API access and roles
Built-in roles
Use these built-in roles unless your organization requires a custom role.
| Role | Typical use | Capability coverage |
|---|---|---|
admin |
Install the app, run first-time setup, and perform the required Splunk restart. | Full setup, restart, and normal API authority. |
data_management_admin |
Automate destinations, Edge Processors, onboarding and offboarding scripts, pipeline definitions, and deployments. | Recommended role for a dedicated API automation account; covers the ordinary data-management lifecycle. |
Keep admin access for installation and one-time setup. Use data_management_admin for normal automation. This limits routine integrations to the permissions they need and avoids granting server-configuration and restart permissions unnecessarily.
Custom roles
For a custom role, consult the OpenAPI specification served by the installed app. Each operation declares its authorization requirements with x-authz-scope and, where applicable, x-authz-requirement. Use that version-specific contract instead of copying capabilities from this guide.
Retrieve the installed OpenAPI specification with an account that can access the app namespace:
curl --fail --user "$SPLUNK_USER:$SPLUNK_PASSWORD" \
"https://splunk.example.com:8089/servicesNS/$SPLUNK_USER/dmx_cmp/openapi/v1" \
--output dmx-cmp-openapi.yaml
Review the required capabilities for an operation in the downloaded dmx-cmp-openapi.yaml before you create or change a custom role.
Authentication
The API supports HTTP Basic authentication, bearer tokens, and Splunk session keys. The examples use Basic authentication for clarity. Store credentials in your secret manager. Do not put them in scripts or request bodies.