Overview

Warrant is an authorization API that lets you define and enforce fine-grained access control rules — roles, permissions, and object-level access — without building your own authorization logic.

Beginner Tip

Model your permissions as 'subject has relation on object' (e.g., user:123 editor document:456) — Warrant's warrant-based model maps directly to common RBAC and ABAC patterns.

Available Data

book title and author
ISBN and publisher
cover image URL
page count
publication date

Example Response

JSON Response
{
  "status": "success",
  "data": {
    "result": "Data from Warrant",
    "description": "APIs for authorization and access control",
    "timestamp": "2025-01-15T10:00:00Z"
  }
}

Field Reference

objectType The type of resource being protected, e.g. 'document', 'folder', or 'project'.
objectId The specific instance of the resource this warrant applies to.
relation The permission relationship, e.g. 'viewer', 'editor', or 'owner'.
subject The entity (user or group) being granted the relation; contains objectType and objectId.

Implementation Example

Request
const url = "https://warrant.dev/";
// Replace headers or query params with the values required by this API.
const response = await fetch(url, {
  headers: {
  "X-API-Key": "YOUR_API_KEY"
  }
});
if (!response.ok) throw new Error(`Request failed: ${response.status}`);
const data = await response.json();
console.log(data);

What Can You Build?

Note: These code examples are AI-generated and unverified. Always refer to the official API documentation for accurate usage.

Common Errors & Troubleshooting

401 Unauthorized Missing or invalid Authorization header
Pass your API key as 'Authorization: ApiKey YOUR_API_KEY' — note the 'ApiKey' prefix, not 'Bearer'.
404 Not Found on check endpoint The warrant (subject/relation/object triple) does not exist
Create the warrant first via POST /v1/warrants before checking access; a missing warrant means access is denied.
400 – invalid object type Using an object type that hasn't been defined in your Warrant schema
Define object types in your Warrant dashboard or via the Object Types API before creating warrants that reference them.

Metadata Score Breakdown

Estimated from metadata — endpoint not independently tested

This score is estimated from observable metadata — HTTPS support, authentication model, declared CORS, and documentation reachability — because the API requires authentication or exposes no publicly testable endpoint. The five-signal breakdown is only shown for live-tested APIs.

Metadata estimate · endpoint not independently tested

Technical Specifications

Auth API Key
HTTPS REQUIRED
CORS YES
Difficulty Intermediate
Verified: 2026-04-04

Similar APIs

View All →