Skip to main content

Access policy SDK and provider support

Choose an integration#

Python SDK 0.2.3 supports caller-bound check_resources, filter_allowed, and get_allowed_actions. Start with Python SDK setup, then use the runtime-check guide for response and failure behavior.

Although the Python signatures contain optional principal arguments, an explicit principal payload is rejected by the public backend. Use only the authenticated caller.

The JavaScript SDK's policy calls, Policy.checkResource and Policy.getAllowedActions, send the same caller-bound check; see the JavaScript SDK reference. The Refine accessControlProvider (1.3.7 and later) sends Refine's list and show as read, edit as update, and clone as create. It takes the policy kind, such as datatable:orders, from params.entityType, then the resource's meta.entityType, then the provider's entityType option. Without any of those it sends the Refine resource name, which matches no policy, so the check is denied. See Refine integration. Registering a Refine provider doesn't protect routes; CanAccess and useCan only decide what to show, and TaruviBase always enforces policies on the server.