# Jupyterhub admin user permissions?

**URL:** <https://discourse.jupyter.org/t/jupyterhub-admin-user-permissions/10916>\
**Category:** JupyterHub\
**Tags:** jupyterhub, how-to, help-wanted\
**Created:** [September 22, 2021, 9:15pm UTC](https://discourse.jupyter.org/t/jupyterhub-admin-user-permissions/10916 "2021-09-22T21:15:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![delc](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/delc/32/5288_2.png) [@delc](https://discourse.jupyter.org/u/delc)\
**Post date:** [September 22, 2021, 9:15pm UTC](https://discourse.jupyter.org/t/jupyterhub-admin-user-permissions/10916/1 "2021-09-22T21:15:59Z")

</div>

I set up jupyterhub v0.11.1 from the helm chart and I was wondering what permissions does the API token allow an “admin” user to perform? Is it simply the rest calls documented on [JupyterHub](https://jupyterhub.readthedocs.io/en/stable/_static/rest-api/index.html)?

I have `c.JupyterHub.admin_access = True` already set.

In the UI, an admin user is able to view the files in a non-admin user’s notebook. It looks like it passes a cookie over to the notebook server in the rest call as a header. I was wondering if it’s possible for an admin user to view the files in a non-admin user’s notebook through _ **using the admin API token alone** _? I was hoping to automate file scripting of non-admin notebooks without having to deal with cookies

---

<div class="post-metadata">

**Author:** ![minrk](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/minrk/32/13_2.png) [@minrk](https://discourse.jupyter.org/u/minrk)\
**Post date:** [September 23, 2021, 11:03am UTC](https://discourse.jupyter.org/t/jupyterhub-admin-user-permissions/10916/2 "2021-09-23T11:03:58Z")

</div>

Yes, API tokens of admins have the same permissions as the owner, which includes API access to individual servers. JupyterHub 2.0 will give you more fine-grained control over this.

---

<div class="post-metadata">

**Author:** ![delc](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/delc/32/5288_2.png) [@delc](https://discourse.jupyter.org/u/delc)\
**Post date:** [September 23, 2021, 6:47pm UTC](https://discourse.jupyter.org/t/jupyterhub-admin-user-permissions/10916/3 "2021-09-23T18:47:17Z")

</div>

Just to be clear, I am not talking about oauth2 tokens. I am talking about _JupyterHub’s API tokens_, as described here: [Using JupyterHub’s REST API — JupyterHub 1.4.2 documentation](https://jupyterhub.readthedocs.io/en/stable/reference/rest.html)

Passing this token to the following REST endpoint:

```auto
curl --location --request GET 'https://server:port.com/user/nonadminuser/api/contents/somefile.ipynb?content=1' \
--header 'Authorization: Bearer my_api_token'

```

causes me to see this screen:

 ![Screen Shot 2021-09-23 at 11.42.32 AM](https://canada1.discourse-cdn.com/flex031/uploads/jupyter/original/2X/a/a58368601b179999cceb274eeb950e5215a4652f.png)

Where the blacked out parts are the non-admin user whose file I am trying to view. Does this mean I need to have an oauth2 token (and therefore an oauth2 provider as well) in order to view user’s files **through the rest API**? If so, is it possible to get an oauth2 bearer token through the client\_credential grant type flow? Because it seems like authorization\_code flow is the only one supported right now (which is not automatable since it requires user interaction)
