UiPath Documentation
uipath-cli
latest
false
UiPath CLI 用户指南
重要 :
请注意,此内容已使用机器翻译进行了本地化。 新发布内容的本地化可能需要 1-2 周的时间才能完成。

uip admin authorization

Syntax and options for `uip admin authorization`, which manages Authorization-service roles, role assignments, the permissions catalog, and effective-access lookups.

uip admin authorization manages UiPath Authorization-service primitives: custom role definitions on the Policy Administration Point (PAP), who has which role (role assignments), a read-only catalog of permission definitions, and effective-access lookups against the Policy Decision Point (PDP). It ships as the @uipath/authz-commands package, one of seven sub-packages assembled into the single uip admin tool — see uip admin for the full directory of admin sub-resources.

备注:

Role/permission policy CRUD for built-in product areas lives on a different command — uip gov access-policy — which targets the same authz-sdk swagger but is owned by the governance tool. This page is about custom roles, who's assigned them, and computing effective access.

This resource spans one page​

Every verb below is invoked as uip admin authorization <verb> — there is no separate sibling page for this sub-resource.

概念​

  • Role shape — a role's --scope plus optional --service together determine where it applies: Organization (org-wide), TenantGlobal (a template applied across every tenant), Tenant (one tenant), or Project (scoped to a service that registers Project-level permissions, e.g. Document Understanding, Reinfer). --service alone infers the scope from the service registry — an org-level service (e.g. apps) infers Organization; a tenant-level service (e.g. documentunderstanding) infers Tenant. Combine --scope and --service to override the inference.
  • Authoring is blocked for services that own their own role catalog — orchestrator, dataservice, insights, taskmining, testmanager, automationops, casemanagement, processmining — and for platform-level services — authz, oms, platform, identity, licensing. roles create/update/delete and roles assignments create all reject --service values from this list; listing roles/permissions/assignments for these services still works.
  • Role authoring is a PUT-style upsert — roles create always creates a new role (the id is server-generated); roles update <id> re-sends the full role body with the same id. update without --description preserves the current description by fetching the role first — it does not clear it.
  • Assignment scope composition — roles assignments list/create build a scope path from --scope/--service/--scope-id/--tenant-id using the same inference matrix as role authoring, with an escape hatch: --scope-path <path> sends an exact path verbatim, overriding every other scope flag. TenantGlobal is not a valid assignment scope (only a role-authoring scope) except as a create-time alias for Tenant.
  • Batch mode — roles assignments create --file <path> and roles assignments delete --file <path>/<id> accept JSON arrays for bulk operations, mutually exclusive with the inline single-item flags/argument. The underlying bulk-update endpoint is best-effort atomic and silently no-ops on unknown/already-deleted assignment ids — delete does not verify ids existed beforehand.
  • --login-validity <minutes> is available on every verb here (overrides the interactive-login token lifetime for that one call — rarely needed).

大纲​

uip admin authorization roles list [--limit <n>] [--offset <n>] [--filter <fragment>] [--service <service>] [--scope <type>] [--role-type BuiltIn|Custom] [--tenant-id <guid>]
uip admin authorization roles get <id>
uip admin authorization roles create --name <name> --file <path> [--description <text>] [--service <service>] [--scope <type>] [--tenant-id <guid>]
uip admin authorization roles update <id> --name <name> --file <path> [--description <text>] [--service <service>] [--scope <type>] [--tenant-id <guid>]
uip admin authorization roles delete <id>

uip admin authorization roles assignments list [--limit <n>] [--offset <n>] [--service <service>] [--identity-id <id>] [--scope <type>] [--scope-id <id>] [--scope-path <path>] [--tenant-id <guid>] [--include-inherited]
uip admin authorization roles assignments create (--role-id <guid> --identity-id <guid> --identity-type <type> [--service <service>] [--scope <type>] [--scope-id <id>] [--scope-path <path>] [--tenant-id <guid>]) | --file <path>
uip admin authorization roles assignments delete [<id>] | --file <path>

uip admin authorization permissions list [--service <service>] [--scope <type>]

uip admin authorization check-access [<identity>] [--scope Tenant|Folder] [--tenant-id <guid>] [--folder-id <guid>] [--service <service>] | --file <path>
uip admin authorization roles list [--limit <n>] [--offset <n>] [--filter <fragment>] [--service <service>] [--scope <type>] [--role-type BuiltIn|Custom] [--tenant-id <guid>]
uip admin authorization roles get <id>
uip admin authorization roles create --name <name> --file <path> [--description <text>] [--service <service>] [--scope <type>] [--tenant-id <guid>]
uip admin authorization roles update <id> --name <name> --file <path> [--description <text>] [--service <service>] [--scope <type>] [--tenant-id <guid>]
uip admin authorization roles delete <id>

uip admin authorization roles assignments list [--limit <n>] [--offset <n>] [--service <service>] [--identity-id <id>] [--scope <type>] [--scope-id <id>] [--scope-path <path>] [--tenant-id <guid>] [--include-inherited]
uip admin authorization roles assignments create (--role-id <guid> --identity-id <guid> --identity-type <type> [--service <service>] [--scope <type>] [--scope-id <id>] [--scope-path <path>] [--tenant-id <guid>]) | --file <path>
uip admin authorization roles assignments delete [<id>] | --file <path>

uip admin authorization permissions list [--service <service>] [--scope <type>]

uip admin authorization check-access [<identity>] [--scope Tenant|Folder] [--tenant-id <guid>] [--folder-id <guid>] [--service <service>] | --file <path>

uip admin authorization roles​

Manage custom role definitions on the PAP.

uip admin authorization roles list​

List roles for the caller's organization — both built-in and custom by default.

选项​
长值默认描述
--limit <n>整数20页面大小。
--offset <n>整数0Records to skip (zero-based).
--filter <fragment>字符串—Substring match on role name.
--service <service>字符串—Owning service (e.g. apps, documentunderstanding). Combines with --scope, or alone infers the scope from the service registry.
--scope <type>Organization|TenantGlobal|Tenant|Project|Folder—Filter by role shape. Optional when --service is given.
--role-type <type>BuiltIn|Custom—Filter by role type.
--tenant-id <guid>UUID—Restrict to roles scoped to a specific tenant. Look up a UUID with uip admin tenants list --filter <name>.

Listing works for every service, including ones whose role catalog can't be authored via this CLI (see Concepts) — only authoring is blocked.

示例​
uip admin authorization roles list
uip admin authorization roles list --scope Organization
uip admin authorization roles list --service apps --filter Admin
uip admin authorization roles list
uip admin authorization roles list --scope Organization
uip admin authorization roles list --service apps --filter Admin
数据形状(--输出 json)​
{
  "Code": "AuthzRolesList",
  "Data": {
    "totalCount": 1,
    "results": [
      {
        "id": "11111111-2222-3333-4444-555555555555",
        "name": "Folder Admin",
        "description": "Folder admin role",
        "type": "BuiltIn",
        "scopeType": "Folder",
        "ownerServiceName": "orchestrator",
        "ownerServiceId": "<service-guid>",
        "tenantId": "<tenant-guid>",
        "createdBy": "<user-guid>",
        "createdOn": "<iso-date>",
        "actionDetails": []
      }
    ]
  }
}
{
  "Code": "AuthzRolesList",
  "Data": {
    "totalCount": 1,
    "results": [
      {
        "id": "11111111-2222-3333-4444-555555555555",
        "name": "Folder Admin",
        "description": "Folder admin role",
        "type": "BuiltIn",
        "scopeType": "Folder",
        "ownerServiceName": "orchestrator",
        "ownerServiceId": "<service-guid>",
        "tenantId": "<tenant-guid>",
        "createdBy": "<user-guid>",
        "createdOn": "<iso-date>",
        "actionDetails": []
      }
    ]
  }
}

uip admin authorization roles get​

Fetch a single role by id.

参数​
名称必填用途
<id>是Role UUID. Obtain from roles list.
示例​
uip admin authorization roles get 11111111-2222-3333-4444-555555555555
uip admin authorization roles get 11111111-2222-3333-4444-555555555555
数据形状(--输出 json)​
{
  "Code": "AuthzRoleGet",
  "Data": {
    "id": "11111111-2222-3333-4444-555555555555",
    "name": "Folder Admin",
    "description": "Folder admin role",
    "type": "BuiltIn",
    "scopeType": "Folder",
    "ownerServiceName": "orchestrator",
    "actionDetails": [
      { "id": "<action-guid>", "name": "OR.FOLDERS.READ", "namespace": "ORCHESTRATOR", "resourceAction": "Read" }
    ]
  }
}
{
  "Code": "AuthzRoleGet",
  "Data": {
    "id": "11111111-2222-3333-4444-555555555555",
    "name": "Folder Admin",
    "description": "Folder admin role",
    "type": "BuiltIn",
    "scopeType": "Folder",
    "ownerServiceName": "orchestrator",
    "actionDetails": [
      { "id": "<action-guid>", "name": "OR.FOLDERS.READ", "namespace": "ORCHESTRATOR", "resourceAction": "Read" }
    ]
  }
}

uip admin authorization roles create​

Create a custom role. Always creates — the role id is server-generated; use roles update <id> to modify an existing role.

选项​
长值必填描述
--name <name>字符串是Role display name.
--file <path>路径是JSON file with the role's granted actions as an array of strings, e.g. ["STUDIO.X.Y", "STUDIO.A.B"].
--description <text>字符串否Role description.
--service <service>字符串否Owning service — infers scope, or combines with --scope. Rejects the authoring-blocked service list.
--scope <type>Organization|TenantGlobal|Tenant|Projectno*Role shape. At least one of --scope/--service is required.
--tenant-id <guid>UUID否Tenant for Tenant/Project scope. Not allowed with Organization/TenantGlobal. Defaults to the login tenant.
示例​
uip admin authorization roles create --scope Organization --name "Org Reader" \
  --description "Read-only org admin" --file ./actions.json

uip admin authorization roles create --service documentunderstanding --name "DU Tenant Editor" --file ./actions.json

uip admin authorization roles create --scope Project --service documentunderstanding \
  --name "DU Project Editor" --file ./actions.json
uip admin authorization roles create --scope Organization --name "Org Reader" \
  --description "Read-only org admin" --file ./actions.json

uip admin authorization roles create --service documentunderstanding --name "DU Tenant Editor" --file ./actions.json

uip admin authorization roles create --scope Project --service documentunderstanding \
  --name "DU Project Editor" --file ./actions.json
数据形状(--输出 json)​
{ "Code": "AuthzRoleCreated", "Data": { "createdRoleId": "<new-role-guid>" } }
{ "Code": "AuthzRoleCreated", "Data": { "createdRoleId": "<new-role-guid>" } }

uip admin authorization roles update​

Update an existing custom role by id — the same PUT-style upsert as create, with the id sent on the body.

参数​
名称必填用途
<id>是Role UUID.
选项​

Same as create (--name required, --file required, --description, --service, --scope, --tenant-id). Omitting --description preserves the role's current value (fetched first) rather than clearing it. Same authoring-blocked service list as create.

示例​
uip admin authorization roles update 11111111-2222-3333-4444-555555555555 \
  --scope Tenant --name "Tenant Reader" --file ./actions.json
uip admin authorization roles update 11111111-2222-3333-4444-555555555555 \
  --scope Tenant --name "Tenant Reader" --file ./actions.json
数据形状(--输出 json)​
{ "Code": "AuthzRoleUpdated", "Data": { "createdRoleId": "11111111-2222-3333-4444-555555555555" } }
{ "Code": "AuthzRoleUpdated", "Data": { "createdRoleId": "11111111-2222-3333-4444-555555555555" } }

uip admin authorization roles delete​

Delete a custom role by id. Built-in roles, host-organization roles, and roles owned by an authoring-blocked service (see Concepts) cannot be deleted — the CLI pre-fetches the role and refuses.

参数​
名称必填用途
<id>是Role UUID.
示例​
uip admin authorization roles delete 11111111-2222-3333-4444-555555555555
uip admin authorization roles delete 11111111-2222-3333-4444-555555555555
数据形状(--输出 json)​
{ "Code": "AuthzRoleDeleted", "Data": {} }
{ "Code": "AuthzRoleDeleted", "Data": {} }

uip admin authorization roles assignments​

Manage who has which role (nested under roles).

uip admin authorization roles assignments list​

List role assignments, grouped by identity. Defaults to the login tenant when no scope flags are given, and to direct (non-inherited) assignments only.

选项​
长值默认描述
--limit <n>整数10Page size (server caps at 10 assignment groups).
--offset <n>整数0Records to skip.
--service <service>字符串—Owning service. Combines with --scope, or alone sets the scope from the service registry.
--identity-id <id>UUID—Restrict to one identity (user/group/external app).
--scope <type>Organization|Tenant|Project|Folder|App登录租户TenantGlobal is not valid here. Project/Folder/App require --service and --scope-id.
--scope-id <id>字符串—Project id / folder name-or-id / app id, paired with --service for Project/Folder/App scope.
--scope-path <path>字符串—Advanced: exact scope path sent verbatim, overriding --scope/--service/--scope-id/--tenant-id.
--tenant-id <guid>UUID登录租户Tenant for Tenant/Project/Folder/App scopes.
--include-inherited标记关闭Include assignments inherited from parent scopes, not just direct ones.

Listing works for every service, including services whose assignments can't be authored via this CLI — only authoring is blocked.

示例​
uip admin authorization roles assignments list
uip admin authorization roles assignments list --scope Folder --service orchestrator --scope-id Insights
uip admin authorization roles assignments list --scope-path /tenant/11111111-2222-3333-4444-555555555555/reinfer
uip admin authorization roles assignments list
uip admin authorization roles assignments list --scope Folder --service orchestrator --scope-id Insights
uip admin authorization roles assignments list --scope-path /tenant/11111111-2222-3333-4444-555555555555/reinfer
数据形状(--输出 json)​
{
  "Code": "AuthzAssignmentsList",
  "Data": {
    "totalCount": 1,
    "results": [
      {
        "securityPrincipalId": "<user-guid>",
        "displayName": "Jane Doe",
        "email": "[email protected]",
        "type": "User",
        "roleAssignmentDtos": [
          {
            "id": "<assignment-guid>",
            "type": "Direct",
            "scope": "/tenant/<tenant-guid>",
            "roleId": "<role-guid>",
            "roleName": "Tenant Administrator",
            "inherited": false,
            "mutable": true
          }
        ]
      }
    ]
  }
}
{
  "Code": "AuthzAssignmentsList",
  "Data": {
    "totalCount": 1,
    "results": [
      {
        "securityPrincipalId": "<user-guid>",
        "displayName": "Jane Doe",
        "email": "[email protected]",
        "type": "User",
        "roleAssignmentDtos": [
          {
            "id": "<assignment-guid>",
            "type": "Direct",
            "scope": "/tenant/<tenant-guid>",
            "roleId": "<role-guid>",
            "roleName": "Tenant Administrator",
            "inherited": false,
            "mutable": true
          }
        ]
      }
    ]
  }
}

uip admin authorization roles assignments create​

Create one role assignment (inline) or many (batch via --file) — the two modes are mutually exclusive.

Options — inline mode​
长值必填描述
--role-id <guid>UUIDyes (inline)Role to assign.
--identity-id <guid>UUIDyes (inline)Security principal to assign the role to.
--identity-type <type>User|Group|Robot|ExternalApplicationyes (inline)Principal type.
--service <service>字符串否Same scope-composition semantics as assignments list. Rejects the authoring-blocked service list.
--scope <type>Organization|TenantGlobal|Tenant|Project|Folder|App否TenantGlobal is accepted here as an alias for Tenant.
--scope-id <id>字符串否Paired with --service for Project/Folder/App.
--scope-path <path>字符串否Advanced: verbatim path, overrides other scope flags.
--tenant-id <guid>UUID否Defaults to the login tenant.
Options — batch mode​
长值必填描述
--file <path>路径yes (batch)JSON array of AddRoleAssignmentRequest objects, each with its own scope: {roleId, securityPrincipalId, securityPrincipalType, scope?, tenantId?}. Sent atomically.

Passing --file together with any inline flag is an error; passing neither is also an error.

示例​
uip admin authorization roles assignments create \
  --role-id 98dc776b-835c-407f-9d58-6676318ac968 \
  --identity-id b44fc962-d544-4c99-b520-71121070ec17 --identity-type User

uip admin authorization roles assignments create --file ./assignments.json
uip admin authorization roles assignments create \
  --role-id 98dc776b-835c-407f-9d58-6676318ac968 \
  --identity-id b44fc962-d544-4c99-b520-71121070ec17 --identity-type User

uip admin authorization roles assignments create --file ./assignments.json
数据形状(--输出 json)​
{ "Code": "AuthzAssignmentCreated", "Data": {} }
{ "Code": "AuthzAssignmentCreated", "Data": {} }

uip admin authorization roles assignments delete​

Delete one assignment (positional id) or many (batch via --file) — mutually exclusive.

参数​
名称必填用途
[id]conditionallySingle assignment UUID. Mutually exclusive with --file.
选项​
长值描述
--file <path>路径JSON array of assignment-id strings, e.g. ["0fae98e1-...", "1aab33cf-..."]. Sent atomically.
备注:

The bulk-update endpoint silently no-ops on unknown or already-deleted ids and still reports Success — this command does not verify ids existed beforehand. List before/after if you need to confirm the deletion happened.

示例​
uip admin authorization roles assignments delete 0fae98e1-0f2e-4f8d-bdab-7ce1cf475676
uip admin authorization roles assignments delete --file ./assignment-ids.json
uip admin authorization roles assignments delete 0fae98e1-0f2e-4f8d-bdab-7ce1cf475676
uip admin authorization roles assignments delete --file ./assignment-ids.json
数据形状(--输出 json)​
{ "Code": "AuthzAssignmentDeleted", "Data": {} }
{ "Code": "AuthzAssignmentDeleted", "Data": {} }

uip admin authorization permissions​

Read-only catalog of permission definitions across services.

uip admin authorization permissions list​

选项​
长值描述
--service <service>字符串Owning service. Combines with --scope, or alone infers the scope from the service registry.
--scope <type>Organization|TenantGlobal|Tenant|ProjectFilter to permissions usable in a role of this shape. Mirrors roles create --scope.
示例​
uip admin authorization permissions list
uip admin authorization permissions list --scope Project --service documentunderstanding
uip admin authorization permissions list
uip admin authorization permissions list --scope Project --service documentunderstanding
数据形状(--输出 json)​
{
  "Code": "AuthzPermissionsList",
  "Data": [
    {
      "id": "<action-guid>",
      "name": "OR.FOLDERS.READ",
      "namespace": "ORCHESTRATOR",
      "serviceDisplayName": "Orchestrator",
      "resourceType": "Folders",
      "resourceAction": "Read",
      "resourceGroup": "Folder",
      "description": "View folders",
      "scopeType": "Folder"
    }
  ]
}
{
  "Code": "AuthzPermissionsList",
  "Data": [
    {
      "id": "<action-guid>",
      "name": "OR.FOLDERS.READ",
      "namespace": "ORCHESTRATOR",
      "serviceDisplayName": "Orchestrator",
      "resourceType": "Folders",
      "resourceAction": "Read",
      "resourceGroup": "Folder",
      "description": "View folders",
      "scopeType": "Folder"
    }
  ]
}

uip admin authorization check-access​

Compute a security principal's effective permissions within a tenant or folder scope, via the Policy Decision Point.

参数​

名称必填用途
[identity]conditionallyUser UUID, or a substring of name/email resolved via identity search. Required unless --file is used.

选项​

长值默认描述
--scope <type>Tenant|FolderTenantEvaluation scope.
--tenant-id <guid>UUID登录租户For Tenant scope, used as both the scope Id and ParentId; for Folder scope, the ParentId.
--folder-id <guid>UUID—Required with --scope Folder. Used as the scope Id.
--service <service>字符串—Restrict the result to one service.
--file <path>路径—Full request body (advanced — e.g. a RoleNameStartsWith filter). Mutually exclusive with the positional and every scope flag.

A non-GUID <identity> is resolved via a user-search substring match: 0 matches fails with a discovery hint, 1 match is used, more than 1 tries an exact email/username match before failing with a candidate list.

示例​

uip admin authorization check-access alice@example.com
uip admin authorization check-access <user-guid> --scope Folder --folder-id <folder-guid>
uip admin authorization check-access --file ./check-access.json
uip admin authorization check-access [email protected]
uip admin authorization check-access <user-guid> --scope Folder --folder-id <folder-guid>
uip admin authorization check-access --file ./check-access.json

数据形状(--输出 json)​

{
  "Code": "AuthzCheckAccess",
  "Data": {
    "roleAssignments": { "totalCount": 0, "results": [] },
    "grantedServicesMetadata": [],
    "grantedRolesMetadata": []
  }
}
{
  "Code": "AuthzCheckAccess",
  "Data": {
    "roleAssignments": { "totalCount": 0, "results": [] },
    "grantedServicesMetadata": [],
    "grantedRolesMetadata": []
  }
}

另请参阅​

此页面有帮助吗?

连接

需要帮助? 支持

想要了解详细内容? UiPath Academy

有问题? UiPath 论坛

保持更新