Skip to main content



API7 Enterprise enables implementing fine-grained access control policies through Role-Based Access Control (RBAC).

Built-in Roles

API7 Enterprise provides three types of built-in roles. The predefined roles cover common personas like API providers, Infrastructure operators, and Super admins. The RBAC system allows composing granular access control policies using these roles. Users are assigned appropriate roles based on their responsibilities and duties in the API lifecycle.

Super Admin

This role has the highest level of permissions. It can perform all administrative operations like adding/modifying routes, services, and plugins, as well as managing other users and assigning roles for them. Typically, the Super Admin role is assigned to core infrastructure administrators.

API Provider

This role enables the management of API publishing and API consumption operations, such as adding, modifying, and publishing services, routes, upstreams, applying plugins, and handling API consumers. Typically, the API Provider role is assigned to API developers.

Runtime Admin

This role enables monitoring and managing runtime configurations like gateway instance and setting alerts. It can modify gateway settings. Typically, the Runtime Admin role is assigned to platform/operations engineers. Logo

API Management for Modern Architectures with Edge, API Gateway, Kubernetes, and Service Mesh.


API7 Cloud

SOC2 Type IRed Herring

Copyright © APISEVEN Ltd. 2019 – 2024. Apache, Apache APISIX, APISIX, and associated open source project names are trademarks of the

Apache Software Foundation