Skip to main content
API · Discovery POST /api/v1/fabric-connections/{sourceUuid}/attestations Records the workspace permission observed by the Owner’s browser for the customer execution factory identity. Send exactly one assignment with principalKind set to executionFactory. The workspace, identity, permission, and current connection ETag must match the reviewed source setup. Requires the GV.APIOwner application role, or a higher role (Owner > Contributor > Reader). Operation ID · attest_fabric_connection_assignments

Request example

Authentication and access

  • Required role: GV.APIOwner
  • Data classification: metadata
  • Side effects: configurationWrite
Use an authentication scheme declared below. Ordinary workloads use application tokens; signed-in users use delegated tokens and Organization membership. Activation and invitation acceptance require a person, and execution callbacks require their registered identity.
  • Microsoft Entra delegated user token
  • Microsoft Entra application token

Parameters

sourceUuid

path Required Opaque Fabric Discovery Source UUID. string (uuid) Opaque Fabric Discovery Source UUID.

Idempotency-Key

header Required Required caller-chosen retry identity. Use 1-128 visible ASCII characters and reuse it only for an exact retry of this request. string minimum length: 1 · maximum length: 128

If-Match

header Required Exact strong ETag from the reviewed Fabric connection or removal plan. Weak validators, wildcards, and tag lists are rejected. string maximum length: 1024

Request body

Required

application/json

Schema FabricConnectionAttestation object Properties assignments— Required array<FabricAssignmentAttestation> minimum items: 1 · maximum items: 1 Array items Schema FabricAssignmentAttestation object Properties disposition— Required string
  • Allowed values: "created","preexisting"
principalId— Required string (uuid) principalKind— Required string
  • Constant: "executionFactory"
role— Required string
  • Allowed values: "Viewer","Contributor","Member","Admin"
roleAssignmentId— Required string (uuid) Additional properties are not allowed. observedAt— Required string (date-time) workspaceId— Required string (uuid) Additional properties are not allowed.

Responses

This guide summarizes response status codes and headers. Retrieve the deployed, authenticated OpenAPI document for the exact response body schemas and examples. The API also provides an authenticated Swagger UI; opening it in a browser does not automatically attach a bearer token. Error responses use application/problem+json. The response’s stable code and type map to the error-code reference.

200

Assignment metadata accepted.

Headers

  • Idempotency-Replayed: boolean
  • Location: string

401

A valid Microsoft Entra bearer token is required.

403

The authenticated principal does not have the required role.

404

The resource does not exist in this tenant.

409

The operation conflicts with current resource or Azure state.

412

If-Match did not match the resource’s current strong ETag.

422

The request is syntactically valid but semantically invalid.

428

The exact current ETag is required in If-Match.

429

The bounded application request rate was exceeded.

Headers

  • Retry-After: Seconds to wait before retrying. integerminimum: 1

503

A required dependency is temporarily unavailable.

Headers

  • Retry-After: Seconds to wait before retrying. integerminimum: 1