> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API permissions

> Map product endpoints to project-scoped API-key permissions.

API keys carry a nested permission document. The Gateway checks the required action for every product route.

## Cloud CDN

| Permission | Allows |
| - | - |
| List distributions | List distributions, read analytics and configuration, and read operation history |
| Create distribution | Create a distribution |
| Modify distribution | Update configuration, delivery rules, Origin Shield, purge, and prefetch |
| Delete distribution | Delete a distribution |
| List origin groups | List and read origin-group details |
| Create origin group | Create an origin group |
| Modify origin group | Update an origin group |
| Delete origin group | Delete an origin group |

## Cloud DNS

| Permission | Allows |
| - | - |
| List zones | List/read zones, analytics, nameservers, and quota reach |
| Create zone | Create a zone |
| Modify zone | Update SOA values or zone status |
| Delete zone | Delete a zone |
| List record sets | List and read record-set details |
| Create record set | Create a record set |
| Modify record set | Replace a record set's configuration and records |
| Delete record set | Delete a record set |

## TLS Manager

| Permission | Allows |
| - | - |
| List certificates | List inventory, summary, certificate details, and usage |
| Create certificate | Import certificate material |
| Modify certificate | Rename an imported certificate |
| Delete certificate | Delete an unused imported certificate |

Selecting a certificate on a distribution also requires **Modify distribution**.

## Cloud Shield

| Permission | Allows |
| - | - |
| List protected resources | Read protection, analytics, investigations, and response-page previews |
| Create protected resource | Attach a distribution and create security configuration |
| Modify protected resource | Change settings and rules, clear local reputation tags, and update configuration |
| Delete protected resource | Detach protection and delete configuration, including POST bulk deletion |

Plan limits and add-ons are checked in addition to permissions. Cloud Shield role assignments require an organization administrator; role bindings restrict existing project access.

## Least-privilege examples

* A CDN cache invalidator needs **Modify distribution**, but not create or delete permissions.
* A DNS deployment job usually needs list, create, modify, and delete record-set permissions, but not zone deletion.
* A monitoring integration needs list permissions only.

<Warning>
  Do not grant API-key management permissions to ordinary delivery or DNS automation. A credential that can create or roll other credentials expands the impact of compromise.
</Warning>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.