Welcome to the Panopto Community

Please note: All new registrants to the Panopto Community Forum must be approved by a forum moderator or admin. As such, if you navigate to a feature that is members-only, you may receive an error page if your registration has not yet been approved. We apologize for any inconvenience and are approving new members as quickly as possible.

Is it possible to restrict API (SOAP/REST) access based on account permissions?

It might not be possible, but I’d like to ask anyway.

In the case of the Microsoft 365 MS Graph API, for example, you first register an application within the tenant.
Although it’s called an “application,” it doesn’t perform any actions on its own; rather, it serves to define the secrets and tokens needed when calling the Graph API from a script.

When registering an application,
・You can specify which areas the app can access (e.g., SharePoint Online only)
・You can specify what actions are permitted (Read-only / Read-Write)
・You can specify the scope of permissions (Full permissions, User)
and so on.
This prevents scripts from being able to do anything they want. Conversely, it also allows you to create scripts and tools that operate with standard user permissions. This is because, if you limit the scope to a user’s permissions, the script cannot access areas beyond what that user is authorized to access.

Is this kind of functionality possible with Panopto’s SOAP API or REST API? Based on the documentation, it appears that calls must be made after authenticating with an account that has global administrator permissions, so I suspect it might not be possible, but I’d like to confirm just in case.

Thank you.

Sign In or Register to comment.