Skip to main content

Access control

Datagrok provides robust security through its authentication, authorization, and credential management systems. These features control access to platform functionalities and data, ensuring that only authorized users can operate within their granted permissions.

Authentication​

Authentication is verification of identity by providing credentials. Datagrok supports the following authentication methods:

You can enable all methods separately or combined. With OpenID, Datagrok can also synchronize group membership from the identity provider. After successful authentication, Datagrok issues a session token for subsequent API calls, ensuring continuous secure access during the session.

To set up authentication, go to Sidebar > Settings () > Users and Sessions. For detailed instructions, see Configure authentication.

danger

If you disable the login/password authentication (for example, after setting up the SSO), the platform will no longer accept logging in with the username/password, so be careful not to lock yourself out and make sure SSO works. We recommend checking that SSO works by signing into Datagrok using incognito mode before disabling the login/password authentication.

If you disable login/password authentication without providing a functional alternative, you may need to redeploy the platform to regain access.

Login-password authentication​

Datagrok uses a username and password to authenticate users. Passwords are salted with random data and encrypted with the 1024xSHA-256 algorithm, ensuring they cannot be read from the system.

When a user logs in, the username and password pair is passed to the server. If the password hash matches the stored hash, a session token is generated. Every subsequent API call must be made with the Authorization: token HTTP header, where token is the session token. This token becomes invalid after logging out.

Datagrok doesn't store user passwords after login. If a user forgets their password, they can reset it using the link on the login form, or a Datagrok Administrator can reset it.

Authentication UML Diagram

Authorization​

Authorization in Datagrok is based on Role-Based Access Control (RBAC) and determines whether a specified user can execute a specified operation against a specified entity. This is achieved by putting users into groups and granting groups permissions.

Groups and roles​

Every permission is granted to a group. Users, groups, and roles are all ways of putting people into groups:

ConceptWhat it isExample
Personal groupCreated automatically for every user. Sharing something with a user grants it to this groupjdoe
GroupA set of users and other groups. Answers "who are these people?"Oncology Discovery
RoleA group marked as a role. Holds permissions and is assigned to groups. Answers "what may they do?"Data Steward, Dashboard Author

A role nests and inherits exactly like a group does. The difference is how you use it:

  • Groups collect people. Let them mirror your organization. Ideally, they come from your identity provider through group synchronization.
  • Roles collect permissions. Grant global permissions and entity permissions to a role, then assign the role to groups. Every member of those groups inherits what the role grants.

Group synchronization never matches roles, so a group created in the identity provider can't grant itself a Datagrok role. To manage roles, see Roles.

The following table shows how permissions reach a user:

Permission kindGranted toReaches a user through
Global permissionA group or roleMembership in that group or role, directly or through nested groups
Entity permissionA group or role, on an entityThe same membership, for that entity only
Entity permission on a spaceA group or role, on the spaceThe same membership, for everything the space contains

Permissions​

When you create an entity, only you (its author) can access it initially. To grant access to others, you need to share it and assign permissions:

Common Entity Permissions

PermissionDescription
ViewSee and open the entity; read basic attributes
EditModify entity attributes
DeleteDelete the entity
ShareChange entity permissions

Data Connection Permissions

PermissionDescription
Data Connection QueryExecute any query on the data connection
Get SchemaRead database schema
List FilesList files on the file connection

Data Connection Write Permissions (Write access)

PermissionDescription
Add RowsInsert rows, including bulk inserts, into tables on the data connection
Change ValuesUpdate existing values on the data connection
Remove RowsDelete rows on the data connection
Truncate TableEmpty a table on the data connection

Data Connection Schema Permissions (Schema changes)

PermissionDescription
Create TableCreate tables on the data connection
Alter SchemaAdd, rename, or drop columns, keys, and indices
Drop TableDrop tables on the data connection

Data Query Permissions

PermissionDescription
Execute Data QueryExecute the query

Table Permissions

PermissionDescription
Read Table DataRead table data

Domain Schema Permissions

PermissionDescription
ExtendAdd user-defined tables and columns to this domain schema

When you share an entity, permissions are grouped as follows:

  • View and use: The View permission and all entity-specific use permissions, such as Execute Data Query or Data Connection Query
  • Write access: The data connection write permissions listed above
  • Schema changes: The data connection schema permissions listed above
  • Full access: All permissions

Entity permissions are granted to groups and roles rather than individual users, which simplifies security administration. For convenience, Datagrok automatically creates a "personal group" for every user in the system, named after the user.

Permission sets assigned to a group are inherited by all members of the group. Groups can be nested, allowing members of a child group to inherit permissions set for a parent group. However, circular membership is forbidden.

note

To fully control access to external data sources (like file shares or databases), you can also associate groups with credentials

Global Permissions​

Global permissions define system-wide capabilities in Datagrok. They can be assigned to roles, users, or groups. These permissions control what users can create, administer, or view across the entire platform.

To edit global permissions, you need the Edit Global Permissions permission. Go to Settings > Global Permissions, or select a group or role and, on the Context Panel, expand Global Permissions and click MANAGE.

Permission for admin actions:

PermissionDescription
Create UserCreate a new user from Users list or with API
Edit UserEdit a user from Users list or with API
Edit GroupEdit any user group, add or remove members
Edit Global PermissionsEdit this list of permissions
Edit SettingsEdit client and group settings, and push group defaults
Start Admin SessionAbility to temporarily disable permissions check
Edit Plugins SettingsChange Datagrok server-side settings
Publish PackageInstall a package or deploy with Datagrok tools
Delete CommentsDelete comments in any chat inside Datagrok
Admin System ConnectionsEdit system data connections such as System:AppData or System:Datagrok
Admin Sticky MetaAbility to set up Sticky Meta
Admin KeysManage server cryptographic keys: create, rotate, move, revoke, delete
Admin SyncManage cross-instance sync pairs and run entity sync
Admin Url AliasesCreate, re-point, and delete URL aliases
Create RepositoryRegister a new package repository
Create GroupCreate a new user group
Create RoleCreate a new user role

Permissions to create entities:

PermissionDescription
Save Entity TypeCreate or edit Entity Type for Sticky Meta
Create EntityCreate any entity within Datagrok
Create ScriptCreate a script
Create Security ConnectionCreate a connection that provides credentials
Create Database ConnectionCreate a connection to a database
Create File ConnectionCreate a file share
Create Data QueryCreate a new data query
Create DashboardCreate a new dashboard
Create SpaceCreate a new space
Create Domain SchemaCreate a user-managed domain database schema

General permissions:

PermissionDescription
Invite UserInvite a new user by email, explicitly or by sharing something
Share With EveryoneShare something with someone the user has no common groups or roles with
Send EmailSend email to any user using group emails
Edit All Users FavoritesAdd to and remove from the favorites every user sees (the All users group)

Permissions to show or hide nodes in Browse Panel:

PermissionDescription
Browse File ConnectionsShow Files section in Browse Panel
Browse Database ConnectionsShow Databases section in Browse Panel
Browse AppsShow Apps section in Browse Panel
Browse SpacesShow Spaces section in Browse Panel
Browse DashboardsShow Dashboards section in Browse Panel
Browse PluginsShow Plugins and Repositories sections in Browse Panel
Browse FunctionsShow Functions section in Browse Panel
Browse QueriesShow Queries section in Browse Panel
Browse ScriptsShow Scripts section in Browse Panel
Browse Open APIShow Open API section in Browse Panel
Browse UsersShow Users section in Browse Panel
Browse GroupsShow Groups section in Browse Panel
Browse RolesShow Roles section in Browse Panel
Browse ModelsShow Predictive Models section in Browse Panel
Browse DockersShow Dockers section in Browse Panel
Browse LayoutsShow Layouts section in Browse Panel
Browse Shared DataShow Shared Data in Browse Panel

The Browse permissions only show or hide sections of the Browse tree. They don't restrict access to the entities themselves. Entity permissions do.

Defaults on a new instance​

On a new instance, the All users group gets these global permissions, so every user can work right away:

  • Create Entity, Create Script, Publish Package, Invite User, Share With Everyone
  • Create Database Connection, Create File Connection, Create Data Query, Create Dashboard, Create Space
  • All Browse permissions

All other global permissions go to the Administrators role. This suits a small team. For an enterprise rollout, review these defaults and move the ones your policy restricts, such as Create Database Connection or Share With Everyone, from All users to dedicated roles.

You can set Datagrok global permissions as part of GROK_PARAMETERS. To get the template JSON, go to the /settings view and click the {} button near the server settings section. Add any parameter to the settings map of GROK_PARAMETERS, respecting the hierarchy.

See also: Configuration

Credentials management system​

Datagrok provides a built-in credentials management system that securely stores and protects data connection and plugin credentials.

Credentials contain sensitive information used to connect to data sources, such as login/password pairs for databases or tokens and private keys for web services.

Each credential is associated with a group and a connection or a plugin. When a user accesses the entity, the system automatically selects the appropriate credential based on the user's group membership.

Entities diagram

Depending on the connection, the call to the external service is performed either on the server or the client side. For client-side calls, the credentials are retrieved from the server. Some connections, such as databases, are intended to be accessible only from the server side. In such cases, set the Requires Server flag to true (accessible via the Edit... command) to prevent the client from retrieving credentials.

Credentials storage​

To enhance security, all external credentials are stored in a separate database and encrypted with a platform key generated during deployment. Even if one of the systems is compromised, an attacker still won't be able to access the credentials.

Credentials retrieving process diagram

If your organization already uses a specialized credential vault like AWS or GCP Secrets Manager, you can configure Datagrok to use it.

To store credentials in Datagrok's credentials storage programmatically, send a POST request to $(GROK_HOST)/api/credentials/for/$(ENTITY_NAME) with a raw body containing JSON, such as {"login": "abc", "password": "123"}, and headers {"Authorization": $(TOKEN), "Content-Type": "application/json"}. For scripts and CI, get the token with keypair authentication rather than a personal developer key.

See this sample:

To add credentials from the UI:

  1. Open the editor: for a data connection, right-click it and select Edit..., then open the Credentials tab. For a package or a Docker container, right-click it and select Credentials....
  2. Select the group and enter the credentials in the fields provided.

    Note: Only the groups you belong to are listed. To assign credentials for the All users group, you must have permissions to edit the connection. To assign credentials for other groups, you must both have permissions to edit the connection and be that group's admin.

  3. Click OK.