What is the point of role based access to API keys when the Ampli CLI serves them up to ayone?

  • 31 March 2023
  • 5 replies
  • 115 views

Userlevel 1
Badge

According this page only Manager or Admin roles have access to API keys.  However the Ampli CLI pulls keys down without regard to user roles.  This then prevents Managers and Admin from withholding production keys until data governance requirements are met.

 

This is a major access hole.  Change my mind.


5 replies

Userlevel 6
Badge +9

Thanks for reaching out here @michael.kuhl The minimum role required in order to use Govern and do functions such as delete, block, edit, etc events and properties will be a Manager role level. However Manager role levels do have access to API keys still. The role level lower than Manager is Member who can see all the Govern items and create Custom Events but that's it. Please keep us posted if you have any additional questions.

Userlevel 1
Badge

Understood, but that doesn’t seem to address my concern:  Developers using the Ampli CLI who are not managers can see API keys via the output of the Ampli CLI.  This is the hole in controlled access to keys to which I refer.

Userlevel 6
Badge +9

Thanks for clarifying @michael.kuhl. I’ll make sure this gets sent to our support team who will be able to dig deeper and get you the specific information you need. 

Userlevel 6
Badge +9

@michael.kuhl I hope all is well. Closing the loop to confirm that your questions have been escalated to and received by our engineering team.

Userlevel 5
Badge +8

Just noting here that the team filed a feature request to the Engineering team to see if they can look into a solution for this and include the role-based access to the Ampli CLI as well. 

Reply