...
- Public : The API is visible to all users (subscribers and anonymous users) of its tenant store. Also, the API can be advertised in multiple stores - a central store and/or non-WSO2 stores.
Restricted by Roles : The API is visible only to specific user roles in the API Storetenant store. When
Restricted by Roles
is selected, a new field called Visible to Roles appears where you can specify the user roles that have access to the API in a comma-separated list (no spaces).Note - Roles that have API creation and Publication publication permission can see all APIs in their tenant stores store even if you put that role under the
Restricted by Roles
category. The reason is because these users can anyway restrict access to those roles. This is because any role that has API creation and publication permission can view and edit all APIs in the API Publisher. Therefore, there is no reason to hide the APIs from them in the Store.
- If you restrict the default
subscriber
role under theVisible to Roles
category, any user who self subscribes to the API Store will be able to access the API. This is because the API Manager assigns the subscriber role to all users who sign up to the API Store.
- Roles that have API creation and Publication publication permission can see all APIs in their tenant stores store even if you put that role under the
...