Skip to content
Kong Logo | Kong Docs Logo
search
  • We're Hiring!
  • Docs
    • Kong Gateway
    • Kong Konnect
    • Kong Mesh
    • Plugin Hub
    • decK
    • Kubernetes Ingress Controller
    • Insomnia
    • Kuma

    • Docs contribution guidelines
  • Plugin Hub
  • Support
  • Community
  • Kong Academy
Get a Demo Start Free Trial
  • Kong Gateway
  • Kong Konnect
  • Kong Mesh
  • Plugin Hub
  • decK
  • Kubernetes Ingress Controller
  • Insomnia
  • Kuma

  • Docs contribution guidelines
    • Overview of Konnect
    • Architecture
    • Network Resiliency and Availability
    • Port and Network Requirements
    • Compatibility
    • Stages of Software Availability
    • Release Notes
      • Control Plane Upgrades FAQ
      • Supported Installation Options
    • Overview
    • Access a Konnect Account
    • Set up a Runtime
    • Configure a Service
    • Implement and Test the Service
      • Publish and Consume Services
      • Register Applications
    • Import Kong Gateway Entities into Konnect
    • Overview
      • Overview
      • Upgrade a Runtime Instance
      • Verify a Runtime Instance
      • Renew Data Plane Certificates
      • Runtime Parameter Reference
      • Overview
      • Create Consumer Groups
        • Overview
        • Set Up and Use a Vault in Konnect
      • Manage Runtime Configuration using decK
    • Backup and Restore
    • Version Compatibility
    • Troubleshooting
    • Overview
    • Manage Service Documentation
      • Overview
      • Configure a Plugin on a Service
      • Configure a Plugin on a Route
    • Overview
    • Access the Dev Portal
    • Sign Up for a Dev Portal Account
      • Manage Developer Access
      • Manage Application Registration Requests
      • Manage Application Connections
      • Auto Approve Dev and App Registrations
      • Azure OIDC
      • Application Overview
      • Enable and Disable App Registration
        • Overview
        • Okta
        • Curity
        • Auth0
      • Create, Edit, and Delete an Application
      • Register an Application with a Service
      • Generate Credentials for an Application
    • Customize Dev Portal
    • Troubleshoot
    • Introduction to Analytics
    • Analyze Services and Routes
    • Reports Use Cases
    • Reports Reference
    • Troubleshoot
      • Manage a Konnect Account or Plan
      • Change to a Different Plan
      • Manage Payment Methods and Invoices
      • Overview
        • Overview
        • Manage Teams
        • Teams Reference
        • Roles Reference
      • Manage Users
      • Manage System Accounts
      • Set up SSO with OIDC
      • Set up SSO with Okta
      • Login Sessions Reference
    • Account and Org Deactivation
    • Troubleshoot
    • Overview
      • API Documentation
      • Identity Integration Guide
      • API Documentation
      • API Documentation
      • Portal RBAC Guide
      • Overview
      • Nodes
      • Data Plane Certificiates
        • Services
        • Routes
        • Consumers
        • Plugins
        • Upstreams
        • Certificates
        • CA Certificates
        • SNIs
        • Targets
        • Vaults
      • API Spec
      • Filtering
    • Labels
    • Plugin Ordering Reference

github-edit-pageEdit this page

report-issueReport an issue

enterprise-switcher-iconSwitch to OSS

On this page
  • Services
  • Runtime groups
Kong Konnect
  • Home
  • Kong Konnect
  • Org Management
  • Teams And Roles
  • Roles reference

Roles reference

A team can have any number of roles. See Manage Teams and Roles.

The following predefined roles are available in Konnect:

Services

Role Description
Admin Admin of an existing Konnect service. The admins have all write access related to a service and service versions.
Application Registration Access to enable or disable application registration for a Konnect service.
Creator Access to create new Konnect services in Service Hub. The creator becomes the owner of the service they create, gaining admin access to the service.

This role does not provide access to creating sub-entities in a service such as service versions, implementations, API specs, or plugins. See the Service Admin, Maintainer, or Plugins Admin roles.
Deployer Access to implement and associate a Konnect service version to a runtime group.

Must also have the Deployer role for the associated runtime group.
Maintainer Access to read, edit, and deploy a Konnect service and its service versions, and manage its plugins.
Plugins Admin Access to install plugins on the Konnect service versions and routes.

Must also have the Admin role in the associated runtime group.
Publisher Access to publish a Konnect service to the Dev Portal.
Viewer Read-only access to all the configurations of a Konnect service, including attributes, versions, Analytics reports, and plugins.

Runtime groups

Role Description
Admin Owner of an existing runtime group. The owners have all write access related to a runtime group, the group’s runtime instances, and its configuration.
Creator Access to create a new runtime group in Runtime Manager. The creator becomes the owner of the runtime group they create, gaining admin access to the new runtime group.

This role does not grant access to existing runtime groups, their runtime instances, or their configurations. See the runtime group Admin or Deployer roles.
Certificate Admin Access to configure certificates for an existing runtime group.
Deployer Access to deploy a service to the runtime group. Must also have the Deployer role for the service being deployed.
Viewer Read-only access to all the configurations of a runtime group and its runtime instances.
Consumer Admin Access to configure consumers for an existing runtime group.
Gateway Service Admin Access to configure gateway services for an existing runtime group.
Key Admin Access to configure keys for an existing runtime group.
Plugin Admin Access to configure plugins for an existing runtime group.
Route Admin Access to configure routes for an existing runtime group.
SNI Admin Access to configure SNIs for an existing runtime group.
Upstream Admin Access to configure upstreams for an existing runtime group.
Vault Admin Access to configure vaults for an existing runtime group.
Thank you for your feedback.
Was this page useful?
  • Kong
    THE CLOUD CONNECTIVITY COMPANY

    Kong powers reliable digital connections across APIs, hybrid and multi-cloud environments.

    • Company
    • Customers
    • Events
    • Investors
    • Careers Hiring!
    • Partners
    • Press
    • Contact
  • Products
    • Kong Konnect
    • Kong Gateway
    • Kong Mesh
    • Get Started
    • Pricing
  • Resources
    • eBooks
    • Webinars
    • Briefs
    • Blog
    • API Gateway
    • Microservices
  • Open Source
    • Install Kong Gateway
    • Kong Community
    • Kubernetes Ingress
    • Kuma
    • Insomnia
  • Solutions
    • Decentralize
    • Secure & Govern
    • Create a Dev Platform
    • API Gateway
    • Kubernetes
    • Service Mesh
Star
  • Terms•Privacy
© Kong Inc. 2023