CockroachDB Cloud API keys, service accounts, role grants, folders, JWT issuers, organization details, billing, and audit logs. Generated from Cockroach Labs' hash-locked 2024-09-16 OpenAPI snapshot and carries 31 of 139 current operations. The enrolled cockroachdb-cloud connection supplies a service-account secret through connection-owned Bearer authentication at cockroachlabs.cloud. Every /api/v1 request fixes Cc-Version to 2024-09-16; SCIM v2 requests deliberately omit that v1-only header. Required JSON bodies are sent verbatim, parsed JSON preserves unsafe integers as exact strings, reads are uncached, every mutation requires approval, and no task, note, or user-work project Source is invented for cloud infrastructure or identity administration.
What this pack installs
- cockroachdb-cloud-access-organization Ingredient
Trust & control
What installing this whole pack would let it do. Recued grants these permissions at install — review them there before approving.
What it's allowed to do
Destructive
Web APIs
cockroachdb-cloud-access-organization
external change
Read: api_keys.list_api_keys · No approvalAdmin: api_keys.create_api_key · Always asksRead: api_keys.get_api_key · No approvalDestructive: api_keys.update_api_key · Always asksDestructive: api_keys.delete_api_key · Always asksRead: audit_logs.list_audit_logs · No approvalRead: folders.list_folders · No approvalAdmin: folders.create_folder · Always asksRead: folders.get_folder · No approvalDestructive: folders.update_folder · Always asksDestructive: folders.delete_folder · Always asksRead: folders.list_folder_contents · No approvalRead: billing.list_invoices · No approvalRead: billing.get_invoice · No approvalRead: jwt_issuers.list_jwtissuers · No approvalAdmin: jwt_issuers.add_jwtissuer · Always asksRead: jwt_issuers.get_jwtissuer · No approvalDestructive: jwt_issuers.update_jwtissuer · Always asksDestructive: jwt_issuers.delete_jwtissuer · Always asksRead: organizations.get_organization_info · No approvalRead: role_management.list_role_grants · No approvalRead: role_management.get_all_roles_for_user · No approvalDestructive: role_management.set_roles_for_user · Always asksAdmin: role_management.add_user_to_role · Always asksDestructive: role_management.remove_user_from_role · Always asksRead: service_accounts.list_service_accounts · No approvalAdmin: service_accounts.create_service_account · Always asksRead: service_accounts.get_service_account · No approvalDestructive: service_accounts.update_service_account · Always asksDestructive: service_accounts.delete_service_account · Always asksRead: role_management.get_person_users_by_email · No approval
Data it touches
SurfacesWeb APIs
Tags
pack:cockroachdb-cloudcockroachdbmanaged-databaseaccessorganizationrolesbillingauditapicomposition