Rule Extensions permissions
The custom-role permissions required to manage and test Snyk Code Rule Extensions through the API and the Snyk Web UI
Last updated
Was this helpful?
The custom-role permissions required to manage and test Snyk Code Rule Extensions through the API and the Snyk Web UI
Rule Extensions are available to Enterprise customers. Access is granted through a custom role. Rule Extensions are managed at the Group level and tested at the Organization level, so a role combines Group-level and Organization-level permissions.
Grant only the permissions a role needs. The set differs slightly depending on whether the role is used through the API or the in-product UI.
A service-account role used with the Rule Extensions REST API needs only the Rule Extensions permissions:
View Rule Extensions
group.rule_extension.read
View Rule Extensions in the Group. Required by Create, Edit, and Delete.
Create Rule Extensions
group.rule_extension.create
Create Rule Extensions in the Group.
Edit Rule Extensions
group.rule_extension.edit
Update Rule Extensions in the Group.
Delete Rule Extensions
group.rule_extension.delete
Permanently delete Rule Extensions from the Group.
Test Rule Extensions
org.rule_extension.project.test
Run an impact test on a Project in the Organization.
To use the API, create a service account that holds this role and authenticate with its token.
Reaching the Rule Extensions screens in the Snyk Web UI (Group settings → Snyk Code) additionally requires permission to view the Group and its Organizations:
View Group
group.read
View details of the Group.
View Group Settings
group.settings.read
View the Group's settings.
View Organizations
group.org.list
View Organizations in the Group.
View Rule Extensions
group.rule_extension.read
View Rule Extensions in the Group.
Create Rule Extensions
group.rule_extension.create
Create Rule Extensions in the Group.
Edit Rule Extensions
group.rule_extension.edit
Update Rule Extensions in the Group.
Delete Rule Extensions
group.rule_extension.delete
Permanently delete Rule Extensions from the Group.
Test Rule Extensions
org.rule_extension.project.test
Run an impact test on a Project in the Organization.
Go to Group settings → Member Roles → Create new role and choose the Group role type.
Add the Group-level and Organization-level permissions above that the role needs.
Assign the role to the member (for UI access) or service account (for API access) that manages Rule Extensions.
Customers who managed access during the closed beta must add the updated Rule Extensions permissions to their custom roles — Snyk does not backfill them. Snyk removes the deprecated SAST Rule Extensions permissions from the UI after a 30-day grace period.
Last updated
Was this helpful?
Was this helpful?

