Endpoint Privileges Map

Back to Security and Authorization

This generated page maps documented endpoints to the privilege actions they require for successful execution. It is derived from each operation’s x-required-privileges field in the OpenAPI source.

Topic Method Endpoint Required Privileges
AI POST /v1/ai/curricula/activities/generate <ul><li>Invoke AI:<ul><li>urn:ayode:privilege-action:/api/invoke/ai</li><li>Scope: none.</li></ul></li></ul>
AI POST /v1/ai/curricula/essential-questions/generate <ul><li>Invoke AI:<ul><li>urn:ayode:privilege-action:/api/invoke/ai</li><li>Scope: none.</li></ul></li></ul>
AI GET /v1/ai/curricula/syllabus/{document-id}/{segment-id} <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
AI POST /v1/ai/curricula/weekly-topic/generate <ul><li>Invoke AI:<ul><li>urn:ayode:privilege-action:/api/invoke/ai</li><li>Scope: none.</li></ul></li></ul>
AI POST /v1/ai/syllabus/async-generate <ul><li>Invoke AI:<ul><li>urn:ayode:privilege-action:/api/invoke/ai</li><li>Scope: none.</li></ul></li></ul>
AI GET /v1/ai/syllabus/retrieve-async/{realmEID}/{token} <ul><li>Invoke AI:<ul><li>urn:ayode:privilege-action:/api/invoke/ai</li><li>Scope: none.</li></ul></li></ul>
AI POST /v1/ai/text/metadata/generate <ul><li>Invoke AI:<ul><li>urn:ayode:privilege-action:/api/invoke/ai</li><li>Scope: none.</li></ul></li></ul>
AI POST /v1/ai/vocabulary/definitions/generate <ul><li>Invoke AI:<ul><li>urn:ayode:privilege-action:/api/invoke/ai</li><li>Scope: none.</li></ul></li></ul>
AI POST /v1/ai/vocabulary/standard-apropos/async-generate <ul><li>Invoke AI:<ul><li>urn:ayode:privilege-action:/api/invoke/ai</li><li>Scope: none.</li></ul></li></ul>
AI GET /v1/ai/vocabulary/standard-apropos/retrieve-async/{realmEID}/{token} <ul><li>Invoke AI:<ul><li>urn:ayode:privilege-action:/api/invoke/ai</li><li>Scope: none.</li></ul></li></ul>
AI POST /v2/ai/async-generate/{human-name} <ul><li>Invoke AI:<ul><li>urn:ayode:privilege-action:/api/invoke/ai</li><li>Scope: none.</li></ul></li></ul>
AI POST /v2/ai/generate/{human-name} <ul><li>Invoke AI:<ul><li>urn:ayode:privilege-action:/api/invoke/ai</li><li>Scope: none.</li></ul></li></ul>
AI GET /v2/ai/retrieve-async/{realmEID}/{token} <ul><li>Invoke AI:<ul><li>urn:ayode:privilege-action:/api/invoke/ai</li><li>Scope: none.</li></ul></li></ul>
AI POST /v2/ai/text/metadata/generate <ul><li>Invoke AI:<ul><li>urn:ayode:privilege-action:/api/invoke/ai</li><li>Scope: none.</li></ul></li></ul>
AI POST /v2/corpus/add <ul><li>Add content to corpus:<ul><li>urn:ayode:privilege-action:/api/corpus/add</li><li>Scope: realm.</li></ul></li></ul>
AI GET /v2/corpus/add/{job-id} <ul><li>Add content to corpus:<ul><li>urn:ayode:privilege-action:/api/corpus/add</li><li>Scope: realm.</li></ul></li></ul>
AI GET /v2/corpus/assets/{realmEID}/{metadataAssetEID} <ul><li>Add content to corpus:<ul><li>urn:ayode:privilege-action:/api/corpus/add</li><li>Scope: realm.</li></ul></li></ul>
AI GET /v2/corpus/realms <ul><li>List corpus-enabled realms:<ul><li>urn:ayode:privilege-action:/api/corpus/realms</li><li>Scope: none.</li></ul></li></ul>
AI GET /v2/corpus/realms/{realmEID} <ul><li>List corpus-enabled realms:<ul><li>urn:ayode:privilege-action:/api/corpus/realms</li><li>Scope: none.</li></ul></li></ul>
Assemblies GET /v1/assemblies/components <ul><li>None. This endpoint is public.</li></ul>
Assemblies GET /v1/assemblies/components/{pathname} <ul><li>Read component assembly or ancillary file:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self or realm.</li><li>Uses self scope when the assembly path uses ~; realm scope when it targets another user EID. If contentURI is provided, the same read privilege is evaluated again against that overlay path.</li></ul></li></ul>
Assemblies GET /v2/assemblies/components/copy/status/{targetRealmEID}/{targetZone}/{targetPathname} <ul><li>Access target asset zone:<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self or realm.</li><li>Uses self scope when zone is ~ or the caller's own user EID; realm scope when zone is another user's EID.</li></ul></li></ul>
Assemblies POST /v2/assemblies/components/copy/{sourceRealmEID}/{sourceZone}/{sourcePathname} <ul><li>Read source assembly manifest and member contents:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self or realm.</li><li>based on sourceZone; explicit same-user within the asserted realm uses self scope, otherwise realm scope</li></ul></li><li>Access target asset zone:<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self or realm.</li><li>based on targetUserURN; explicit same-user within the asserted realm uses self scope, otherwise realm scope</li></ul></li><li>Read existing target manifest and member versions (copy provenance):<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self or realm.</li><li>evaluated only when the target pathname already holds at least one version — the same condition that selects /file-system/file/write over /file-system/file/create; evaluated under the target-side assertion (targetAssertedRealm), using the same targetUserURN-derived self/realm basis as "Access target asset zone"; evaluated by the asynchronous worker, so a missing grant fails the copy terminally through the status endpoint rather than as a synchronous 403 on the 202 request</li></ul></li><li>Create or write target manifest / member file versions:<ul><li>urn:ayode:privilege-action:/file-system/file/create</li><li>Scope: self or realm.</li><li>based on targetUserURN; explicit same-user within the asserted realm uses self scope, otherwise realm scope</li></ul></li><li>Create or write target manifest / member file versions:<ul><li>urn:ayode:privilege-action:/file-system/file/write</li><li>Scope: self or realm.</li><li>based on targetUserURN; explicit same-user within the asserted realm uses self scope, otherwise realm scope</li></ul></li></ul>
Assemblies GET /v2/assemblies/components/status/{targetRealmEID}/{targetZone}/{targetPathname} <ul><li>Read saved assembly status:<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self.</li><li>The target assembly save status is available only for targetZone=~ in this tranche.</li></ul></li></ul>
Assemblies POST /v2/assemblies/components/{targetRealmEID}/{targetZone}/{targetPathname} <ul><li>Read source file contents:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self or realm.</li><li>Local ./ references use self scope in the target zone; external asset URNs use self scope only when the explicit source user EID matches the caller and the source realm matches the asserted realm. Otherwise, realm scope applies.</li></ul></li><li>Create or write manifest / consolidated files:<ul><li>urn:ayode:privilege-action:/file-system/file/create</li><li>Scope: self.</li><li>Applies when the target manifest or consolidated asset does not yet exist.</li></ul></li><li>Create or write manifest / consolidated files:<ul><li>urn:ayode:privilege-action:/file-system/file/write</li><li>Scope: self.</li><li>Applies when the target manifest or consolidated asset already exists and a new version is being written.</li></ul></li></ul>
Assets POST /v1/assets/downloads <ul><li>Download file contents:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self.</li></ul></li></ul>
Assets GET /v1/assets/downloads/status/{pathname} <ul><li>Download file contents:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self.</li></ul></li></ul>
Assets GET /v1/assets/metadata/{pathname} <ul><li>Read asset metadata:<ul><li>urn:ayode:privilege-action:/api/assets/metadata/read</li><li>Scope: self or realm.</li><li>Uses self scope when zone=~; realm scope when zone is another user EID.</li></ul></li></ul>
Assets GET /v1/assets/status/{pathname} <ul><li>Read transfer status:<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self.</li></ul></li></ul>
Assets GET /v1/assets/{realmEID}/{zone}/ <ul><li>Directory listing:<ul><li>urn:ayode:privilege-action:/file-system/directory/read</li><li>Scope: self.</li></ul></li></ul>
Assets DELETE /v1/assets/{realmEID}/{zone}/{basename}.{extension} <ul><li>Delete asset:<ul><li>urn:ayode:privilege-action:/file-system/file/delete</li><li>Scope: self.</li></ul></li></ul>
Assets GET /v1/assets/{realmEID}/{zone}/{basename}.{extension} <ul><li>File content:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self.</li></ul></li></ul>
Assets GET /v1/assets/{realmEID}/{zone}/{basename}.{extension}{version} <ul><li>File content:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self.</li></ul></li><li>File versions:<ul><li>urn:ayode:privilege-action:/file-system/file/versions/list</li><li>Scope: self.</li></ul></li></ul>
Assets GET /v1/assets/{realmEID}/{zone}/{path}/ <ul><li>Directory listing:<ul><li>urn:ayode:privilege-action:/file-system/directory/read</li><li>Scope: self.</li></ul></li></ul>
Assets DELETE /v1/assets/{realmEID}/{zone}/{path}/{basename}.{extension} <ul><li>Delete asset:<ul><li>urn:ayode:privilege-action:/file-system/file/delete</li><li>Scope: self.</li></ul></li></ul>
Assets GET /v1/assets/{realmEID}/{zone}/{path}/{basename}.{extension} <ul><li>File content:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self.</li></ul></li></ul>
Assets GET /v1/assets/{realmEID}/{zone}/{path}/{basename}.{extension}{version} <ul><li>File content:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self.</li></ul></li><li>File versions:<ul><li>urn:ayode:privilege-action:/file-system/file/versions/list</li><li>Scope: self.</li></ul></li></ul>
Assets GET /v2/assets/copy/status/{targetRealmEID}/{targetZone}/{targetPathname} <ul><li>Access target asset zone:<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self or realm.</li><li>Uses self scope when zone is ~ or the caller's own user EID; realm scope when zone is another user's EID.</li></ul></li></ul>
Assets POST /v2/assets/copy/{sourceRealmEID}/{sourceZone}/{sourcePathname} <ul><li>Read source file contents:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self or realm.</li><li>based on sourceZone; explicit same-user within the asserted realm uses self scope, otherwise realm scope</li></ul></li><li>Access target asset zone:<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self or realm.</li><li>based on targetUserURN; explicit same-user within the asserted realm uses self scope, otherwise realm scope</li></ul></li><li>Create or write target file version:<ul><li>urn:ayode:privilege-action:/file-system/file/create</li><li>Scope: self or realm.</li><li>based on targetUserURN; explicit same-user within the asserted realm uses self scope, otherwise realm scope</li></ul></li><li>Create or write target file version:<ul><li>urn:ayode:privilege-action:/file-system/file/write</li><li>Scope: self or realm.</li><li>based on targetUserURN; explicit same-user within the asserted realm uses self scope, otherwise realm scope</li></ul></li></ul>
Assets GET /v2/assets/{realmEID}/{zone} <ul><li>Read the directory contents:<ul><li>urn:ayode:privilege-action:/file-system/directory/read</li><li>Scope: self or realm.</li><li>based on zone</li></ul></li></ul>
Assets GET /v2/assets/{realmEID}/{zone}/{pathname} <ul><li>Directory listing:<ul><li>urn:ayode:privilege-action:/file-system/directory/read</li><li>Scope: self or realm.</li><li>Uses self scope when zone is ~ or the caller's own user EID; realm scope when zone is another user's EID.</li></ul></li><li>File content:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self or realm.</li><li>Uses self scope when zone is ~ or the caller's own user EID; realm scope when zone is another user's EID.</li></ul></li><li>File versions:<ul><li>urn:ayode:privilege-action:/file-system/file/versions/list</li><li>Scope: self or realm.</li><li>Uses self scope when zone is ~ or the caller's own user EID; realm scope when zone is another user's EID.</li></ul></li></ul>
Assets PATCH /v2/assets/{realmEID}/{zone}/{pathname} <ul><li>Access target asset zone:<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self or realm.</li><li>Uses self scope when zone=~; realm scope when zone is another user EID.</li></ul></li><li>Create file:<ul><li>urn:ayode:privilege-action:/file-system/file/create</li><li>Scope: self.</li><li>Applies when the target file does not yet exist.</li></ul></li><li>Write new version:<ul><li>urn:ayode:privilege-action:/file-system/file/write</li><li>Scope: self.</li><li>Applies when the target file already exists.</li></ul></li></ul>
Assets POST /v2/assets/{realmEID}/{zone}/{pathname} <ul><li>Access target asset zone:<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self or realm.</li><li>Uses self scope when zone=~; realm scope when zone is another user EID.</li></ul></li><li>Create file:<ul><li>urn:ayode:privilege-action:/file-system/file/create</li><li>Scope: self.</li><li>Applies when the target file does not yet exist.</li></ul></li><li>Write new version:<ul><li>urn:ayode:privilege-action:/file-system/file/write</li><li>Scope: self.</li><li>Applies when the target file already exists.</li></ul></li></ul>
Assets PUT /v2/assets/{realmEID}/{zone}/{pathname} <ul><li>Access target asset zone:<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self or realm.</li><li>Uses self scope when zone=~; realm scope when zone is another user EID.</li></ul></li></ul>
Assets GET /v2/realms/{realmEID}/files <ul><li>Read the directory contents:<ul><li>urn:ayode:privilege-action:/realm-file-system/directory/read</li><li>Scope: realm.</li></ul></li></ul>
Assets GET /v2/realms/{realmEID}/files/status/{pathname} <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Assets DELETE /v2/realms/{realmEID}/files/{pathname} <ul><li>Delete file:<ul><li>urn:ayode:privilege-action:/realm-file-system/file/delete</li><li>Scope: realm.</li></ul></li></ul>
Assets GET /v2/realms/{realmEID}/files/{pathname} <ul><li>Directory listing:<ul><li>urn:ayode:privilege-action:/realm-file-system/directory/read</li><li>Scope: realm.</li></ul></li><li>File content:<ul><li>urn:ayode:privilege-action:/realm-file-system/file/read</li><li>Scope: realm.</li></ul></li><li>File versions:<ul><li>urn:ayode:privilege-action:/realm-file-system/file/versions/list</li><li>Scope: realm.</li></ul></li></ul>
Assets PATCH /v2/realms/{realmEID}/files/{pathname} <ul><li>Create file:<ul><li>urn:ayode:privilege-action:/realm-file-system/file/create</li><li>Scope: realm.</li><li>Applies when the target file does not yet exist.</li></ul></li><li>Write new version:<ul><li>urn:ayode:privilege-action:/realm-file-system/file/write</li><li>Scope: realm.</li><li>Applies when the target file already exists.</li></ul></li></ul>
Assets POST /v2/realms/{realmEID}/files/{pathname} <ul><li>Create file:<ul><li>urn:ayode:privilege-action:/realm-file-system/file/create</li><li>Scope: realm.</li><li>Applies when the target file does not yet exist.</li></ul></li><li>Write new version:<ul><li>urn:ayode:privilege-action:/realm-file-system/file/write</li><li>Scope: realm.</li><li>Applies when the target file already exists.</li></ul></li></ul>
Assets PUT /v2/realms/{realmEID}/files/{pathname} <ul><li>Create file:<ul><li>urn:ayode:privilege-action:/realm-file-system/file/create</li><li>Scope: realm.</li><li>Applies when the target file does not yet exist.</li></ul></li><li>Write new version:<ul><li>urn:ayode:privilege-action:/realm-file-system/file/write</li><li>Scope: realm.</li><li>Applies when the target file already exists.</li></ul></li></ul>
Assets GET /v3/assets/{realmEID}/{zone} <ul><li>Read the directory contents:<ul><li>urn:ayode:privilege-action:/file-system/directory/read</li><li>Scope: self or realm.</li><li>based on zone</li></ul></li></ul>
Assets GET /v3/assets/{realmEID}/{zone}/{pathname} <ul><li>Directory listing:<ul><li>urn:ayode:privilege-action:/file-system/directory/read</li><li>Scope: self or realm.</li><li>Uses self scope when zone is ~ or the caller's own user EID; realm scope when zone is another user's EID.</li></ul></li><li>File content:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self or realm.</li><li>Uses self scope when zone is ~ or the caller's own user EID; realm scope when zone is another user's EID.</li></ul></li><li>File versions:<ul><li>urn:ayode:privilege-action:/file-system/file/versions/list</li><li>Scope: self or realm.</li><li>Uses self scope when zone is ~ or the caller's own user EID; realm scope when zone is another user's EID.</li></ul></li></ul>
Browser Observability GET /v1/browser-diagnostic-sessions <ul><li>Read browser diagnostic sessions:<ul><li>urn:ayode:privilege-action:/api/browser-diagnostic-sessions/read</li><li>Scope: none.</li></ul></li></ul>
Browser Observability POST /v1/browser-diagnostic-sessions <ul><li>None. This endpoint is public.</li></ul>
Browser Observability GET /v1/browser-diagnostic-sessions/{sessionID} <ul><li>Read browser diagnostic sessions:<ul><li>urn:ayode:privilege-action:/api/browser-diagnostic-sessions/read</li><li>Scope: none.</li></ul></li></ul>
Browser Observability POST /v1/browser-diagnostic-sessions/{sessionID}/associate-user <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Browser Observability POST /v1/browser-diagnostic-sessions/{sessionID}/close <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Browser Observability GET /v1/browser-diagnostic-sessions/{sessionID}/endpoint-invocations <ul><li>Read browser diagnostic sessions:<ul><li>urn:ayode:privilege-action:/api/browser-diagnostic-sessions/read</li><li>Scope: none.</li></ul></li></ul>
Browser Observability GET /v1/browser-diagnostic-sessions/{sessionID}/events <ul><li>Read browser diagnostic sessions:<ul><li>urn:ayode:privilege-action:/api/browser-diagnostic-sessions/read</li><li>Scope: none.</li></ul></li></ul>
Browser Observability POST /v1/browser-diagnostic-sessions/{sessionID}/events <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Browser Observability POST /v1/browser-observability/endpoint-invocations <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Browser Observability POST /v1/browser-observability/logs <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Browser Observability GET /v1/shell-terminal-sessions <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Browser Observability POST /v1/shell-terminal-sessions <ul><li>None. This endpoint is public.</li></ul>
Browser Observability GET /v1/shell-terminal-sessions/{sessionID} <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Browser Observability POST /v1/shell-terminal-sessions/{sessionID}/chunks <ul><li>None. This endpoint is public.</li></ul>
Browser Observability POST /v1/shell-terminal-sessions/{sessionID}/close <ul><li>None. This endpoint is public.</li></ul>
Browser Observability GET /v1/shell-terminal-sessions/{sessionID}/events <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Chat GET /v1/chat/channels <ul><li>List chat channels:<ul><li>urn:ayode:privilege-action:/chat/channels/read</li><li>Scope: realm.</li></ul></li></ul>
Chat POST /v1/chat/channels <ul><li>Create chat channel:<ul><li>urn:ayode:privilege-action:/chat/channels/create</li><li>Scope: realm.</li></ul></li></ul>
Chat GET /v1/chat/channels/{channelEID} <ul><li>Read chat channel:<ul><li>urn:ayode:privilege-action:/chat/channels/read</li><li>Scope: realm.</li></ul></li></ul>
Chat GET /v1/chat/channels/{channelEID}/threads <ul><li>List chat threads:<ul><li>urn:ayode:privilege-action:/chat/channels/read</li><li>Scope: realm.</li></ul></li></ul>
Chat POST /v1/chat/channels/{channelEID}/threads <ul><li>Create chat thread:<ul><li>urn:ayode:privilege-action:/chat/threads/create</li><li>Scope: realm.</li></ul></li></ul>
Chat GET /v1/chat/events <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Chat DELETE /v1/chat/messages/{messageEID} <ul><li>Delete chat message:<ul><li>urn:ayode:privilege-action:/chat/messages/delete</li><li>Scope: self.</li></ul></li></ul>
Chat GET /v1/chat/messages/{messageEID} <ul><li>Read chat messages:<ul><li>urn:ayode:privilege-action:/chat/messages/read</li><li>Scope: realm.</li></ul></li></ul>
Chat PATCH /v1/chat/messages/{messageEID} <ul><li>Edit chat message:<ul><li>urn:ayode:privilege-action:/chat/messages/edit</li><li>Scope: self.</li></ul></li></ul>
Chat GET /v1/chat/messages/{messageEID}/history <ul><li>Read chat messages:<ul><li>urn:ayode:privilege-action:/chat/messages/read</li><li>Scope: realm.</li></ul></li></ul>
Chat DELETE /v1/chat/messages/{messageEID}/reactions <ul><li>React to chat message:<ul><li>urn:ayode:privilege-action:/chat/messages/react</li><li>Scope: realm.</li></ul></li></ul>
Chat POST /v1/chat/messages/{messageEID}/reactions <ul><li>React to chat message:<ul><li>urn:ayode:privilege-action:/chat/messages/react</li><li>Scope: realm.</li></ul></li></ul>
Chat GET /v1/chat/threads/{threadEID} <ul><li>Read chat thread:<ul><li>urn:ayode:privilege-action:/chat/threads/read</li><li>Scope: realm.</li></ul></li></ul>
Chat PATCH /v1/chat/threads/{threadEID} <ul><li>Update chat thread:<ul><li>urn:ayode:privilege-action:/chat/threads/update</li><li>Scope: realm.</li></ul></li></ul>
Chat POST /v1/chat/threads/{threadEID}/leave <ul><li>Leave chat thread:<ul><li>urn:ayode:privilege-action:/chat/threads/removeMember</li><li>Scope: self.</li></ul></li></ul>
Chat GET /v1/chat/threads/{threadEID}/members <ul><li>Read chat thread:<ul><li>urn:ayode:privilege-action:/chat/threads/read</li><li>Scope: realm.</li></ul></li></ul>
Chat DELETE /v1/chat/threads/{threadEID}/members/{userEID} <ul><li>Remove chat thread member:<ul><li>urn:ayode:privilege-action:/chat/threads/removeMember</li><li>Scope: realm.</li></ul></li></ul>
Chat POST /v1/chat/threads/{threadEID}/members/{userEID} <ul><li>Add chat thread member:<ul><li>urn:ayode:privilege-action:/chat/threads/addMember</li><li>Scope: realm.</li></ul></li></ul>
Chat GET /v1/chat/threads/{threadEID}/membership-history <ul><li>Read chat thread:<ul><li>urn:ayode:privilege-action:/chat/threads/read</li><li>Scope: realm.</li></ul></li></ul>
Chat GET /v1/chat/threads/{threadEID}/messages <ul><li>Read chat messages:<ul><li>urn:ayode:privilege-action:/chat/messages/read</li><li>Scope: realm.</li></ul></li></ul>
Chat POST /v1/chat/threads/{threadEID}/messages <ul><li>Post chat message:<ul><li>urn:ayode:privilege-action:/chat/messages/post</li><li>Scope: realm.</li></ul></li></ul>
Chat POST /v1/chat/threads/{threadEID}/moderator-messages <ul><li>Post as moderator:<ul><li>urn:ayode:privilege-action:/chat/messages/postAsModerator</li><li>Scope: realm.</li></ul></li></ul>
Chat GET /v1/chat/threads/{threadEID}/reactions <ul><li>Read chat messages:<ul><li>urn:ayode:privilege-action:/chat/messages/read</li><li>Scope: realm.</li></ul></li></ul>
Chat POST /v1/chat/threads/{threadEID}/read-marker <ul><li>Update chat read marker:<ul><li>urn:ayode:privilege-action:/chat/readMarker/update</li><li>Scope: self.</li></ul></li></ul>
Chat GET /v1/chat/threads/{threadEID}/read-receipts <ul><li>Read chat thread read receipts:<ul><li>urn:ayode:privilege-action:/chat/readReceipts/read</li><li>Scope: realm.</li></ul></li></ul>
Chat POST /v1/chat/threads/{threadEID}/terminate <ul><li>Terminate chat thread:<ul><li>urn:ayode:privilege-action:/chat/threads/terminate</li><li>Scope: realm.</li></ul></li></ul>
Chat GET /v1/chat/unread-counts <ul><li>Read chat unread counts:<ul><li>urn:ayode:privilege-action:/chat/unreadCounts/read</li><li>Scope: self.</li></ul></li></ul>
Connections DELETE /v1/connections/google <ul><li>Access Google APIs:<ul><li>urn:ayode:privilege-action:/integrations/google/apis</li><li>Scope: self.</li></ul></li></ul>
Connections GET /v1/connections/google <ul><li>Access Google APIs:<ul><li>urn:ayode:privilege-action:/integrations/google/apis</li><li>Scope: self.</li></ul></li></ul>
Connections GET /v1/connections/google/authorize <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Connections GET /v1/connections/google/callback <ul><li>None. This endpoint is public.</li></ul>
Connections GET /v1/connections/google/services/drive/imports/status/{sourcePath} <ul><li>Access Google APIs:<ul><li>urn:ayode:privilege-action:/integrations/google/apis</li><li>Scope: self.</li></ul></li></ul>
Connections PATCH /v1/connections/google/services/drive/imports/{sourcePath} <ul><li>Write file contents:<ul><li>urn:ayode:privilege-action:/file-system/file/write</li></ul></li></ul>
Connections PUT /v1/connections/google/services/drive/imports/{sourcePath} <ul><li>Access Google APIs:<ul><li>urn:ayode:privilege-action:/integrations/google/apis</li><li>Scope: self.</li></ul></li><li>Write file contents:<ul><li>urn:ayode:privilege-action:/file-system/file/write</li></ul></li></ul>
Connections GET /v1/connections/google/services/drive/{pathname} <ul><li>Access Google APIs:<ul><li>urn:ayode:privilege-action:/integrations/google/apis</li><li>Scope: self.</li></ul></li></ul>
Content Delivery POST /v1/contents/images/uploads/{filename} <ul><li>Create content delivery image:<ul><li>urn:ayode:privilege-action:/content-delivery-storage/create/images</li><li>Scope: none.</li></ul></li></ul>
Content Delivery POST /v1/contents/images/urls <ul><li>Create content delivery image:<ul><li>urn:ayode:privilege-action:/content-delivery-storage/create/images</li><li>Scope: none.</li></ul></li></ul>
Content Delivery POST /v1/contents/javascript/uploads/{filename} <ul><li>Create content delivery JavaScript:<ul><li>urn:ayode:privilege-action:/content-delivery-storage/create/javascript</li><li>Scope: none.</li></ul></li></ul>
Content Delivery POST /v1/contents/javascript/urls <ul><li>Create content delivery JavaScript:<ul><li>urn:ayode:privilege-action:/content-delivery-storage/create/javascript</li><li>Scope: none.</li></ul></li></ul>
Gaming GET /v1/games/{realm-eid}/{league-eid}/{game-eid}/plays <ul><li>List plays:<ul><li>urn:ayode:privilege-action:/play/list</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/games/{realm-eid}/{league-eid}/{game-eid}/plays <ul><li>Record play:<ul><li>urn:ayode:privilege-action:/play/record</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/leagues/{realm-eid} <ul><li>List leagues:<ul><li>urn:ayode:privilege-action:/league/list</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/leagues/{realm-eid} <ul><li>Create league:<ul><li>urn:ayode:privilege-action:/league/create</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming DELETE /v1/leagues/{realm-eid}/{league-eid} <ul><li>Delete league:<ul><li>urn:ayode:privilege-action:/league/delete</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/leagues/{realm-eid}/{league-eid} <ul><li>Read league:<ul><li>urn:ayode:privilege-action:/league/read</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming PATCH /v1/leagues/{realm-eid}/{league-eid} <ul><li>Update league:<ul><li>urn:ayode:privilege-action:/league/update</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming DELETE /v1/plays/{play-eid} <ul><li>Invalidate play:<ul><li>urn:ayode:privilege-action:/play/invalidate</li><li>Scope: realm.</li></ul></li></ul>
Gaming GET /v1/plays/{play-eid} <ul><li>Read play:<ul><li>urn:ayode:privilege-action:/play/read</li><li>Scope: realm.</li></ul></li></ul>
Gaming GET /v1/seasons/{realm-eid}/{league-eid} <ul><li>List seasons:<ul><li>urn:ayode:privilege-action:/season/list</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/seasons/{realm-eid}/{league-eid} <ul><li>Create season:<ul><li>urn:ayode:privilege-action:/season/create</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming DELETE /v1/seasons/{realm-eid}/{league-eid}/{season-eid} <ul><li>Delete season:<ul><li>urn:ayode:privilege-action:/season/delete</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/seasons/{realm-eid}/{league-eid}/{season-eid} <ul><li>Read season:<ul><li>urn:ayode:privilege-action:/season/read</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming PATCH /v1/seasons/{realm-eid}/{league-eid}/{season-eid} <ul><li>Update season:<ul><li>urn:ayode:privilege-action:/season/update</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/games <ul><li>List games:<ul><li>urn:ayode:privilege-action:/game/list</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/games <ul><li>Create game:<ul><li>urn:ayode:privilege-action:/game/create</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming DELETE /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/games/{game-eid} <ul><li>Delete game:<ul><li>urn:ayode:privilege-action:/game/delete</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/games/{game-eid} <ul><li>Read game:<ul><li>urn:ayode:privilege-action:/game/read</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming PATCH /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/games/{game-eid} <ul><li>Update game:<ul><li>urn:ayode:privilege-action:/game/update</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/games/{game-eid}/complete <ul><li>Complete game:<ul><li>urn:ayode:privilege-action:/game/update</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/games/{game-eid}/participants <ul><li>List game participants:<ul><li>urn:ayode:privilege-action:/game/read</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/games/{game-eid}/participants <ul><li>Manage game participants:<ul><li>urn:ayode:privilege-action:/game/manage</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming DELETE /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/games/{game-eid}/participants/{team-eid} <ul><li>Manage game participants:<ul><li>urn:ayode:privilege-action:/game/manage</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/games/{game-eid}/participants/{team-eid} <ul><li>Read game participant:<ul><li>urn:ayode:privilege-action:/game/read</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming PATCH /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/games/{game-eid}/participants/{team-eid} <ul><li>Manage game participants:<ul><li>urn:ayode:privilege-action:/game/manage</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/games/{game-eid}/start <ul><li>Start game:<ul><li>urn:ayode:privilege-action:/game/update</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/leaderboard <ul><li>Read season leaderboard:<ul><li>urn:ayode:privilege-action:/season/read</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/teams <ul><li>List season participants:<ul><li>urn:ayode:privilege-action:/season/read</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming DELETE /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/teams/{team-eid} <ul><li>Withdraw team from season:<ul><li>urn:ayode:privilege-action:/season/register</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/teams/{team-eid} <ul><li>Read season participant:<ul><li>urn:ayode:privilege-action:/season/read</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/seasons/{realm-eid}/{league-eid}/{season-eid}/teams/{team-eid} <ul><li>Register team for season:<ul><li>urn:ayode:privilege-action:/season/register</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/skills <ul><li>List skills:<ul><li>urn:ayode:privilege-action:/team/join</li><li>Scope: self.</li></ul></li></ul>
Gaming GET /v1/teams/{realm-eid}/{league-eid} <ul><li>List teams:<ul><li>urn:ayode:privilege-action:/team/list</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/teams/{realm-eid}/{league-eid} <ul><li>Create team:<ul><li>urn:ayode:privilege-action:/team/create</li><li>Scope: self or realm.</li><li>Self scope applies when managerUserEID resolves to the current caller.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming DELETE /v1/teams/{realm-eid}/{league-eid}/{team-eid} <ul><li>Delete team:<ul><li>urn:ayode:privilege-action:/team/delete</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/teams/{realm-eid}/{league-eid}/{team-eid} <ul><li>Read team:<ul><li>urn:ayode:privilege-action:/team/read</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming PATCH /v1/teams/{realm-eid}/{league-eid}/{team-eid} <ul><li>Update team:<ul><li>urn:ayode:privilege-action:/team/update</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/teams/{realm-eid}/{league-eid}/{team-eid}/activate <ul><li>Activate team:<ul><li>urn:ayode:privilege-action:/team/update</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/teams/{realm-eid}/{league-eid}/{team-eid}/bans <ul><li>Manage team bans:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/teams/{realm-eid}/{league-eid}/{team-eid}/bans <ul><li>Manage team bans:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming DELETE /v1/teams/{realm-eid}/{league-eid}/{team-eid}/bans/{user-eid} <ul><li>Manage team bans:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming PUT /v1/teams/{realm-eid}/{league-eid}/{team-eid}/captain <ul><li>Manage team roster:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/teams/{realm-eid}/{league-eid}/{team-eid}/desired-skills <ul><li>List team desired skills:<ul><li>urn:ayode:privilege-action:/team/join</li><li>Scope: self.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming PUT /v1/teams/{realm-eid}/{league-eid}/{team-eid}/desired-skills <ul><li>Replace team desired skills:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/teams/{realm-eid}/{league-eid}/{team-eid}/leave <ul><li>Leave team:<ul><li>urn:ayode:privilege-action:/team/leave</li><li>Scope: self.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/teams/{realm-eid}/{league-eid}/{team-eid}/members <ul><li>List team members:<ul><li>urn:ayode:privilege-action:/team/read</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/teams/{realm-eid}/{league-eid}/{team-eid}/members <ul><li>Manage team roster:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming DELETE /v1/teams/{realm-eid}/{league-eid}/{team-eid}/members/{user-eid} <ul><li>Manage team roster:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/teams/{realm-eid}/{league-eid}/{team-eid}/members/{user-eid} <ul><li>Read team membership:<ul><li>urn:ayode:privilege-action:/team/read</li><li>Scope: self or realm.</li><li>Uses self scope when userEID=~; realm scope when userEID is explicit.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/teams/{realm-eid}/{league-eid}/{team-eid}/membership-requests <ul><li>Manage team membership requests:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/teams/{realm-eid}/{league-eid}/{team-eid}/membership-requests <ul><li>Create invite:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Applies when requestType=invite. Self scope applies when the caller is the current team manager.</li></ul></li><li>Create application:<ul><li>urn:ayode:privilege-action:/team/join</li><li>Scope: self.</li><li>Applies when requestType=apply.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/teams/{realm-eid}/{league-eid}/{team-eid}/membership-requests/{request-eid} <ul><li>Read team membership request:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/teams/{realm-eid}/{league-eid}/{team-eid}/membership-requests/{request-eid}/accept <ul><li>Accept invite:<ul><li>urn:ayode:privilege-action:/team/join</li><li>Scope: self.</li><li>Applies when the request is an invite and the invited user accepts it.</li></ul></li><li>Accept application:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Applies when the request is an apply and the current team manager accepts it.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/teams/{realm-eid}/{league-eid}/{team-eid}/membership-requests/{request-eid}/decline <ul><li>Decline invite:<ul><li>urn:ayode:privilege-action:/team/join</li><li>Scope: self.</li><li>Applies when the request is an invite and the invited user declines it.</li></ul></li><li>Decline application:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Applies when the request is an apply and the current team manager declines it.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming POST /v1/teams/{realm-eid}/{league-eid}/{team-eid}/membership-requests/{request-eid}/withdraw <ul><li>Withdraw invite:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Applies when the request is an invite and the current team manager withdraws it.</li></ul></li><li>Withdraw application:<ul><li>urn:ayode:privilege-action:/team/join</li><li>Scope: self.</li><li>Applies when the request is an apply and the requesting user withdraws it.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/teams/{realm-eid}/{league-eid}/{team-eid}/skill-matches/users <ul><li>List team skill user matches:<ul><li>urn:ayode:privilege-action:/team/manage</li><li>Scope: self or realm.</li><li>Self scope applies when the caller is the current team manager.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming GET /v1/teams/{realm-eid}/{league-eid}/{team-eid}/skill-summary <ul><li>Read team skill summary:<ul><li>urn:ayode:privilege-action:/team/join</li><li>Scope: self.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Gaming PATCH /v2/leagues/{realm-eid}/{league-eid} <ul><li>Update league:<ul><li>urn:ayode:privilege-action:/league/update</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Jobs POST /v2/jobs/execution-content/uploads <ul><li>Create job execution content bundle:<ul><li>urn:ayode:privilege-action:/job-execution-content/create</li><li>Scope: none.</li></ul></li></ul>
Jobs PATCH /v2/jobs/execution-content/uploads/{id} <ul><li>Create job execution content bundle:<ul><li>urn:ayode:privilege-action:/job-execution-content/create</li><li>Scope: none.</li><li>Checked at initialize time; the caller finalizing must also be the session's own initiator (403 otherwise).</li></ul></li></ul>
Jobs POST /v2/jobs/execution-content/uploads/{id} <ul><li>Create job execution content bundle:<ul><li>urn:ayode:privilege-action:/job-execution-content/create</li><li>Scope: none.</li></ul></li></ul>
Jobs GET /v2/jobs/execution-content/uploads/{id}/status <ul><li>Create job execution content bundle:<ul><li>urn:ayode:privilege-action:/job-execution-content/create</li><li>Scope: none.</li></ul></li></ul>
Jobs GET /v2/jobs/{pathname} <ul><li>Read job:<ul><li>urn:ayode:privilege-action:/job/read</li><li>Scope: self.</li></ul></li><li>Update job progress:<ul><li>urn:ayode:privilege-action:/job/update</li><li>Scope: self.</li><li>Enforced only on a poll that observes a fresh, non-terminal HTCondor status and upserts progress via api_jwt_jobsUpdateProgress_v1 – not on every poll.</li></ul></li></ul>
Jobs POST /v2/jobs/{pathname} <ul><li>Create a new job:<ul><li>urn:ayode:privilege-action:/job/create</li><li>Scope: self.</li></ul></li></ul>
Lessons GET /v2/assignments <ul><li>List assignments:<ul><li>urn:ayode:privilege-action:/assignment/list</li><li>Scope: realm.</li></ul></li><li>Staff visibility (evaluated internally):<ul><li>urn:ayode:privilege-action:/assignment/create</li><li>Scope: realm.</li><li>Evaluated internally; its absence narrows the result to learner-visible rows and never denies the request.</li></ul></li></ul>
Lessons POST /v2/assignments <ul><li>Create assignment:<ul><li>urn:ayode:privilege-action:/assignment/create</li><li>Scope: realm.</li></ul></li><li>Read back the created assignment:<ul><li>urn:ayode:privilege-action:/assignment/read</li><li>Scope: realm.</li><li>Evaluated internally after the assignment row is created, to build the response body.</li></ul></li></ul>
Lessons POST /v2/assignments/bulk <ul><li>Create assignment (per requested section):<ul><li>urn:ayode:privilege-action:/assignment/create</li><li>Scope: realm.</li><li>Evaluated once per requested section, scoped to that section's realm.</li></ul></li></ul>
Lessons POST /v2/assignments/confirm <ul><li>Create assignment (per section / per draft assignment):<ul><li>urn:ayode:privilege-action:/assignment/create</li><li>Scope: realm.</li><li>Evaluated per section / per draft assignment, scoped to that section's realm.</li></ul></li></ul>
Lessons POST /v2/assignments/review <ul><li>Create assignment (review/preview surface):<ul><li>urn:ayode:privilege-action:/assignment/create</li><li>Scope: realm.</li><li>Evaluated per requested section / run, scoped to the section's realm.</li></ul></li></ul>
Lessons GET /v2/assignments/target-options <ul><li>List assignment target options:<ul><li>urn:ayode:privilege-action:/assignment/create</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/assignments/target-summary <ul><li>Read assignment target summary:<ul><li>urn:ayode:privilege-action:/assignment/create</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/assignments/{assignmentEID} <ul><li>Read assignment:<ul><li>urn:ayode:privilege-action:/assignment/read</li><li>Scope: realm.</li></ul></li><li>Staff visibility (evaluated internally):<ul><li>urn:ayode:privilege-action:/assignment/create</li><li>Scope: realm.</li><li>Evaluated internally; its absence narrows visibility to learner-visible rows (404 Not Found otherwise) and never denies the request outright.</li></ul></li></ul>
Lessons GET /v2/assignments/{assignmentEID}/challenges <ul><li>List assignment challenges:<ul><li>urn:ayode:privilege-action:/assignment/challenge/list</li><li>Scope: realm.</li></ul></li><li>Staff visibility via assignment authoring (evaluated internally):<ul><li>urn:ayode:privilege-action:/assignment/create</li><li>Scope: realm.</li><li>Evaluated internally against the parent assignment's section realm; either this or Staff visibility via assignment-challenge authoring resolves the caller as staff, which widens the result beyond learner-visible rows. Absence of both narrows visibility to learner-visible rows (404 Not Found when the parent is not visible) and never denies the request outright.</li></ul></li><li>Staff visibility via assignment-challenge authoring (evaluated internally):<ul><li>urn:ayode:privilege-action:/assignment/challenge/create</li><li>Scope: realm.</li><li>Evaluated internally against the parent assignment's section realm; either this or Staff visibility via assignment authoring resolves the caller as staff, which widens the result beyond learner-visible rows. Absence of both narrows visibility to learner-visible rows (404 Not Found when the parent is not visible) and never denies the request outright.</li></ul></li></ul>
Lessons POST /v2/assignments/{assignmentEID}/challenges <ul><li>Create assignment challenge:<ul><li>urn:ayode:privilege-action:/assignment/challenge/create</li><li>Scope: realm.</li></ul></li><li>Read back the created assignment challenge:<ul><li>urn:ayode:privilege-action:/assignment/challenge/read</li><li>Scope: realm.</li><li>Evaluated internally after the assignment challenge row is created, to build the response body. This grant is defensive: no known live caller reaches this endpoint today, but the readback enforces the privilege regardless.</li></ul></li></ul>
Lessons GET /v2/assignments/{assignmentEID}/challenges/{assignmentChallengeEID} <ul><li>Read assignment challenge:<ul><li>urn:ayode:privilege-action:/assignment/challenge/read</li><li>Scope: realm.</li></ul></li><li>Staff visibility via assignment authoring (evaluated internally):<ul><li>urn:ayode:privilege-action:/assignment/create</li><li>Scope: realm.</li><li>Evaluated internally against the parent assignment's section realm; either this or Staff visibility via assignment-challenge authoring resolves the caller as staff, which widens visibility beyond learner-visible rows. Absence of both narrows visibility to learner-visible rows (404 Not Found when the parent is not visible) and never denies the request outright.</li></ul></li><li>Staff visibility via assignment-challenge authoring (evaluated internally):<ul><li>urn:ayode:privilege-action:/assignment/challenge/create</li><li>Scope: realm.</li><li>Evaluated internally against the parent assignment's section realm; either this or Staff visibility via assignment authoring resolves the caller as staff, which widens visibility beyond learner-visible rows. Absence of both narrows visibility to learner-visible rows (404 Not Found when the parent is not visible) and never denies the request outright.</li></ul></li></ul>
Lessons GET /v2/assignments/{assignmentEID}/challenges/{assignmentChallengeEID}/gameplay-policies <ul><li>List assignment challenge gameplay policies:<ul><li>urn:ayode:privilege-action:/assignment/challenge/gameplay-policy/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/assignments/{assignmentEID}/challenges/{assignmentChallengeEID}/gameplay-policies <ul><li>Create assignment challenge gameplay policy:<ul><li>urn:ayode:privilege-action:/assignment/challenge/gameplay-policy/create</li><li>Scope: realm.</li></ul></li><li>Read back the created assignment challenge gameplay policy:<ul><li>urn:ayode:privilege-action:/assignment/challenge/gameplay-policy/read</li><li>Scope: realm.</li><li>Evaluated internally after the gameplay policy row is created, to build the response body. This grant is defensive: no known live caller reaches this endpoint today, but the readback enforces the privilege regardless.</li></ul></li></ul>
Lessons GET /v2/assignments/{assignmentEID}/challenges/{assignmentChallengeEID}/gameplay-policies/{assignmentChallengeGameplayPolicyEID} <ul><li>Read assignment challenge gameplay policy:<ul><li>urn:ayode:privilege-action:/assignment/challenge/gameplay-policy/read</li><li>Scope: realm.</li></ul></li></ul>
Lessons PATCH /v2/assignments/{assignmentEID}/challenges/{assignmentChallengeEID}/gameplay-policies/{assignmentChallengeGameplayPolicyEID} <ul><li>Update assignment challenge gameplay policy:<ul><li>urn:ayode:privilege-action:/assignment/challenge/gameplay-policy/update</li><li>Scope: realm.</li></ul></li><li>Read back the updated assignment challenge gameplay policy:<ul><li>urn:ayode:privilege-action:/assignment/challenge/gameplay-policy/read</li><li>Scope: realm.</li><li>Evaluated internally after the gameplay policy row is updated, to build the response body. This grant is defensive: no known live caller reaches this endpoint today, but the readback enforces the privilege regardless.</li></ul></li></ul>
Lessons GET /v2/assignments/{assignmentEID}/challenges/{assignmentChallengeEID}/variants <ul><li>List challenge variants:<ul><li>urn:ayode:privilege-action:/challenge/variant/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/assignments/{assignmentEID}/challenges/{assignmentChallengeEID}/variants <ul><li>Create challenge variant:<ul><li>urn:ayode:privilege-action:/challenge/variant/create</li><li>Scope: realm.</li></ul></li><li>Read back the created challenge variant:<ul><li>urn:ayode:privilege-action:/challenge/variant/read</li><li>Scope: realm.</li><li>Evaluated internally after the challenge variant row is created, to build the response body.</li></ul></li></ul>
Lessons GET /v2/assignments/{assignmentEID}/challenges/{assignmentChallengeEID}/variants/{challengeVariantEID} <ul><li>Read challenge variant:<ul><li>urn:ayode:privilege-action:/challenge/variant/read</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/assignments/{assignmentEID}/students/{studentEID}/challenges <ul><li>List challenge assignments:<ul><li>urn:ayode:privilege-action:/challenge/assignment/list</li><li>Scope: self.</li></ul></li></ul>
Lessons GET /v2/assignments/{assignmentEID}/students/{studentEID}/challenges/{challengeAssignmentEID} <ul><li>Read challenge assignment:<ul><li>urn:ayode:privilege-action:/challenge/assignment/read</li><li>Scope: self.</li></ul></li></ul>
Lessons GET /v2/assignments/{assignmentEID}/students/{studentEID}/challenges/{challengeAssignmentEID}/attempts <ul><li>List challenge attempts:<ul><li>urn:ayode:privilege-action:/challenge/attempt/list</li><li>Scope: self.</li></ul></li></ul>
Lessons POST /v2/assignments/{assignmentEID}/students/{studentEID}/challenges/{challengeAssignmentEID}/attempts <ul><li>Create challenge attempt:<ul><li>urn:ayode:privilege-action:/challenge/attempt/create</li><li>Scope: self.</li></ul></li><li>Enqueue job:<ul><li>urn:ayode:privilege-action:/job/create</li><li>Scope: self.</li><li>Enforced only for a jobAsync challenge assignment, via createJobAsyncChallengeAttempt's jobs.CreateProcessV2 call.</li></ul></li></ul>
Lessons GET /v2/assignments/{assignmentEID}/students/{studentEID}/challenges/{challengeAssignmentEID}/attempts/{challengeAttemptEID} <ul><li>Read challenge attempt:<ul><li>urn:ayode:privilege-action:/challenge/attempt/read</li><li>Scope: self.</li></ul></li></ul>
Lessons GET /v2/assignments/{assignmentEID}/students/{studentEID}/challenges/{challengeAssignmentEID}/attempts/{challengeAttemptEID}/result <ul><li>Read challenge result:<ul><li>urn:ayode:privilege-action:/challenge/result/read</li><li>Scope: self.</li></ul></li></ul>
Lessons POST /v2/assignments/{assignmentEID}/students/{studentEID}/challenges/{challengeAssignmentEID}/test <ul><li>Create challenge test:<ul><li>urn:ayode:privilege-action:/challenge/attempt/create</li><li>Scope: self.</li></ul></li><li>Enqueue job:<ul><li>urn:ayode:privilege-action:/job/create</li><li>Scope: self.</li><li>Enforced by jobs.CreateProcessV2's underlying job-enqueue procedures on every call, not conditionally.</li></ul></li></ul>
Lessons GET /v2/challenges <ul><li>List challenges:<ul><li>urn:ayode:privilege-action:/challenge/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/challenges <ul><li>Create challenge:<ul><li>urn:ayode:privilege-action:/challenge/create</li><li>Scope: realm.</li></ul></li><li>Read back the created challenge:<ul><li>urn:ayode:privilege-action:/challenge/read</li><li>Scope: realm.</li><li>Evaluated internally after the challenge row is created, to build the response body.</li></ul></li></ul>
Lessons GET /v2/challenges/{challengeEID} <ul><li>Read challenge:<ul><li>urn:ayode:privilege-action:/challenge/read</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/challenges/{challengeEID}/objective-proposals <ul><li>List challenge-objective alignment proposals:<ul><li>urn:ayode:privilege-action:/challenge/objective/proposal/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons DELETE /v2/challenges/{challengeEID}/objectives/{objectiveEID} <ul><li>Unalign challenge from objective:<ul><li>urn:ayode:privilege-action:/challenge/objective/unalign</li><li>Scope: realm.</li></ul></li></ul>
Lessons PUT /v2/challenges/{challengeEID}/objectives/{objectiveEID} <ul><li>Align challenge to objective:<ul><li>urn:ayode:privilege-action:/challenge/objective/align</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/challenges/{challengeEID}/variants <ul><li>List challenge variants:<ul><li>urn:ayode:privilege-action:/challenge/variant/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/challenges/{challengeEID}/variants <ul><li>Create challenge variant:<ul><li>urn:ayode:privilege-action:/challenge/variant/create</li><li>Scope: realm.</li></ul></li><li>Read back the created challenge variant:<ul><li>urn:ayode:privilege-action:/challenge/variant/read</li><li>Scope: realm.</li><li>Evaluated internally after the challenge variant row is created, to build the response body.</li></ul></li></ul>
Lessons GET /v2/challenges/{challengeEID}/variants/{challengeVariantEID} <ul><li>Read challenge variant:<ul><li>urn:ayode:privilege-action:/challenge/variant/read</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/courses <ul><li>List courses:<ul><li>urn:ayode:privilege-action:/course/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/courses <ul><li>Create course:<ul><li>urn:ayode:privilege-action:/course/create</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/courses/{courseEID} <ul><li>Read course:<ul><li>urn:ayode:privilege-action:/course/read</li><li>Scope: realm.</li></ul></li></ul>
Lessons PATCH /v2/courses/{courseEID} <ul><li>Rename course:<ul><li>urn:ayode:privilege-action:/course/rename</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/courses/{courseEID}/archive <ul><li>Archive course:<ul><li>urn:ayode:privilege-action:/course/archive</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/courses/{courseEID}/objectives <ul><li>List course objectives:<ul><li>urn:ayode:privilege-action:/scope-sequence/objective/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/courses/{courseEID}/objectives <ul><li>Create course objective:<ul><li>urn:ayode:privilege-action:/scope-sequence/objective/create</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/courses/{courseEID}/objectives/generate <ul><li>Generate objective set from standards authority:<ul><li>urn:ayode:privilege-action:/scope-sequence/objective/generate</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/courses/{courseEID}/objectives/generate/status <ul><li>Read objective-set generation status:<ul><li>urn:ayode:privilege-action:/scope-sequence/objective/generate</li><li>Scope: realm.</li></ul></li></ul>
Lessons DELETE /v2/courses/{courseEID}/objectives/{objectiveEID} <ul><li>Retire course objective:<ul><li>urn:ayode:privilege-action:/scope-sequence/objective/retire</li><li>Scope: realm.</li></ul></li></ul>
Lessons PATCH /v2/courses/{courseEID}/objectives/{objectiveEID} <ul><li>Update course objective:<ul><li>urn:ayode:privilege-action:/scope-sequence/objective/update</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/lessons <ul><li>List lessons:<ul><li>urn:ayode:privilege-action:/lesson/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/lessons <ul><li>Create lesson:<ul><li>urn:ayode:privilege-action:/lesson/create</li><li>Scope: realm.</li></ul></li><li>Read back the created lesson:<ul><li>urn:ayode:privilege-action:/lesson/read</li><li>Scope: realm.</li><li>Evaluated internally after the lesson row is created, to build the response body.</li></ul></li><li>Read and validate the referenced published lesson asset and its component content:<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self.</li><li>Evaluated internally on canonicalVariant.lessonPathname at canonicalVariant.lessonAssetVersion, and again on each pinned component contentURI it references, in the caller's own zone of the asserted realm (a lesson is always created from the caller's own asset; copy another user's asset to yourself first). Self scope only – no cross-user read fallback is reachable on this path.</li></ul></li><li>Read and validate the referenced published lesson asset and its component content:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self.</li><li>Same evaluation as the access check above; both must allow.</li></ul></li><li>Read each pinned component assembly manifest (sourceURI):<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self or realm.</li><li>Evaluated once per distinct pinned sourceURI, against that URI's own realm and explicit user zone: self scope when that zone is the caller's, realm scope otherwise. A realm-scope read whose role holds no unconditional realm-scope grant is re-evaluated through the layered read fallbacks, in order: enrolled-course published-lesson content; then same-realm Copy-v2 provenance (the intended way to share a component inside a realm); then lesson authoring – which covers only a lesson variant's own pathname, never a manifest.</li></ul></li><li>Read each pinned component assembly manifest (sourceURI):<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self or realm.</li><li>Same evaluation and fallback order as the access check above; both must allow.</li></ul></li></ul>
Lessons GET /v2/lessons/{lessonEID} <ul><li>Read lesson:<ul><li>urn:ayode:privilege-action:/lesson/read</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/lessons/{lessonEID}/generated-assignments <ul><li>Create mission when mission is supplied:<ul><li>urn:ayode:privilege-action:/mission/create</li><li>Scope: realm.</li></ul></li><li>Read mission when missionEID is supplied:<ul><li>urn:ayode:privilege-action:/mission/read</li><li>Scope: realm.</li></ul></li><li>Read the parent lesson variant before generating the assignment:<ul><li>urn:ayode:privilege-action:/lesson/variant/read</li><li>Scope: realm.</li><li>Evaluated internally to resolve the lesson variant that anchors the generated mission/assignment, before any mission, challenge, or assignment row is created.</li></ul></li><li>Publish the lesson variant (create lesson variant):<ul><li>urn:ayode:privilege-action:/lesson/variant/create</li><li>Scope: realm.</li><li>Evaluated internally, with the same actions as creating a lesson publication, to resolve the lesson publication source and scan its content for protected-service references before any mission, challenge, or assignment row is created, and again when the lesson publication is recorded. Either this privilege or Create lesson satisfies the check.</li></ul></li><li>Publish the lesson variant (create lesson):<ul><li>urn:ayode:privilege-action:/lesson/create</li><li>Scope: realm.</li><li>Evaluated internally only when Create lesson variant is not granted, as the alternative privilege for resolving the lesson publication source and recording the lesson publication.</li></ul></li><li>Create generated challenges:<ul><li>urn:ayode:privilege-action:/challenge/create</li><li>Scope: realm.</li></ul></li><li>Read back created challenges:<ul><li>urn:ayode:privilege-action:/challenge/read</li><li>Scope: realm.</li><li>Evaluated internally after each generated challenge row is created, to build the response body.</li></ul></li><li>Create assignment:<ul><li>urn:ayode:privilege-action:/assignment/create</li><li>Scope: realm.</li></ul></li><li>Read back the created assignment:<ul><li>urn:ayode:privilege-action:/assignment/read</li><li>Scope: realm.</li><li>Evaluated internally after the assignment row is created, to build the response body.</li></ul></li><li>List assignment challenge links for response assembly:<ul><li>urn:ayode:privilege-action:/assignment/challenge/list</li><li>Scope: realm.</li></ul></li><li>Create challenge variants:<ul><li>urn:ayode:privilege-action:/challenge/variant/create</li><li>Scope: realm.</li></ul></li><li>Read back created challenge variants:<ul><li>urn:ayode:privilege-action:/challenge/variant/read</li><li>Scope: realm.</li><li>Evaluated internally after each generated challenge variant row is created, to build the response body.</li></ul></li><li>List existing mission challenges when republishing against a reused mission:<ul><li>urn:ayode:privilege-action:/challenge/list</li><li>Scope: realm.</li><li>Evaluated internally only when reuseMissionEID is supplied, to inspect the generated mission's existing challenge set before deciding what to (re)create.</li></ul></li><li>List existing challenge variants when reusing an existing challenge:<ul><li>urn:ayode:privilege-action:/challenge/variant/list</li><li>Scope: realm.</li><li>Evaluated internally only on the mission-reuse, challenge-reuse branch, to select an existing challenge variant for assignment rather than creating a new one.</li></ul></li></ul>
Lessons POST /v2/lessons/{lessonEID}/generated-challenges <ul><li>Create mission when mission is supplied:<ul><li>urn:ayode:privilege-action:/mission/create</li><li>Scope: realm.</li></ul></li><li>Read mission when missionEID is supplied:<ul><li>urn:ayode:privilege-action:/mission/read</li><li>Scope: realm.</li></ul></li><li>Read the parent lesson variant before generating challenges:<ul><li>urn:ayode:privilege-action:/lesson/variant/read</li><li>Scope: realm.</li><li>Evaluated internally to resolve the lesson variant that anchors the generated mission/challenges, before any mission or challenge row is created.</li></ul></li><li>Create generated challenges:<ul><li>urn:ayode:privilege-action:/challenge/create</li><li>Scope: realm.</li></ul></li><li>Read back created challenges:<ul><li>urn:ayode:privilege-action:/challenge/read</li><li>Scope: realm.</li><li>Evaluated internally after each generated challenge row is created, to build the response body.</li></ul></li><li>Create challenge variants:<ul><li>urn:ayode:privilege-action:/challenge/variant/create</li><li>Scope: realm.</li></ul></li><li>Read back created challenge variants:<ul><li>urn:ayode:privilege-action:/challenge/variant/read</li><li>Scope: realm.</li><li>Evaluated internally after each generated challenge variant row is created, to build the response body.</li></ul></li><li>List existing mission challenges when republishing against a reused mission:<ul><li>urn:ayode:privilege-action:/challenge/list</li><li>Scope: realm.</li><li>Evaluated internally only when reuseMissionEID is supplied, to inspect the generated mission's existing challenge set before deciding what to (re)create.</li></ul></li></ul>
Lessons GET /v2/lessons/{lessonEID}/publications <ul><li>Read lesson:<ul><li>urn:ayode:privilege-action:/lesson/read</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/lessons/{lessonEID}/publications <ul><li>Create lesson variant:<ul><li>urn:ayode:privilege-action:/lesson/variant/create</li><li>Scope: realm.</li></ul></li><li>Create lesson:<ul><li>urn:ayode:privilege-action:/lesson/create</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/lessons/{lessonEID}/relationships <ul><li>List lesson relationships:<ul><li>urn:ayode:privilege-action:/lesson/relationship/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/lessons/{lessonEID}/relationships <ul><li>Create lesson relationship:<ul><li>urn:ayode:privilege-action:/lesson/relationship/create</li><li>Scope: realm.</li></ul></li></ul>
Lessons DELETE /v2/lessons/{lessonEID}/relationships/{lessonRelationshipEID} <ul><li>Delete lesson relationship:<ul><li>urn:ayode:privilege-action:/lesson/relationship/delete</li><li>Scope: realm.</li></ul></li></ul>
Lessons PATCH /v2/lessons/{lessonEID}/status <ul><li>Update lesson:<ul><li>urn:ayode:privilege-action:/lesson/update</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/lessons/{lessonEID}/subgroup-variants <ul><li>Generate lesson variants by subgroup:<ul><li>urn:ayode:privilege-action:/subgroup/lesson-variant/generate</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/lessons/{lessonEID}/subgroup-variants/{generationEID} <ul><li>Read subgroup lesson variant generation:<ul><li>urn:ayode:privilege-action:/subgroup/lesson-variant/generate</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/lessons/{lessonEID}/variants <ul><li>List lesson variants:<ul><li>urn:ayode:privilege-action:/lesson/variant/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/lessons/{lessonEID}/variants <ul><li>Read the parent lesson before creating the variant:<ul><li>urn:ayode:privilege-action:/lesson/read</li><li>Scope: realm.</li><li>Evaluated internally to resolve the parent lesson before the lesson variant row is created.</li></ul></li><li>Create lesson variant:<ul><li>urn:ayode:privilege-action:/lesson/variant/create</li><li>Scope: realm.</li></ul></li><li>Read back the created lesson variant:<ul><li>urn:ayode:privilege-action:/lesson/variant/read</li><li>Scope: realm.</li><li>Evaluated internally after the lesson variant row is created, to build the response body.</li></ul></li><li>Read and validate the referenced lesson asset in the lesson owner's zone:<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self or realm.</li><li>Evaluated internally on lessonPathname at lessonAssetVersion, and again on each pinned component contentURI it references, in the lesson OWNER's zone of the asserted realm: self scope when the caller owns the lesson, realm scope otherwise. A non-owner whose role holds no unconditional realm-scope grant is authorized through the layered read fallbacks, evaluated in order only after that ordinary grant check fails: (1) enrolled-course published-lesson content; (2) same-realm Copy-v2 provenance; (3) lesson authoring – the caller holds a realm-scope /lesson/variant/create or /lesson/create grant in the realm AND the requested pathname is exactly an existing, non-withdrawn lesson variant's own pathname owned by the lesson author. A variant that reuses the lesson's existing asset pathname (at any version) is therefore covered; a brand-new pathname in another author's zone is not.</li></ul></li><li>Read and validate the referenced lesson asset in the lesson owner's zone:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self or realm.</li><li>Same evaluation and fallback order as the access check above; both must allow.</li></ul></li><li>Read each pinned component assembly manifest (sourceURI):<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self or realm.</li><li>Evaluated once per distinct pinned sourceURI, against that URI's own realm and explicit user zone: self scope when that zone is the caller's, realm scope otherwise. A realm-scope read whose role holds no unconditional realm-scope grant is re-evaluated through the layered read fallbacks, in order: enrolled-course published-lesson content; then same-realm Copy-v2 provenance (the intended way to share a component inside a realm); then lesson authoring – which covers only a lesson variant's own pathname, never a manifest.</li></ul></li><li>Read each pinned component assembly manifest (sourceURI):<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self or realm.</li><li>Same evaluation and fallback order as the access check above; both must allow.</li></ul></li></ul>
Lessons GET /v2/lessons/{lessonEID}/variants/{lessonVariantEID} <ul><li>Read lesson variant:<ul><li>urn:ayode:privilege-action:/lesson/variant/read</li><li>Scope: realm.</li></ul></li></ul>
Lessons PATCH /v2/lessons/{lessonEID}/variants/{lessonVariantEID}/content <ul><li>Read the parent lesson before saving content:<ul><li>urn:ayode:privilege-action:/lesson/read</li><li>Scope: realm.</li><li>Evaluated internally to resolve the parent lesson before the edited variant content is saved.</li></ul></li><li>Read lesson variant:<ul><li>urn:ayode:privilege-action:/lesson/variant/read</li><li>Scope: realm.</li></ul></li><li>Update lesson:<ul><li>urn:ayode:privilege-action:/lesson/update</li><li>Scope: realm.</li><li>The caller must additionally be the lesson's own owning instructor; a non-owning realm member holding only the realm-wide grant is rejected with 403 Forbidden_NotLessonOwner.</li></ul></li><li>Write the edited content as a new asset version in the lesson owner's zone:<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self or realm.</li><li>Evaluated internally on the variant's lessonPathname in the lesson OWNER's zone before the copy-on-write version is minted: self scope when the caller owns the lesson, realm scope for a same-realm non-owner. A non-owner's realm-scope access is evaluated through the same layered fallbacks as the reads (enrolled-course published-lesson content, then same-realm Copy-v2 provenance, then lesson authoring). A non-owner who passes this access check mints a new asset version in the owner's zone BEFORE the lesson-owner gate rejects the request with 403 Forbidden_NotLessonOwner; the variant's version pointer is not advanced and the minted version is orphaned.</li></ul></li><li>Write the edited content as a new asset version in the lesson owner's zone:<ul><li>urn:ayode:privilege-action:/file-system/file/write</li><li>Scope: self or realm.</li><li>Evaluated at self scope when the caller owns the lesson, realm scope for a same-realm non-owner, by api_jwt_fileSystemWriteFile_v2 (the V2 write path – the legacy api_jwt_fileSystemWriteFile_v1 hard-codes self and is not reached here) when the pathname already exists in the owner's zone (the normal save). The proc's own authorization call (internal_securityIsActionAuthorizedForJWT_v2) evaluates Layer 1 ONLY – it does not re-run the /file-system/access Layer 2 fallbacks (#4542/#4548/#4585 W1) that the access/read-back checks above use; a same-realm non-owner is authorized here only by the generic realm-scope predicate itself, not by an enrolled-course, Copy-v2-provenance, or lesson-authoring fallback. The persisted Files/FileVersions row is owned by the target (lesson-owner) user in both scopes.</li></ul></li><li>Write the edited content as a new asset version in the lesson owner's zone:<ul><li>urn:ayode:privilege-action:/file-system/file/create</li><li>Scope: self or realm.</li><li>Same evaluation as /file-system/file/write above (self for the owner, realm for a same-realm non-owner via api_jwt_fileSystemWriteFile_v2, Layer 1 only, no Layer 2 fallback), evaluated instead of /file-system/file/write only when the pathname does not yet exist in the owner's zone.</li></ul></li><li>Read back and validate the newly written version and its component content:<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self or realm.</li><li>Evaluated on the newly minted version and again on each pinned component contentURI, in the lesson OWNER's zone, before the lesson-owner gate: self scope when the caller owns the lesson, realm scope for a same-realm non-owner. A non-owner's realm-scope read-back is evaluated through the identical layered fallback chain as the write-access check above (enrolled-course published-lesson content, then same-realm Copy-v2 provenance, then lesson authoring) before the lesson-owner gate rejects the request with 403 Forbidden_NotLessonOwner.</li></ul></li><li>Read back and validate the newly written version and its component content:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self or realm.</li><li>Same evaluation and fallback order as the access check above; both must allow.</li></ul></li><li>Read each pinned component assembly manifest (sourceURI):<ul><li>urn:ayode:privilege-action:/file-system/access</li><li>Scope: self or realm.</li><li>Evaluated once per distinct pinned sourceURI, against that URI's own realm and explicit user zone: self scope when that zone is the caller's, realm scope otherwise. A realm-scope read whose role holds no unconditional realm-scope grant is re-evaluated through the layered read fallbacks, in order: enrolled-course published-lesson content; then same-realm Copy-v2 provenance (the intended way to share a component inside a realm); then lesson authoring – which covers only a lesson variant's own pathname, never a manifest.</li></ul></li><li>Read each pinned component assembly manifest (sourceURI):<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self or realm.</li><li>Same evaluation and fallback order as the access check above; both must allow.</li></ul></li></ul>
Lessons GET /v2/missions <ul><li>List missions:<ul><li>urn:ayode:privilege-action:/mission/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/missions <ul><li>Create mission:<ul><li>urn:ayode:privilege-action:/mission/create</li><li>Scope: realm.</li></ul></li><li>Read back the created mission:<ul><li>urn:ayode:privilege-action:/mission/read</li><li>Scope: realm.</li><li>Evaluated internally after the mission row is created, to build the response body.</li></ul></li></ul>
Lessons GET /v2/missions/{missionEID} <ul><li>Read mission:<ul><li>urn:ayode:privilege-action:/mission/read</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/plans <ul><li>List plans:<ul><li>urn:ayode:privilege-action:/scope-sequence/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/plans <ul><li>Create plan:<ul><li>urn:ayode:privilege-action:/scope-sequence/create</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/plans/{planEID} <ul><li>Read plan:<ul><li>urn:ayode:privilege-action:/scope-sequence/read</li><li>Scope: realm.</li></ul></li></ul>
Lessons PATCH /v2/plans/{planEID} <ul><li>Update plan:<ul><li>urn:ayode:privilege-action:/scope-sequence/update</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/plans/{planEID}/activate-at-term-end <ul><li>Defer plan activation:<ul><li>urn:ayode:privilege-action:/scope-sequence/activate</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/plans/{planEID}/edit-context <ul><li>Read plan edit context:<ul><li>urn:ayode:privilege-action:/scope-sequence/read</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/plans/{planEID}/impact/activation <ul><li>Preview activation impact:<ul><li>urn:ayode:privilege-action:/scope-sequence/read</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/plans/{planEID}/impact/claim-release <ul><li>Preview claim-release impact:<ul><li>urn:ayode:privilege-action:/scope-sequence/unit/objective/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/plans/{planEID}/impact/objective-retirement <ul><li>Preview objective-retirement impact:<ul><li>urn:ayode:privilege-action:/scope-sequence/objective/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/plans/{planEID}/impact/unit-deletion <ul><li>Preview unit-deletion impact:<ul><li>urn:ayode:privilege-action:/scope-sequence/unit/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/plans/{planEID}/units <ul><li>List units:<ul><li>urn:ayode:privilege-action:/scope-sequence/unit/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/plans/{planEID}/units <ul><li>Create unit:<ul><li>urn:ayode:privilege-action:/scope-sequence/unit/create</li><li>Scope: realm.</li></ul></li></ul>
Lessons DELETE /v2/plans/{planEID}/units/{unitEID} <ul><li>Delete unit:<ul><li>urn:ayode:privilege-action:/scope-sequence/unit/delete</li><li>Scope: realm.</li></ul></li></ul>
Lessons PATCH /v2/plans/{planEID}/units/{unitEID} <ul><li>Update unit:<ul><li>urn:ayode:privilege-action:/scope-sequence/unit/update</li><li>Scope: realm.</li></ul></li></ul>
Lessons DELETE /v2/plans/{planEID}/units/{unitEID}/lessons/{lessonEID} <ul><li>Remove lesson:<ul><li>urn:ayode:privilege-action:/scope-sequence/unit/lesson/remove</li><li>Scope: realm.</li></ul></li></ul>
Lessons PUT /v2/plans/{planEID}/units/{unitEID}/lessons/{lessonEID} <ul><li>Place lesson:<ul><li>urn:ayode:privilege-action:/scope-sequence/unit/lesson/place</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/plans/{planEID}/units/{unitEID}/objectives <ul><li>List unit objectives:<ul><li>urn:ayode:privilege-action:/scope-sequence/unit/objective/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons DELETE /v2/plans/{planEID}/units/{unitEID}/objectives/{objectiveEID} <ul><li>Unclaim objective:<ul><li>urn:ayode:privilege-action:/scope-sequence/unit/objective/unclaim</li><li>Scope: realm.</li></ul></li></ul>
Lessons PUT /v2/plans/{planEID}/units/{unitEID}/objectives/{objectiveEID} <ul><li>Claim objective:<ul><li>urn:ayode:privilege-action:/scope-sequence/unit/objective/claim</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/sections <ul><li>List sections:<ul><li>urn:ayode:privilege-action:/section/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/sections <ul><li>Create section:<ul><li>urn:ayode:privilege-action:/section/create</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/sections/{sectionEID} <ul><li>Read section:<ul><li>urn:ayode:privilege-action:/section/read</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/sections/{sectionEID}/archive <ul><li>Archive section:<ul><li>urn:ayode:privilege-action:/section/archive</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/sections/{sectionEID}/members <ul><li>Add member to section:<ul><li>urn:ayode:privilege-action:/section/member/add</li><li>Scope: realm.</li></ul></li></ul>
Lessons DELETE /v2/sections/{sectionEID}/members/{userEID} <ul><li>Remove member from section:<ul><li>urn:ayode:privilege-action:/section/member/remove</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/subjects <ul><li>List subjects:<ul><li>urn:ayode:privilege-action:/subject/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/subjects <ul><li>Create subject:<ul><li>urn:ayode:privilege-action:/subject/create</li><li>Scope: realm.</li></ul></li></ul>
Lessons PATCH /v2/subjects/{subjectEID} <ul><li>Rename subject:<ul><li>urn:ayode:privilege-action:/subject/rename</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/terms <ul><li>List terms:<ul><li>urn:ayode:privilege-action:/term/list</li><li>Scope: realm.</li></ul></li></ul>
Lessons POST /v2/terms <ul><li>Create term:<ul><li>urn:ayode:privilege-action:/term/create</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/users/{userRef}/challenges <ul><li>Enumerate challenge assignments:<ul><li>urn:ayode:privilege-action:/challenge/assignment/enumerate</li><li>Scope: self.</li></ul></li></ul>
Lessons GET /v2/users/{userRef}/courses <ul><li>List sections:<ul><li>urn:ayode:privilege-action:/section/list</li><li>Scope: self.</li></ul></li></ul>
Lessons GET /v2/users/{userRef}/sections <ul><li>List challenge assignments:<ul><li>urn:ayode:privilege-action:/challenge/assignment/list</li><li>Scope: self.</li></ul></li></ul>
Lessons GET /v2/users/{userRef}/sections/{sectionEID}/lessons <ul><li>List challenge assignments:<ul><li>urn:ayode:privilege-action:/challenge/assignment/list</li><li>Scope: self.</li></ul></li></ul>
Lessons POST /v2/workbench-bundles <ul><li>Create workbench bundle:<ul><li>urn:ayode:privilege-action:/workbench-bundle/create</li><li>Scope: realm.</li></ul></li></ul>
Lessons GET /v2/workbench-bundles/{bundleID} <ul><li>Read workbench bundle:<ul><li>urn:ayode:privilege-action:/workbench-bundle/read</li><li>Scope: self or realm.</li><li>Self scope when the caller is the student who dealt/owns the referenced variant, or the instructor who stored the bundle; realm scope when the caller is an instructor who may publish an owning lesson. Evaluated in one authorization-frame-first-result-set; every non-allow outcome collapses to the identical 404 response.</li></ul></li></ul>
Lessons GET /v3/assignments/{assignmentEID}/students/{studentEID}/challenges <ul><li>List challenge assignments:<ul><li>urn:ayode:privilege-action:/challenge/assignment/list</li><li>Scope: self.</li></ul></li></ul>
Lessons > Sections POST /v2/sections/subgroups <ul><li>Detect subgroups:<ul><li>urn:ayode:privilege-action:/subgroup/detect</li><li>Scope: realm.</li></ul></li></ul>
Organizations GET /v1/standard-authorities/{urn} <ul><li>Read standard authorities:<ul><li>urn:ayode:privilege-action:/standard-authorities/read</li><li>Scope: none.</li></ul></li></ul>
Organizations GET /v1/standards/{standardAuthorityEIDurn} <ul><li>Read standard:<ul><li>urn:ayode:privilege-action:/standard/read</li><li>Scope: none.</li></ul></li></ul>
Organizations GET /v1/standards/{standardAuthorityEIDurn}/{standardRootEIDurn} <ul><li>Read standard:<ul><li>urn:ayode:privilege-action:/standard/read</li><li>Scope: none.</li></ul></li></ul>
Organizations GET /v1/worldwide-administrative-divisions <ul><li>Read administrative divisions:<ul><li>urn:ayode:privilege-action:/worldwide-administrative-division/read</li><li>Scope: none.</li></ul></li></ul>
Organizations GET /v1/worldwide-administrative-divisions/{urn} <ul><li>Read worldwide administrative divisions:<ul><li>urn:ayode:privilege-action:/worldwide-administrative-division/read</li><li>Scope: none.</li></ul></li></ul>
Platform Management POST /v1/platform/realms/0/create <ul><li>Create top-level realm:<ul><li>urn:ayode:privilege-action:/platform/realm[0]/create</li><li>Scope: none.</li></ul></li><li>Add top-level realm admin:<ul><li>urn:ayode:privilege-action:/platform/realm[0]/admin/add</li><li>Scope: none.</li></ul></li></ul>
Platform Management GET /v1/platform/users <ul><li>List all platform users:<ul><li>urn:ayode:privilege-action:/platform/users/list</li><li>Scope: none.</li></ul></li></ul>
Platform Management POST /v1/teams/{realm-eid}/{league-eid}/{team-eid}/purge <ul><li>Purge a team:<ul><li>urn:ayode:privilege-action:/platform/teams/purge</li><li>Scope: none.</li></ul></li></ul>
Platform Management DELETE /v1/users/{user-eid} <ul><li>Request user deletion:<ul><li>urn:ayode:privilege-action:/platform/users/delete</li><li>Scope: none.</li></ul></li></ul>
Platform Management GET /v1/users/{user-eid}/deletion-status <ul><li>Read user deletion status:<ul><li>urn:ayode:privilege-action:/platform/users/delete</li><li>Scope: none.</li></ul></li></ul>
Platform Management POST /v1/users/{user-eid}/deletion/approve <ul><li>Approve user deletion:<ul><li>urn:ayode:privilege-action:/platform/users/delete/approve</li><li>Scope: none.</li></ul></li></ul>
Platform Management POST /v1/users/{user-eid}/deletion/deny <ul><li>Deny user deletion:<ul><li>urn:ayode:privilege-action:/platform/users/delete/deny</li><li>Scope: none.</li></ul></li></ul>
Platform Management POST /v2/platform/realms/0/create <ul><li>Create top-level realm:<ul><li>urn:ayode:privilege-action:/platform/realm[0]/create</li><li>Scope: none.</li></ul></li><li>Add top-level realm admin:<ul><li>urn:ayode:privilege-action:/platform/realm[0]/admin/add</li><li>Scope: none.</li></ul></li></ul>
Realms GET /v1/realms/{realm-eid}/statistics <ul><li>Read realm statistics:<ul><li>urn:ayode:privilege-action:/realm/statistics/read</li><li>Scope: realm.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v1/auth/callback <ul><li>None. This endpoint is public.</li></ul>
Security GET /v1/auth/login <ul><li>None. This endpoint is public.</li></ul>
Security POST /v1/auth/shell/access-tokens <ul><li>Access shell:<ul><li>urn:ayode:privilege-action:/shell/access</li><li>Scope: self.</li></ul></li><li>Read the pinned startup script:<ul><li>urn:ayode:privilege-action:/file-system/file/read</li><li>Scope: self or realm.</li><li>required only when startupScript is supplied; evaluated in the realm named by startupScript.realmEID (not necessarily the request's asserted realm); self scope when the caller is startupScript.userEID, otherwise realm scope; checked before the Access shell check above</li></ul></li><li>Use protected web service:<ul><li>urn:ayode:privilege-action:/shell-service/use</li><li>Scope: self.</li><li>Required only when contentRegistrationEID is supplied. Registrations live in the realm where the session runs and may pin a Public-catalog definition by EID; no role holds content-registration or /shell-service/use actions in the Public realm (#5945).</li></ul></li></ul>
Security GET /v1/auth/shell/access-tokens/by-token/{token-eid}/consume <ul><li>Access shell:<ul><li>urn:ayode:privilege-action:/shell/access</li><li>Scope: self.</li></ul></li></ul>
Security GET /v1/auth/shell/access-tokens/extensions/by-token/{token-eid}/consume <ul><li>Access shell:<ul><li>urn:ayode:privilege-action:/shell/access</li><li>Scope: self.</li></ul></li></ul>
Security POST /v1/auth/shell/access-tokens/{session-id}/close <ul><li>None. This endpoint is public.</li></ul>
Security POST /v1/auth/shell/access-tokens/{session-id}/consume <ul><li>None. This endpoint is public.</li></ul>
Security POST /v1/auth/shell/access-tokens/{session-id}/disconnect <ul><li>Access shell:<ul><li>urn:ayode:privilege-action:/shell/access</li><li>Scope: self.</li></ul></li></ul>
Security POST /v1/auth/shell/access-tokens/{session-id}/extend <ul><li>Access shell:<ul><li>urn:ayode:privilege-action:/shell/access</li><li>Scope: self.</li></ul></li></ul>
Security POST /v1/auth/shell/access-tokens/{session-id}/extend/{extension-token}/consume <ul><li>None. This endpoint is public.</li></ul>
Security POST /v1/auth/shell/access-tokens/{session-id}/heartbeat <ul><li>None. This endpoint is public.</li></ul>
Security GET /v1/privilege-actions <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Security GET /v1/privilege-matrix/{realm-eid} <ul><li>List realm privilege matrix:<ul><li>urn:ayode:privilege-action:/realm/privileges/list</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v1/privilege-predicates <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Security GET /v1/privileges/{realm-eid} <ul><li>List privileges in realm:<ul><li>urn:ayode:privilege-action:/privilege/list</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security POST /v1/privileges/{realm-eid} <ul><li>Create privilege:<ul><li>urn:ayode:privilege-action:/privilege/create</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security DELETE /v1/privileges/{realm-eid}/{privilege-eid} <ul><li>Delete privilege:<ul><li>urn:ayode:privilege-action:/privilege/delete</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security PUT /v1/privileges/{realm-eid}/{privilege-eid} <ul><li>Update privilege:<ul><li>urn:ayode:privilege-action:/privilege/update</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v1/realms <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Security POST /v1/realms/instructor-preview/self-enrollment <ul><li>Self-grant Instructor Preview enrollment:<ul><li>urn:ayode:privilege-action:/user/self-grant/instructor-preview</li><li>Scope: self.</li></ul></li></ul>
Security DELETE /v1/realms/{realm-eid} <ul><li>Delete realm:<ul><li>urn:ayode:privilege-action:/realm/delete</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v1/realms/{realm-eid} <ul><li>List realms:<ul><li>urn:ayode:privilege-action:/realm/list</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security PUT /v1/realms/{realm-eid} <ul><li>Rename realm:<ul><li>urn:ayode:privilege-action:/realm/rename</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security POST /v1/realms/{realm-eid}/children <ul><li>Create realm:<ul><li>urn:ayode:privilege-action:/realm/create</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v1/realms/{realm-eid}/default-roles <ul><li>List realm default roles:<ul><li>urn:ayode:privilege-action:/realm/default-roles/list</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security DELETE /v1/realms/{realm-eid}/default-roles/{role-eid} <ul><li>Delete realm default role:<ul><li>urn:ayode:privilege-action:/realm/default-roles/delete</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security POST /v1/realms/{realm-eid}/default-roles/{role-eid} <ul><li>Create realm default role:<ul><li>urn:ayode:privilege-action:/realm/default-roles/create</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v1/realms/{realm-eid}/members <ul><li>List members in realm:<ul><li>urn:ayode:privilege-action:/realm/member/list</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security DELETE /v1/realms/{realm-eid}/members/{user-eid} <ul><li>Remove member from realm:<ul><li>urn:ayode:privilege-action:/realm/member/remove</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security POST /v1/realms/{realm-eid}/members/{user-eid} <ul><li>Add member into realm:<ul><li>urn:ayode:privilege-action:/realm/member/add</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security PUT /v1/realms/{realm-eid}/members/{user-eid}/display-name <ul><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v1/roles/{realm-eid} <ul><li>List roles:<ul><li>urn:ayode:privilege-action:/role/list</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security POST /v1/roles/{realm-eid} <ul><li>Create role:<ul><li>urn:ayode:privilege-action:/role/create</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security DELETE /v1/roles/{realm-eid}/{role-eid} <ul><li>Delete role:<ul><li>urn:ayode:privilege-action:/role/delete</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v1/roles/{realm-eid}/{role-eid} <ul><li>List roles:<ul><li>urn:ayode:privilege-action:/role/list</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security PUT /v1/roles/{realm-eid}/{role-eid} <ul><li>Rename role:<ul><li>urn:ayode:privilege-action:/role/rename</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security DELETE /v1/roles/{realm-eid}/{role-eid}/members <ul><li>Remove member from role:<ul><li>urn:ayode:privilege-action:/role/member/remove</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v1/roles/{realm-eid}/{role-eid}/members <ul><li>List members in role:<ul><li>urn:ayode:privilege-action:/role/member/list</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security POST /v1/roles/{realm-eid}/{role-eid}/members <ul><li>Add member to role:<ul><li>urn:ayode:privilege-action:/role/member/add</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v1/roles/{realm-eid}/{role-eid}/privileges <ul><li>List Role Privileges:<ul><li>urn:ayode:privilege-action:/role/privilege/list</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security DELETE /v1/roles/{realm-eid}/{role-eid}/privileges/{privilege-eid} <ul><li>Remove Privilege from Role:<ul><li>urn:ayode:privilege-action:/role/privilege/remove</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security POST /v1/roles/{realm-eid}/{role-eid}/privileges/{privilege-eid} <ul><li>Associate Privilege to Role:<ul><li>urn:ayode:privilege-action:/role/privilege/add</li><li>Scope: none.</li></ul></li><li>Remove Privilege from Role:<ul><li>urn:ayode:privilege-action:/role/privilege/remove</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v1/shell-services/content-registrations <ul><li>List shell service content registrations:<ul><li>urn:ayode:privilege-action:/shell-service/content/list</li><li>Scope: realm.</li><li>Registrations live in the realm where the session runs and may pin a Public-catalog definition by EID; no role holds content-registration or /shell-service/use actions in the Public realm (#5945).</li></ul></li></ul>
Security POST /v1/shell-services/content-registrations <ul><li>Register shell service content:<ul><li>urn:ayode:privilege-action:/shell-service/content/write</li><li>Scope: realm.</li><li>Registrations live in the realm where the session runs and may pin a Public-catalog definition by EID; no role holds content-registration or /shell-service/use actions in the Public realm (#5945).</li></ul></li></ul>
Security DELETE /v1/shell-services/content-registrations/{registration-eid} <ul><li>Register shell service content:<ul><li>urn:ayode:privilege-action:/shell-service/content/write</li><li>Scope: realm.</li><li>Registrations live in the realm where the session runs and may pin a Public-catalog definition by EID; no role holds content-registration or /shell-service/use actions in the Public realm (#5945).</li></ul></li></ul>
Security GET /v1/shell-services/content-registrations/{registration-eid} <ul><li>Read shell service content registration:<ul><li>urn:ayode:privilege-action:/shell-service/content/read</li><li>Scope: realm.</li><li>Registrations live in the realm where the session runs and may pin a Public-catalog definition by EID; no role holds content-registration or /shell-service/use actions in the Public realm (#5945).</li></ul></li></ul>
Security PUT /v1/shell-services/content-registrations/{registration-eid} <ul><li>Register shell service content:<ul><li>urn:ayode:privilege-action:/shell-service/content/write</li><li>Scope: realm.</li><li>Registrations live in the realm where the session runs and may pin a Public-catalog definition by EID; no role holds content-registration or /shell-service/use actions in the Public realm (#5945).</li></ul></li></ul>
Security GET /v1/shell-services/definitions <ul><li>List shell protected service definitions:<ul><li>urn:ayode:privilege-action:/shell-service/definition/list</li><li>Scope: realm.</li><li>In the Public realm, every member holds this action through the preconfigured Public-Users role (#5994); shell-service content-registration actions and definition write are not granted there.</li></ul></li></ul>
Security POST /v1/shell-services/definitions <ul><li>Define shell protected service:<ul><li>urn:ayode:privilege-action:/shell-service/definition/write</li><li>Scope: realm.</li></ul></li></ul>
Security DELETE /v1/shell-services/definitions/{definition-eid} <ul><li>Define shell protected service:<ul><li>urn:ayode:privilege-action:/shell-service/definition/write</li><li>Scope: realm.</li></ul></li></ul>
Security GET /v1/shell-services/definitions/{definition-eid} <ul><li>Latest version:<ul><li>urn:ayode:privilege-action:/shell-service/definition/read</li><li>Scope: realm.</li><li>In the Public realm, every member holds this action through the preconfigured Public-Users role (#5994); shell-service content-registration actions and definition write are not granted there.</li></ul></li><li>Specific version:<ul><li>urn:ayode:privilege-action:/shell-service/definition/read</li><li>Scope: realm.</li><li>In the Public realm, every member holds this action through the preconfigured Public-Users role (#5994); shell-service content-registration actions and definition write are not granted there.</li></ul></li><li>Version list:<ul><li>urn:ayode:privilege-action:/shell-service/definition/versions/list</li><li>Scope: realm.</li><li>In the Public realm, every member holds this action through the preconfigured Public-Users role (#5994); shell-service content-registration actions and definition write are not granted there.</li></ul></li></ul>
Security PUT /v1/shell-services/definitions/{definition-eid} <ul><li>Define shell protected service:<ul><li>urn:ayode:privilege-action:/shell-service/definition/write</li><li>Scope: realm.</li></ul></li></ul>
Security GET /v1/shell-services/sessions/{session-id}/bundle/{layer}/{ordinal} <ul><li>None. This endpoint is public.</li></ul>
Security POST /v1/shell-storage/sessions/{session-id}/ensure-ready <ul><li>None. This endpoint is public.</li></ul>
Security GET /v1/shells/{user-eid}/quota <ul><li>Read shell quota:<ul><li>urn:ayode:privilege-action:/shell/quota/read</li><li>Scope: self.</li></ul></li></ul>
Security PATCH /v1/shells/{user-eid}/quota <ul><li>Read shell quota:<ul><li>urn:ayode:privilege-action:/shell/quota/read</li><li>Scope: self.</li></ul></li><li>Reduce shell quota:<ul><li>urn:ayode:privilege-action:/shell/quota/reduce</li><li>Scope: self.</li></ul></li></ul>
Security GET /v1/sso/discourse <ul><li>None. This endpoint is public.</li></ul>
Security GET /v1/users/{user-eid}/privileges <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Security POST /v2/link-actions <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Security POST /v2/link-actions/{token}/retrieve <ul><li>None. This endpoint is public.</li></ul>
Security GET /v2/privileges/{realm-eid} <ul><li>List privileges in realm:<ul><li>urn:ayode:privilege-action:/privilege/list</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security POST /v2/privileges/{realm-eid} <ul><li>Create privilege:<ul><li>urn:ayode:privilege-action:/privilege/create</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security PUT /v2/privileges/{realm-eid}/{privilege-eid} <ul><li>Update privilege:<ul><li>urn:ayode:privilege-action:/privilege/update</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v2/realms <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Security GET /v2/realms/{realm-eid} <ul><li>List realms:<ul><li>urn:ayode:privilege-action:/realm/list</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security PUT /v2/realms/{realm-eid} <ul><li>Rename realm:<ul><li>urn:ayode:privilege-action:/realm/rename</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v2/realms/{realm-eid}/assertion-locus <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Security POST /v2/realms/{realm-eid}/default-roles/{role-eid} <ul><li>Create realm default role:<ul><li>urn:ayode:privilege-action:/realm/default-roles/create</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security POST /v2/realms/{realm-eid}/members/{user-eid} <ul><li>Add member into realm:<ul><li>urn:ayode:privilege-action:/realm/member/add</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security POST /v2/roles/{realm-eid} <ul><li>Create role:<ul><li>urn:ayode:privilege-action:/role/create</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security PUT /v2/roles/{realm-eid}/{role-eid} <ul><li>Rename role:<ul><li>urn:ayode:privilege-action:/role/rename</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security POST /v2/roles/{realm-eid}/{role-eid}/members <ul><li>Add member to role:<ul><li>urn:ayode:privilege-action:/role/member/add</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v2/roles/{realm-eid}/{role-eid}/privileges <ul><li>List Role Privileges:<ul><li>urn:ayode:privilege-action:/role/privilege/list</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security POST /v2/roles/{realm-eid}/{role-eid}/privileges/{privilege-eid} <ul><li>Associate Privilege to Role:<ul><li>urn:ayode:privilege-action:/role/privilege/add</li><li>Scope: none.</li></ul></li><li>Remove Privilege from Role:<ul><li>urn:ayode:privilege-action:/role/privilege/remove</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security GET /v2/shell-services/content-registrations <ul><li>List shell service content registrations:<ul><li>urn:ayode:privilege-action:/shell-service/content/list</li><li>Scope: realm.</li><li>Registrations live in the realm where the session runs and may pin a Public-catalog definition by EID; no role holds content-registration or /shell-service/use actions in the Public realm (#5945).</li></ul></li></ul>
Security GET /v2/shell-services/content-registrations/{registration-eid} <ul><li>Read shell service content registration:<ul><li>urn:ayode:privilege-action:/shell-service/content/read</li><li>Scope: realm.</li><li>Registrations live in the realm where the session runs and may pin a Public-catalog definition by EID; no role holds content-registration or /shell-service/use actions in the Public realm (#5945).</li></ul></li></ul>
Security GET /v2/shell-services/definitions <ul><li>List shell protected service definitions:<ul><li>urn:ayode:privilege-action:/shell-service/definition/list</li><li>Scope: realm.</li><li>In the Public realm, every member holds this action through the preconfigured Public-Users role (#5994); shell-service content-registration actions and definition write are not granted there.</li></ul></li></ul>
Security POST /v2/shell-services/definitions <ul><li>Define shell protected service:<ul><li>urn:ayode:privilege-action:/shell-service/definition/write</li><li>Scope: realm.</li></ul></li></ul>
Security GET /v2/shell-services/definitions/{definition-eid} <ul><li>Latest version:<ul><li>urn:ayode:privilege-action:/shell-service/definition/read</li><li>Scope: realm.</li><li>In the Public realm, every member holds this action through the preconfigured Public-Users role (#5994); shell-service content-registration actions and definition write are not granted there.</li></ul></li><li>Specific version:<ul><li>urn:ayode:privilege-action:/shell-service/definition/read</li><li>Scope: realm.</li><li>In the Public realm, every member holds this action through the preconfigured Public-Users role (#5994); shell-service content-registration actions and definition write are not granted there.</li></ul></li><li>Version list:<ul><li>urn:ayode:privilege-action:/shell-service/definition/versions/list</li><li>Scope: realm.</li><li>In the Public realm, every member holds this action through the preconfigured Public-Users role (#5994); shell-service content-registration actions and definition write are not granted there.</li></ul></li></ul>
Security PUT /v2/shell-services/definitions/{definition-eid} <ul><li>Define shell protected service:<ul><li>urn:ayode:privilege-action:/shell-service/definition/write</li><li>Scope: realm.</li></ul></li></ul>
Security POST /v3/privileges/{realm-eid} <ul><li>Create privilege:<ul><li>urn:ayode:privilege-action:/privilege/create</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
Security PUT /v3/privileges/{realm-eid}/{privilege-eid} <ul><li>Update privilege:<ul><li>urn:ayode:privilege-action:/privilege/update</li><li>Scope: none.</li></ul></li><li>Resolve realm path URN:<ul><li>urn:ayode:privilege-action:/realm/map</li><li>Scope: self.</li><li>Required only when the realm-eid path parameter is supplied as a realm path URN (urn:ayode:realm:<path>).</li></ul></li></ul>
System GET /v2/now <ul><li>None. This endpoint is public.</li></ul>
System GET /v2/system/configuration <ul><li>None. This endpoint is public.</li></ul>
Tags GET /v1/tags/{realmEID}/{source}/{entityEID} <ul><li>Read metadata attributes for exercises or assets:<ul><li>urn:ayode:privilege-action:/metadata/attributes/read</li><li>Scope: self.</li><li>Applies when source is exercises or assets.</li></ul></li><li>Read metadata attributes for realm assets:<ul><li>urn:ayode:privilege-action:/realm-assets/metadata/attributes/read</li><li>Scope: realm.</li><li>Applies when source is realmAssets.</li></ul></li></ul>
Tags PATCH /v1/tags/{realmEID}/{source}/{entityEID} <ul><li>Write metadata attributes for exercises or assets:<ul><li>urn:ayode:privilege-action:/metadata/attributes/write</li><li>Scope: self.</li><li>Applies when source is exercises or assets.</li></ul></li><li>Write metadata attributes for realm assets:<ul><li>urn:ayode:privilege-action:/realm-assets/metadata/attributes/write</li><li>Scope: realm.</li><li>Applies when source is realmAssets.</li></ul></li></ul>
Tags GET /v1/tags/{realmEID}/{source}/{entityEID}/{typedTagName} <ul><li>Read metadata attributes for exercises or assets:<ul><li>urn:ayode:privilege-action:/metadata/attributes/read</li><li>Scope: self.</li><li>Applies when source is exercises or assets.</li></ul></li><li>Read metadata attributes for realm assets:<ul><li>urn:ayode:privilege-action:/realm-assets/metadata/attributes/read</li><li>Scope: realm.</li><li>Applies when source is realmAssets.</li></ul></li></ul>
Tags PUT /v1/tags/{realmEID}/{source}/{entityEID}/{typedTagName} <ul><li>Write metadata attributes for exercises or assets:<ul><li>urn:ayode:privilege-action:/metadata/attributes/write</li><li>Scope: self.</li><li>Applies when source is exercises or assets.</li></ul></li><li>Write metadata attributes for realm assets:<ul><li>urn:ayode:privilege-action:/realm-assets/metadata/attributes/write</li><li>Scope: realm.</li><li>Applies when source is realmAssets.</li></ul></li></ul>
Tags GET /v2/tags/entities/{realmEID}/{source} <ul><li>Read metadata attributes for exercises or assets:<ul><li>urn:ayode:privilege-action:/metadata/attributes/read</li><li>Scope: self or realm.</li><li>Applies when source is exercises or assets; scope is based on scope.</li></ul></li><li>Read metadata attributes for realm assets:<ul><li>urn:ayode:privilege-action:/realm-assets/metadata/attributes/read</li><li>Scope: realm.</li><li>Applies when source is realmAssets; scope=realm only.</li></ul></li></ul>
Tags PUT /v2/tags/{realmEID}/{source}/{entityEID}/{typedTagName} <ul><li>Write metadata attributes for exercises or assets:<ul><li>urn:ayode:privilege-action:/metadata/attributes/write</li><li>Scope: self.</li><li>Applies when source is exercises or assets.</li></ul></li><li>Write metadata attributes for realm assets:<ul><li>urn:ayode:privilege-action:/realm-assets/metadata/attributes/write</li><li>Scope: realm.</li><li>Applies when source is realmAssets.</li></ul></li></ul>
Text Extraction POST /v1/text/extract <ul><li>Extract text from documents:<ul><li>urn:ayode:privilege-action:/api/text/extract</li><li>Scope: none.</li></ul></li></ul>
Text Extraction GET /v1/text/extract/{job-id} <ul><li>Extract text from documents:<ul><li>urn:ayode:privilege-action:/api/text/extract</li><li>Scope: none.</li></ul></li></ul>
Text Extraction POST /v2/text/extract <ul><li>Extract text from documents:<ul><li>urn:ayode:privilege-action:/api/text/extract</li><li>Scope: none.</li></ul></li></ul>
Users GET /v1/users/identify-me <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Users GET /v1/users/profile <ul><li>Read user profile:<ul><li>urn:ayode:privilege-action:/user-profile/read</li><li>Scope: self.</li></ul></li></ul>
Users PUT /v1/users/profile <ul><li>Write user profile:<ul><li>urn:ayode:privilege-action:/user-profile/write</li><li>Scope: self.</li></ul></li></ul>
Users GET /v1/users/{user-eid}/advertised-skills <ul><li>List advertised skills:<ul><li>urn:ayode:privilege-action:/team/join</li><li>Scope: self.</li></ul></li></ul>
Users PUT /v1/users/{user-eid}/advertised-skills <ul><li>Replace advertised skills:<ul><li>urn:ayode:privilege-action:/team/join</li><li>Scope: self.</li></ul></li></ul>
Users GET /v1/users/{user-eid}/skill-matches/teams <ul><li>List matching teams:<ul><li>urn:ayode:privilege-action:/team/join</li><li>Scope: self.</li></ul></li></ul>
Users GET /v1/users/{user-eid}/team-requests <ul><li>List personal team requests:<ul><li>urn:ayode:privilege-action:/team/join</li><li>Scope: self.</li><li>The selected user-eid must resolve to the current caller.</li></ul></li></ul>
Users GET /v1/users/{user-eid}/teams <ul><li>List teams:<ul><li>urn:ayode:privilege-action:/team/list</li><li>Scope: self or realm.</li><li>Uses self scope when user-eid=~; realm scope when user-eid is explicit.</li></ul></li></ul>
Users GET /v2/users/crisp/config <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Users GET /v2/users/profile <ul><li>Read user profile:<ul><li>urn:ayode:privilege-action:/user-profile/read</li><li>Scope: self.</li></ul></li></ul>
Users PUT /v2/users/profile <ul><li>Write user profile:<ul><li>urn:ayode:privilege-action:/user-profile/write</li><li>Scope: self.</li></ul></li></ul>
Users GET /v2/users/who-am-i <ul><li>None. This endpoint requires authentication but does not evaluate a privilege action.</li></ul>
Web Extraction POST /v2/web/extract <ul><li>Extract content from web pages:<ul><li>urn:ayode:privilege-action:/api/web/extract</li><li>Scope: none.</li></ul></li></ul>
Web Extraction GET /v2/web/extract/{job-id} <ul><li>Extract content from web pages:<ul><li>urn:ayode:privilege-action:/api/web/extract</li><li>Scope: none.</li></ul></li></ul>