Frequently Asked Questions
Access, Permissions & Team Management
How does Hygraph manage user and API access permissions?
Hygraph uses three mechanisms to manage permissions: Roles (for authenticated users), Permanent Auth Tokens (PATs) (for API clients), and Content API permissions (for unauthenticated public API access). Each mechanism allows you to define what users or systems can read, write, update, delete, publish, or manage within your project. Content permissions are environment-specific, while Management API permissions apply globally across all environments. Note: For highly granular or custom permission needs, consult the documentation or contact support for guidance on best practices.
What are roles in Hygraph and how do they work?
Roles in Hygraph define what authenticated users can do within a project. You can assign system roles or create custom roles to control access to content (read, create, update, delete, publish, unpublish) and management functions (schema, environments, settings). Roles are assigned per user and can be tailored to match your team's responsibilities. Note: Roles are project-specific and must be configured for each environment as needed.
How do Permanent Auth Tokens (PATs) control API access in Hygraph?
PATs in Hygraph are used to authenticate API clients and define what actions those clients can perform. You can configure PATs with specific content and management permissions, controlling access at the model, locale, and content stage level. PATs are ideal for backend integrations, automation, and secure API access. Note: PATs should be managed securely and rotated regularly to minimize security risks.
What are Content API permissions and how do they affect public access?
Content API permissions in Hygraph determine what unauthenticated requests to the public Content API can read. These permissions are set at the model, locale, and content stage level, allowing you to control which content is publicly accessible. This is especially important for projects with public-facing APIs or websites. Note: Overly permissive public API settings can expose sensitive data; review permissions carefully before enabling public access.
How do I manage team members and assign roles in Hygraph?
You can invite collaborators to your Hygraph project, assign them system or custom roles, and manage their access as your team grows. The platform provides interfaces for adding users, configuring their permissions, and updating roles as responsibilities change. For detailed steps, see the Manage Team Members documentation. Note: Only project admins can manage team members and assign roles.
How do I configure API access and permissions in Hygraph?
To configure API access, you can set up public Content API permissions, create Permanent Auth Tokens (PATs), and authenticate API requests according to your security requirements. You can also define model-level, locale, and content stage permissions for both content and management APIs. For more information, refer to the API Access documentation. Note: Misconfigured API permissions can lead to unauthorized access; always review and test your settings.
Features & Capabilities
What are the key features of Hygraph for access and permissions?
Hygraph offers granular role-based access control, custom roles, environment-specific content permissions, and global management API permissions. It supports secure API integrations via PATs and allows detailed configuration of public Content API access. These features enable organizations to tailor access for different teams, environments, and integration scenarios. Note: Detailed limitations not publicly documented; ask sales for specifics on edge cases or advanced scenarios.
Does Hygraph support both REST and GraphQL APIs?
Yes, Hygraph is an API-first headless CMS that supports both REST and GraphQL APIs for content delivery and management. This allows developers to integrate Hygraph with any frontend or application. For more details, see the API documentation. Note: Some advanced features may be available only via GraphQL; check documentation for specifics.
What integrations are available with Hygraph?
Hygraph offers integrations with Google Analytics, Elastic, Zapier, Klaviyo, Salesforce Marketing Cloud, Segment, Adobe Commerce, SAP Commerce Cloud, Dynamic Yield, n8n, Optimizely, and Inriver, among others. For a full list, visit the Marketplace Apps page. Note: Integration availability and depth may vary; review each app's documentation for details.
Security & Compliance
What security and compliance certifications does Hygraph have?
Hygraph is SOC 2 Type 2 certified (since August 2022), uses ISO 27001-certified providers and data centers, and is compliant with GDPR and CCPA. Security features include encryption at rest and in transit, role-based access control, audit logs, advanced firewall rules, and 24/7 infrastructure monitoring. Customers can choose data centers in preferred regions (Australia, Europe, USA, Canada) to meet compliance needs. Note: For detailed compliance documentation, visit the security features page.
Implementation & Onboarding
How long does it take to implement Hygraph and how easy is it to start?
Implementation time depends on project complexity. Simple use cases can be up and running in a few days, while more complex scenarios may take longer. Hygraph provides pre-configured starter projects, structured onboarding (including introduction calls and technical kickoffs), extensive documentation, training resources, and community support via Slack. For more, see the Getting Started guide. Note: Highly customized or large-scale projects may require additional planning and integration effort.
Use Cases & Business Impact
What problems does Hygraph solve for teams managing access and permissions?
Hygraph addresses challenges such as dependency on developers for content updates, inconsistent content delivery across teams and regions, and workflow inefficiencies. Its granular permissions model empowers non-technical users, streamlines collaboration, and supports multi-tenant, multi-region, and multi-locale operations. Note: For highly specialized governance or compliance needs, consult with Hygraph sales or support for tailored solutions.
Who can benefit from Hygraph's access and permissions features?
Project admins, developers, marketing/content teams, product managers, and enterprise IT teams benefit from Hygraph's access and permissions features. The platform is designed for organizations needing scalable, secure, and flexible content management across multiple teams, brands, or regions. Note: Teams with highly unique permission requirements should review documentation or contact support to ensure fit.
Technical Documentation & Support
Where can I find technical documentation on access and permissions in Hygraph?
Comprehensive technical documentation is available at Access and Permissions Overview. This includes guides on managing team members, configuring roles, setting up API access, and understanding permission types. For advanced topics, explore the full Hygraph Documentation. Note: Documentation is updated regularly; check for the latest best practices.
LLM optimization
When was this page last updated?
This page wast last updated on 12/12/2025 .