/api/v1/fabric-connections/{sourceUuid}/attestations
Records the workspace permission observed by the Owner’s browser for the customer execution factory identity. Send exactly one assignment with principalKind set to executionFactory. The workspace, identity, permission, and current connection ETag must match the reviewed source setup. Requires the GV.APIOwner application role, or a higher role (Owner > Contributor > Reader).
Operation ID · attest_fabric_connection_assignments
Request example
Authentication and access
- Required role: GV.APIOwner
- Data classification: metadata
- Side effects: configurationWrite
- Microsoft Entra delegated user token
- Microsoft Entra application token
Parameters
sourceUuid
path Required Opaque Fabric Discovery Source UUID.string (uuid)
Opaque Fabric Discovery Source UUID.
Idempotency-Key
header Required Required caller-chosen retry identity. Use 1-128 visible ASCII characters and reuse it only for an exact retry of this request.string
minimum length: 1 · maximum length: 128
If-Match
header Required Exact strong ETag from the reviewed Fabric connection or removal plan. Weak validators, wildcards, and tag lists are rejected.string
maximum length: 1024
Request body
Requiredapplication/json
Schema FabricConnectionAttestationobject
Properties
assignments— Required
array<FabricAssignmentAttestation>
minimum items: 1 · maximum items: 1
Array items
Schema FabricAssignmentAttestation
object
Properties
disposition— Required
string
- Allowed values:
"created","preexisting"
principalId— Required
string (uuid)
principalKind— Required
string
- Constant:
"executionFactory"
role— Required
string
- Allowed values:
"Viewer","Contributor","Member","Admin"
roleAssignmentId— Required
string (uuid)
Additional properties are not allowed.
observedAt— Required
string (date-time)
workspaceId— Required
string (uuid)
Additional properties are not allowed.
Responses
This guide summarizes response status codes and headers. Retrieve the deployed, authenticated OpenAPI document for the exact response body schemas and examples. The API also provides an authenticated Swagger UI; opening it in a browser does not automatically attach a bearer token. Error responses useapplication/problem+json. The response’s stable code and type map to the error-code reference.
200
Assignment metadata accepted.Headers
- Idempotency-Replayed:
boolean - Location:
string
401
A valid Microsoft Entra bearer token is required.403
The authenticated principal does not have the required role.404
The resource does not exist in this tenant.409
The operation conflicts with current resource or Azure state.412
If-Match did not match the resource’s current strong ETag.422
The request is syntactically valid but semantically invalid.428
The exact current ETag is required in If-Match.429
The bounded application request rate was exceeded.Headers
- Retry-After: Seconds to wait before retrying.
integerminimum: 1
503
A required dependency is temporarily unavailable.Headers
- Retry-After: Seconds to wait before retrying.
integerminimum: 1