Welcome to the Panopto Community

Please note: All new registrants to the Panopto Community Forum must be approved by a forum moderator or admin. As such, if you navigate to a feature that is members-only, you may receive an error page if your registration has not yet been approved. We apologize for any inconvenience and are approving new members as quickly as possible.

Questions regarding API limits

Howdy!

Our institution is new to Panopto and had some questions regarding the API. Any help would be much appreciated!

  1. Do all users have API access?
  2. How does Panopto API determine what the user can do? Like, if they are a creator for some videos, but only a viewer in others, is it dependent on what they are trying to do with the specific video?
  3. What are the rate limits?
  4. I am aware that only admins can do certain things, but what are the general limitations between users and various flavors of admin?
Tagged:

Answers

  • Hi Randi,

    Here are some responses, let me know if you need additional clarification.

    Do all users have API access?

    • No separate API privilege. Any authenticated user can call the API as themselves, with the same rights they have in the UI
    • They need an OAuth2 client and access token first. Users can create their own under User Settings → API Clients; admins manage org-wide clients under System → API Clients
    • Use a user-based client so the token is tied to a user. A no-user Server Application token can only see public content

    How does the API decide what a user can do?

    • Same permissions as the UI, evaluated per folder/video and per action
    • Creator on some content and Viewer on other content: they can edit only the Creator items and only view the rest
    • List APIs only return what that user is allowed to see
    • 401 = not signed in / bad token. 403 = signed in, but not allowed to do that

    Rate limits

    • Default: 5/sec, 100/min, 5,000/hour
    • Counted per OAuth client (and IP), separately per endpoint
    • Over the limit returns HTTP 429. Support can raise these

    Users vs admins

    • Viewer: watch/list shared content
    • Creator: create/edit/share in folders they have Creator on
    • Videographer: manage all content, but not site admin APIs (users/groups/settings)
    • Administrator: full site control, including user and group APIs
    • Content APIs follow folder/video roles. User/group/site APIs generally require Administrator

    I hope this helps.

    Thanks,

    Adis

Sign In or Register to comment.