Providing 3rd parties access to only certain tables

Options

hi there,

We have a HIPAA compliant app where only some tables store sensitive information. We’d like to use something like Retool for internal tooling.
I’d like to permission only certain tables to a 3rd party to maintain HIPAA compliance. Is there a way to do that? To my understanding, Xano can generate read only or read/write tokens, but’s it’s all or nothing across your tables.

Perhaps @Michael Udinski you would know? Saw some of your videos on tokens. Thanks!

Best Answer

Answers

  • Michael Udinski
    Michael Udinski Administrator

    ADMIN

    Options

    Hey @jackb — just to clarify, when you say 3rd parties to access only certain tables. Do you mean a 3rd party API to only access data from certain tables?

  • jackb
    jackb Member
    Options

    @Michael Udinski yes, I'm referring to the Metadata API. Ideally, I'd like to create an access token that only provides third parties with access to certain tables. Even with RBAC, it seems to still be 'all or nothing' across the entire database.

    Is this accurate? There is no way to provide access to only certain tables?