Skip to main content
Question

Minimum or Recommended Permissions for Creating Data Virtualization APIs

  • July 24, 2026
  • 6 replies
  • 87 views

chriswilson
Enthusiast
Forum|alt.badge.img+22

We are working through the setup of a service user for a project, intended to only be able to create and run its own Data Virtualization APIs and nothing else.  The aim is to avoid excessive permissions. 

I have been searching for a list of recommended or minimum permissions but have not yet established that, so I’m putting the question out here.

We have granted:

  • Create/manage for data virtualization
  • Run jobs
  • Access Resources/Data

We’re looking into other permissions.

We’ll work through it but I am definitely thinking that documentation of this would be handy from the Safe point of view to save time, if possible.  Possibly as an addition to https://support.safe.com/hc/en-us/articles/36098228739469-Secure-Data-Virtualization-Endpoints-with-Authentication

 

6 replies

chriswilson
Enthusiast
Forum|alt.badge.img+22
  • Author
  • Enthusiast
  • July 28, 2026

@rylanatsafe wondering (from my previous idea on importing schemas for DV endpoints) if this is one you could help with?  We are looking at testing with the current over-powerful solution but I would hope there’s an idea of the permissions set to start such a user account off with.


zoe.forbes
Safer
Forum|alt.badge.img+9
  • Safer
  • July 28, 2026

Hi ​@chriswilson,

I had a look into this and think the only required permissions are Create/Manage Data Virtualization, and Access Run Workspace. Technically the Run Workspace permission isn’t required, but without this all responses have to be Manual.

No access to Resources is required as jobs run under the permissions granted to the Engine service.

Let me know if you have questions about this!


chriswilson
Enthusiast
Forum|alt.badge.img+22
  • Author
  • Enthusiast
  • July 28, 2026

@zoe.forbes thanks for getting in touch - I almost tagged you but stayed on most recent contact for the Data Virtualization module!

Unfortunately having gone through this a couple of times with our platform team (I’m no longer on the admin/superuser side at my current org) we get this error:

When loading the Data Virtualization page I get a 403 error involving fmeapiv4/resources/connections/FME_SHAREDRESOURCE_LOG

Then when clicking Create API I get another 403 error either involving fmeapiv4/roles or fmeapiv4/accounts - that coincides with the error flag/screenshot above.

I am hesitant to post any further URL details but I hope this gets you started.

These could be environmental of course, but it seems there are things going on in the background that could require additional permissions.  Of course for a service user we don’t want it going anywhere near having widespread security permissions, while I understand that securing APIs and endpoints is part of Data Virtualization, per https://support.safe.com/hc/en-us/articles/36098228739469-Secure-Data-Virtualization-Endpoints-with-Authentication


zoe.forbes
Safer
Forum|alt.badge.img+9
  • Safer
  • July 28, 2026

Hi ​@chriswilson,

That’s interesting behavior, which build are you using? I’ll try to reproduce and get back to you!


chriswilson
Enthusiast
Forum|alt.badge.img+22
  • Author
  • Enthusiast
  • July 28, 2026

@zoe.forbes we are on 

FME Flow 2026.1.1

Build 26121 - win64


zoe.forbes
Safer
Forum|alt.badge.img+9
  • Safer
  • July 29, 2026

@chriswilson Thanks for letting me know. I installed your build and can see the failing log request is expected, and determines whether the View Log File button is displayed:

Seeing an error popup here is not expected however - let me know if you see this.

When creating an API, I’m able to reproduce a blocking error which I think could be what you’re seeing:

While I believe this is a bug which I’ll report, this only occurs when Sharing Enabled is unchecked in the user’s settings:

Please let me know if you have questions about any of this. I’m more than happy to continue working here, but if you’d prefer to Submit a Ticket feel free to.