[docs-scanner] Unclear relationship between sandbox:use PAT permission and granular account permissions
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Newbie friendliness
- 88/100
- Issue type
- Documentation
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- docker
- Domain
- documentation
Research direction
Open content/manuals/ai/sandboxes-api/authentication.md and read the “Authenticate automation with a PAT” and “Resource access and permissions” sections. Clarify how the sandbox:use PAT scope relates to sandboxesCreate, sandboxesRead, and sandboxesDelete, including that both checks affect each request. Confirm the documentation explains how to diagnose permission failures.
Written by the indexing model from the issue text.
Description
File: content/manuals/ai/sandboxes-api/authentication.md
Issue
The authentication documentation describes two different permission concepts without explaining their relationship:
-
PAT scope: "When creating the token, select the
sandbox:usepermission in your Docker account's personal access token settings." -
Account permissions: "Each request also checks whether you have permission for the action on the target resource. For example, creating a sandbox requires
sandboxesCreate, reading it requiressandboxesRead, and deleting it requiressandboxesDelete."
The document never clarifies:
- Does the
sandbox:usePAT scope grant all the granular permissions (sandboxesCreate,sandboxesRead, etc.)? - Are the granular permissions separate account-level settings that must also be configured?
- If a PAT has
sandbox:usebut the account lackssandboxesCreate, what happens?
Why this matters
A reader setting up authentication needs to know:
- Whether selecting
sandbox:useis sufficient for all sandbox operations - Whether additional account configuration is required beyond creating the PAT
- How to diagnose permission errors (is it the PAT scope or the account permission?)
The current text suggests these are related but doesn't explain the relationship, leaving readers uncertain whether they've completed the setup correctly.
Suggested fix
Add a clarifying sentence in the "Authenticate automation with a PAT" section:
When creating the token, select the
sandbox:usepermission in your Docker account's personal access token settings. This scope grants access to all sandbox operations, subject to your account's permissions. The API checks both the PAT scope and your account permissions for each request.
Or add a subsection under "Resource access and permissions" that explicitly states:
The
sandbox:usePAT scope authorizes your application to act on your behalf. Your account's permissions (sandboxesCreate,sandboxesRead, etc.) then determine which operations succeed. Both the PAT scope and the account permission must allow the action.
Found by nightly documentation quality scanner
- Dominant language
- Markdown
- Stars
- 4.7k
- Forks
- 8.5k
- Avg merge
- 1d 18h
- Merged PRs (30d)
- 127
Getting set up
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from docker/docs
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
status/triage
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
Instructions no longer validPossibly taken @aevesdocker claimed this 6 days ago. Openstatus/triage
Difficulty 1/5 Under an hour Newbie friendliness 85/100
docker/docs#26171 · 1 assignee ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 95/100
Maintainers usually reply within 1 day
Similar issues
-
add-on doc enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
JuliaGraphics/ColorTypes.jl#344 · 1 comment ·
Maintainers usually reply within 1 day
-
agent-butler-finding chore
Difficulty 1/5 Under an hour Newbie friendliness 88/100
jordansmall/spindrift#4146 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
DaveGamble/cJSON#1093 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
midnightntwrk/midnight-docs#1430 ·
Maintainers usually reply within 1 day
-
bug documentation needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
stacklok/docs-website#1185 ·
Maintainers usually reply within 1 day