Role-based access control (RBAC)
RBAC applies to multi-user authentication
Role-based access control governs users signed in through multi-user
authentication, which is off by default in InfluxDB 3 Enterprise. Existing
apiv3_ token workflows are unaffected. See
Manage users and authentication
to enable it.
Role-based access control (RBAC) governs what authenticated users can do in InfluxDB 3 Enterprise. Each user is assigned one or more built-in roles that determine their permissions.
Built-in roles
InfluxDB 3 Enterprise provides three built-in roles:
- Admin: Full access to all resources, including creating and managing other users, roles, and tokens.
- Auditor: Can list and describe databases and read tokens, users, and roles. Can’t query or write data.
- Member: Can query and write data and create databases, and can create, read, and delete tokens. Can read users and roles. Can’t delete databases or manage users, roles, or admin tokens.
Auditor and Member grant less than their names suggest
Only the Admin role (or an admin token) has full access. The
Auditor role can’t read data, and neither Auditor nor Member
can access system endpoints such as /health, /metrics, /ping, and
/ready, or query the _internal database. Use an admin token for user
and role management.
Assign roles
Assign roles to a user with the influxdb3 update user-roles command. See
Manage users and authentication
for the user-management workflow.
Custom roles
Authoring custom roles (creating roles and editing role permissions) is
disabled by default (--rbac-authoring-disabled defaults to true).
Listing roles and assigning the built-in roles to users remain available
regardless of this setting.
See
configuration options
for details.
Limitations
RBAC has the following known limitation in InfluxDB 3 Enterprise:
- Token scope can exceed role scope: A user with token-creation permission (Admin or Member) can create a token with database-level permissions broader than their own role. InfluxDB 3 Enterprise only restricts non-admin users from creating tokens that grant system-resource permissions.
Was this page helpful?
Thank you for your feedback!
Support and feedback
Thank you for being part of our community! We welcome and encourage your feedback and bug reports for InfluxDB 3 Enterprise and this documentation. To find support, use the following resources:
Customers with an annual or support contract can contact InfluxData Support. Customers using a trial license can email trial@influxdata.com for assistance.