Playground API
DocsStatsBlogStudio
Documentation Tree
Technical BlogFeature Deep Dives
  • Introduction
  • Quickstart
    5 min
  • How It Works
  • Recipes & Cookbooks
  • Platform Comparisons
  • Real-World Showcase
  • Interactive Studio
    Studio
  • GraphiQL IDE
    IDE
  • Session Quotas & Activity
  • Network Chaos Simulator
  • Atomic Sandbox Reset
  • Overview & Models
    Hub
  • Users Resource
  • Posts Resource
  • Comments Resource
  • Todos Resource
  • Custom Collections
    Custom
  • Multipart File Uploads
    Upload
  • Dynamic SVG Avatars
    SVG
  • Image Thumbnails
    CDN
  • Relational Filtering
  • Full-Text Search
  • Dynamic Sorting
  • Offset Pagination
  • Cursor Pagination
    Scroll
  • CSV & Excel Export & Import
    IO
  • Custom Collections
    CRUD
  • Overview & Architecture
    Hub
  • JWT Auth Flow
  • Refresh Token Rotation
    Mutex
  • RBAC Permission Matrix
    Roles
  • Expiry Simulation
  • Clock Skew Drift
  • Password Recovery Loop
  • Dual-Mode Sandboxing
  • GraphiQL IDE
    IDE
  • Relational Queries
  • Stateful Mutations
  • Realtime Subscriptions
  • Overview & Flowcharts
    Hub
  • Hosted Checkout
    Stripe
  • Payment Intents API
  • 3DS Challenge Modal
    Modal
  • Customers Vault
  • Charges & Refunds
  • Test Cards Catalog
  • Overview & Channels
    Hub
  • Virtual Email Mailbox
    Mailtrap
  • Virtual SMS Terminal
    Phone
  • In-App Notifications
  • Message Dispatcher
  • Realtime Studio
    Studio
  • Native WebSocket (/ws)
  • Socket.io Gateway
  • Presence & Echo Bot
  • Server-Sent Events (SSE)
    SSE
  • Analytics Telemetry
  • Webhook Subscriptions
  • HMAC SHA-256 Signatures
  • Delivery Logs
  • Manual Retry Simulator
  • Network Latency Delay
  • HTTP Status Codes
  • Rate-Limit Simulator
    429
  • Flaky Network & Jitter
    Chaos
  • Session Quotas & Activity
  • JSON Snapshots
    JSON
  • Headless CI/CD Testing
    CI
  • Mobile QR Code Sync
  • System Metrics & Health
  • Atomic Sandbox Reset
  • Official TypeScript SDK
  • Multi-Language Generators
  • DevTools Extension
  • OpenAPI 3.1 Spec
    JSON
  • Postman Collection v2.1
  • Bruno Collection
  • Insomnia Workspace
  • TypeScript .d.ts
    .d.ts
  • AI Prompt Rules
    Rules
  • Context Index (llms.txt)
  • Full Schema (llms-full.txt)
  • Manifest (product.json)
  • All Feature Articles
    Blog
  • React CRUD Without Backend
    Deep Dive
  • Why Static APIs Fail
  • Mocking Stateful Auth
  • WebSockets & SSE Guide
Technical Blog
Articles

In-depth articles explaining stateful mock APIs, WebSockets, payments, and frontend resilience.

Read Articles
PreviousRefresh Token Rotation
NextExpiry Simulation
Auth & Security

RBAC Permission Matrix & Scopes

4 Role Tiers

Role-Based Access Control (RBAC) with granular scope evaluation. Simulate requests as admin, editor, viewer, or guest using custom simulation headers to test route authorization guards and HTTP 403 Forbidden responses.

Interactive Role Authorization Tester

Select an authorization scenario below to test permission enforcement on live backend endpoints:

Simulate: Admin: Delete Resource (Allowed)

DELETE
response.json
1
{
2
// Click "Send" above to execute this request against the live server.
3
}

Resource Permission Matrix

Authorization privileges across system collections and operational action boundaries:

Resource DomainRead (GET)Create (POST)Update (PUT/PATCH)Delete (DELETE)Admin / Reset
Users & ProfilesAll RolesEditor, AdminEditor, AdminAdmin OnlyAdmin Only
Posts & CommentsAll RolesEditor, AdminEditor, AdminAdmin OnlyAdmin Only
Todos ChecklistAll RolesEditor, AdminEditor, AdminAdmin OnlyAdmin Only
Media & File UploadsAll RolesEditor, AdminEditor, AdminAdmin OnlyAdmin Only
Sandbox Reset & SeedingEditor, AdminAdmin OnlyAdmin OnlyAdmin OnlyAdmin Only

Programmatic RBAC Discovery Endpoints

Query system roles, persona definitions, and full permission matrix mappings directly via REST endpoints:

GET

Roles & Personas Dictionary (/auth/roles)

Returns all supported roles (admin, editor, viewer, guest), persona credentials, and default scopes:

Query Supported Roles & Personas

GET
response.json
1
{
2
// Click "Send" above to execute this request against the live server.
3
}
GET

Granular Permission Matrix (/auth/permissions)

Returns the system permission matrix, allowed action verbs per role, and wildcard matching syntax (*:read, posts:*):

Query Granular Permission Matrix

GET
response.json
1
{
2
// Click "Send" above to execute this request against the live server.
3
}

Frontend Authorization Guard Recipes

Patterns for protecting sensitive components and action buttons in React 19:

authGuards.tsx
1
// React 19 / Next.js <PermissionGuard /> Component
2
import React from 'react';
3
import { useAuth } from '@/hooks/useAuth';
4
5
interface PermissionGuardProps {
6
requiredRole?: 'admin' | 'editor' | 'viewer';
7
requiredScope?: string;
8
fallback?: React.ReactNode;
9
children: React.ReactNode;
10
}
11
12
export function PermissionGuard({
13
requiredRole,
14
requiredScope,
15
fallback = null,
16
children,
17
}: PermissionGuardProps) {
18
const { user } = useAuth();
19
20
if (!user) return <>{fallback}</>;
21
22
// Admin superuser bypasses all scope checks
23
if (user.role === 'admin') return <>{children}</>;
24
25
// Check role hierarchy
26
if (requiredRole && user.role !== requiredRole) {
27
if (requiredRole === 'editor' && user.role !== 'admin') {
28
return <>{fallback}</>;
29
}
30
}
31
32
// Check specific granular scope
33
if (requiredScope) {
34
const hasScope = user.scopes?.includes('*') ||
35
user.scopes?.includes(requiredScope) ||
36
user.scopes?.includes(${requiredScope.split(':')[0]}:*);
37
if (!hasScope) return <>{fallback}</>;
38
}
39
40
return <>{children}</>;
41
}