Access Controls in Rustici Generator
This guide covers how Rustici Generator authenticates callers and authorizes what they can do. Access is layered: a credential defines identity, and authorization scopes decide which API actions are allowed (globally or per tenant). For MCP tokens, you can further limit search and read visibility through access control targets and policies.
How access is decided
Generator evaluates access in this order:
- Authenticate with a credential to mint a bearer token. Tokens are audience-bound: request
API_V1for the REST API orMCPfor Generator’s MCP server. See API Authentication . - Authorize the action using the credential’s
scopesandtenantsproperties. These are SUBJECT and VERB pairings (for example,READonCONTENT). A request is allowed if either the globalscopesor the matching tenant entry permits it. Verbs are not compounding:WRITEdoes not includeREADorDELETE. See Authorization Scopes . - Isolate data by tenant. Most endpoints require a tenant. A credential can only see a tenant’s data only if it has access to the tenant. See Tenant Management .
- Optionally filter content for MCP. Credential scopes still apply, but an Access Control Policy attached at login can hide content inside the tenant. Policies are built from targets (named groups of content). Policies can only be attached to MCP tokens, not
API_V1tokens. See Access Control Targets and Policies .
The root credential created at setup uses the * wildcard for both subject and verb and can perform any action. We strongly recommend creating additional credentials with tighter scopes instead of using root for day-to-day integrations. See
Credentials Management
.
In this section
- Credentials Management — create, update, and restrict credentials
- Authorization Scopes
— SUBJECT and VERB values, global vs tenant-specific scopes, and the
*wildcard - Access Control Targets and Policies — grouping content into targets, composing policies, and attaching a policy to an MCP token
If you are connecting an LLM client, see MCP Integration for credential recommendations and how policies apply to search and read tools.