Skip to content

[docs-scanner] Unclear relationship between sandbox:use PAT permission and granular account permissions #26225

Description

@docker-agent

File: content/manuals/ai/sandboxes-api/authentication.md

Issue

The authentication documentation describes two different permission concepts without explaining their relationship:

  1. PAT scope: "When creating the token, select the sandbox:use permission in your Docker account's personal access token settings."

  2. Account permissions: "Each request also checks whether you have permission for the action on the target resource. For example, creating a sandbox requires sandboxesCreate, reading it requires sandboxesRead, and deleting it requires sandboxesDelete."

The document never clarifies:

  • Does the sandbox:use PAT scope grant all the granular permissions (sandboxesCreate, sandboxesRead, etc.)?
  • Are the granular permissions separate account-level settings that must also be configured?
  • If a PAT has sandbox:use but the account lacks sandboxesCreate, what happens?

Why this matters

A reader setting up authentication needs to know:

  • Whether selecting sandbox:use is sufficient for all sandbox operations
  • Whether additional account configuration is required beyond creating the PAT
  • How to diagnose permission errors (is it the PAT scope or the account permission?)

The current text suggests these are related but doesn't explain the relationship, leaving readers uncertain whether they've completed the setup correctly.

Suggested fix

Add a clarifying sentence in the "Authenticate automation with a PAT" section:

When creating the token, select the sandbox:use permission in your Docker account's personal access token settings. This scope grants access to all sandbox operations, subject to your account's permissions. The API checks both the PAT scope and your account permissions for each request.

Or add a subsection under "Resource access and permissions" that explicitly states:

The sandbox:use PAT scope authorizes your application to act on your behalf. Your account's permissions (sandboxesCreate, sandboxesRead, etc.) then determine which operations succeed. Both the PAT scope and the account permission must allow the action.


Found by nightly documentation quality scanner

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions