attached to a virtual key (deprecated path)
A valid request URL is required to generate request examples{
"users": [
{
"id": "<string>",
"name": "<string>",
"email": "[email protected]",
"role_id": 123,
"role": {
"id": 123,
"name": "<string>",
"description": "<string>",
"is_system_role": true
},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"teams": [
{
"id": "<string>",
"name": "<string>"
}
],
"business_units": [
{
"id": "<string>",
"name": "<string>"
}
],
"access_profiles": [
{
"id": 123,
"user_id": "<string>",
"parent_profile_id": 123,
"name": "<string>",
"is_active": true,
"expires_at": "2023-11-07T05:31:56Z",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
],
"access_profile": {
"id": 123,
"user_id": "<string>",
"parent_profile_id": 123,
"name": "<string>",
"is_active": true,
"expires_at": "2023-11-07T05:31:56Z",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
}
],
"count": 123
}/api/governance/virtual-keys/{vk_id}/users instead.| Permission | Granted via |
|---|---|
VirtualKeys:View | RBAC role or API key scope |
Authorizations
Management API authentication for /api/* endpoints. Use the Authorization header
with Bearer <token>, where <token> is one of:
- a Bifrost management API key,
- a dashboard session token issued by
POST /api/session/login, - base64 of
<admin-username>:<admin-password>(legacy equivalent ofBasicAuth).
Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs -
the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.
Authentication alone is not sufficient in Bifrost Enterprise: each operation page shows a
Required Permissions table (Resource:Operation, for example Dashboard:View) above
its Authorizations section, and the caller's RBAC role or management API key scopes must
include what it lists, otherwise the request is rejected with 403 Forbidden.
A local admin — authenticated with the admin password, or any caller on a deployment with dashboard auth disabled — bypasses these checks and can call every management endpoint. See Required permissions for how permissions are derived and which endpoints are exempt.
Path Parameters
Was this page helpful?

