Documentation

Enterprise users and permissions reference

Important
Authentication must be enabled before authorization can be managed. If authentication is not enabled, permissions will not be enforced. See “Enable authentication”.

Users

Users have permissions and roles.

Roles

Roles are groups of permissions. A single role can belong to several users.

InfluxDB Enterprise clusters have two built-in roles:

Global Admin

The Global Admin role has all 16 cluster permissions.

Admin

The Admin role has all cluster permissions except for the permissions to:

  • Add/Remove Nodes
  • Copy Shard
  • Manage Shards
  • Rebalance

Permissions

A permission (also privilege) is the ability to access a resource in some way, including:

  • viewing the resource
  • copying the resource
  • dropping the resource
  • writing to the resource
  • full management capabilities

InfluxDB Enterprise clusters have 16 permissions:

PermissionDescriptionToken
View AdminPermission to view or edit admin screensViewAdmin
View ChronografPermission to use Chronograf toolsViewChronograf
Create DatabasesPermission to create databasesCreateDatabase
Create Users & RolesPermission to create users and rolesCreateUserAndRole
Add/Remove NodesPermission to add/remove nodes from a clusterAddRemoveNode
Drop DatabasesPermission to drop databasesDropDatabase
Drop DataPermission to drop measurements and seriesDropData
ReadPermission to read dataReadData
WritePermission to write dataWriteData
RebalancePermission to rebalance a clusterRebalance
Manage ShardsPermission to copy and delete shardsManageShard
Manage Continuous QueriesPermission to create, show, and drop continuous queriesManageContnuousQuery
Manage QueriesPermission to show and kill queriesManageQuery
Manage SubscriptionsPermission to show, add, and drop subscriptionsManageSubscription
MonitorPermission to show stats and diagnosticsMonitor
Copy ShardPermission to copy shardsCopyShard

In addition, two tokens govern Kapacitor permissions:

  • KapacitorAPI: Grants the user permission to create, read, update and delete tasks, topics, handlers and similar Kapacitor artifacts.
  • KapacitorConfigAPI: Grants the user permission to override the Kapacitor configuration dynamically using the configuration endpoint.

Permissions scope

Using the InfluxDB Enterprise Meta API, these permissions can be set at the cluster-wide level (for all databases at once) and for specific databases. For examples, see Manage authorization with the InfluxDB Enterprise Meta API.

Permission to Statement

The following table describes permissions required to execute the associated database statement.

PermissionStatement
CreateDatabasePermissionAlterRetentionPolicyStatement, CreateDatabaseStatement, CreateRetentionPolicyStatement, ShowRetentionPoliciesStatement
ManageContinuousQueryPermissionCreateContinuousQueryStatement, DropContinuousQueryStatement, ShowContinuousQueriesStatement
ManageSubscriptionPermissionCreateSubscriptionStatement, DropSubscriptionStatement, ShowSubscriptionsStatement
CreateUserAndRolePermissionCreateUserStatement, DropUserStatement, GrantAdminStatement, GrantStatement, RevokeAdminStatement, RevokeStatement, SetPasswordUserStatement, ShowGrantsForUserStatement, ShowUsersStatement
DropDataPermissionDeleteSeriesStatement, DeleteStatement, DropMeasurementStatement, DropSeriesStatement
DropDatabasePermissionDropDatabaseStatement, DropRetentionPolicyStatement
ManageShardPermissionDropShardStatement,ShowShardGroupsStatement, ShowShardsStatement
ManageQueryPermissionKillQueryStatement, ShowQueriesStatement
MonitorPermissionShowDiagnosticsStatement, ShowStatsStatement
ReadDataPermissionShowFieldKeysStatement, ShowMeasurementsStatement, ShowSeriesStatement, ShowTagKeysStatement, ShowTagValuesStatement, ShowRetentionPoliciesStatement
NoPermissionsShowDatabasesStatement
Determined by type of select statementSelectStatement

Statement to Permission

The following table describes database statements and the permissions required to execute them. It also describes whether these permissions apply the the database or cluster level.

StatementPermissionsScope
AlterRetentionPolicyStatementCreateDatabasePermissionDatabase
CreateContinuousQueryStatementManageContinuousQueryPermissionDatabase
CreateDatabaseStatementCreateDatabasePermissionCluster
CreateRetentionPolicyStatementCreateDatabasePermissionDatabase
CreateSubscriptionStatementManageSubscriptionPermissionDatabase
CreateUserStatementCreateUserAndRolePermissionDatabase
DeleteSeriesStatementDropDataPermissionDatabase
DeleteStatementDropDataPermissionDatabase
DropContinuousQueryStatementManageContinuousQueryPermissionDatabase
DropDatabaseStatementDropDatabasePermissionCluster
DropMeasurementStatementDropDataPermissionDatabase
DropRetentionPolicyStatementDropDatabasePermissionDatabase
DropSeriesStatementDropDataPermissionDatabase
DropShardStatementManageShardPermissionCluster
DropSubscriptionStatementManageSubscriptionPermissionDatabase
DropUserStatementCreateUserAndRolePermissionDatabase
GrantAdminStatementCreateUserAndRolePermissionDatabase
GrantStatementCreateUserAndRolePermissionDatabase
KillQueryStatementManageQueryPermissionDatabase
RevokeAdminStatementCreateUserAndRolePermissionDatabase
RevokeStatementCreateUserAndRolePermissionDatabase
SelectStatementDetermined by type of select statementn/a
SetPasswordUserStatementCreateUserAndRolePermissionDatabase
ShowContinuousQueriesStatementManageContinuousQueryPermissionDatabase
ShowDatabasesStatementNoPermissionsClusterThe user’s grants determine which databases are returned in the results.
ShowDiagnosticsStatementMonitorPermissionDatabase
ShowFieldKeysStatementReadDataPermissionDatabase
ShowGrantsForUserStatementCreateUserAndRolePermissionDatabase
ShowMeasurementsStatementReadDataPermissionDatabase
ShowQueriesStatementManageQueryPermissionDatabase
ShowRetentionPoliciesStatementCreateDatabasePermissionDatabase
ShowSeriesStatementReadDataPermissionDatabase
ShowShardGroupsStatementManageShardPermissionCluster
ShowShardsStatementManageShardPermissionCluster
ShowStatsStatementMonitorPermissionDatabase
ShowSubscriptionsStatementManageSubscriptionPermissionDatabase
ShowTagKeysStatementReadDataPermissionDatabase
ShowTagValuesStatementReadDataPermissionDatabase
ShowUsersStatementCreateUserAndRolePermissionDatabase

Was this page helpful?

Thank you for your feedback!


InfluxDB OSS 2.9.0: API tokens are hashed by default

Stronger token security in InfluxDB OSS 2.9.0 — tokens are hashed on disk by default. Existing tokens are hashed on first startup and can’t be recovered afterward. Capture any plaintext tokens you still need before you upgrade.

View InfluxDB OSS 2.9.0 release notes

Hashed tokens authenticate exactly like unhashed tokens — clients and integrations keep working.

Also new in 2.9.0:

  • Configurable backup compression
  • Restore support for backups containing hashed tokens
  • Tighter Edge Data Replication queue validation
  • Flux upgrade
  • Compaction reliability improvements

Key enhancements in Explorer 1.8

Explorer 1.8 is now available with streaming data subscriptions (beta), line protocol preview, and query history & saved queries.

View Explorer 1.8 release notes

Explorer 1.8 includes new features and improvements that make it easier to ingest, explore, and manage data.

Highlights:

  • Streaming data subscriptions (beta): Stream data into Explorer from MQTT, Kafka, and AMQP sources.
  • Line protocol preview: Preview line protocol, schema, and parse errors before data is written.
  • Custom sample data: Generate custom sample datasets with line protocol and schema preview.
  • Query history and saved queries: Browse query history and save/re-run named queries.
  • Retention period management: Set, update, or clear retention periods on databases and tables.

For more details, see Explorer 1.8 release notes

InfluxDB 3.9: Performance upgrade preview

InfluxDB 3 Enterprise 3.9 includes a beta of major performance upgrades with faster single-series queries, wide-and-sparse table support, and more.

InfluxDB 3 Enterprise 3.9 includes a beta of major performance and feature updates.

Key improvements:

  • Faster single-series queries
  • Consistent resource usage
  • Wide-and-sparse table support
  • Automatic distinct value caches for reduced latency with metadata queries

Preview features are subject to breaking changes.

For more information, see:

Telegraf Enterprise now in public beta

Get early access to the Telegraf Controller and provide feedback to help shape the future of Telegraf Enterprise.

See the Blog Post

The upcoming Telegraf Enterprise offering is for organizations running Telegraf at scale and is comprised of two key components:

  • Telegraf Controller: A control plane (UI + API) that centralizes Telegraf configuration management and agent health visibility.
  • Telegraf Enterprise Support: Official support for Telegraf Controller and Telegraf plugins.

Join the Telegraf Enterprise beta to get early access to the Telegraf Controller and provide feedback to help shape the future of Telegraf Enterprise.

For more information:

Telegraf Controller v0.0.7-beta now available

Telegraf Controller v0.0.7-beta is now available with new features, improvements, bug fixes, and an important breaking change.

View the release notes
Download Telegraf Controller v0.0.7-beta

InfluxDB Docker latest tag changing to InfluxDB 3 Core

On May 27, 2026, the latest tag for InfluxDB Docker images will point to InfluxDB 3 Core. To avoid unexpected upgrades, use specific version tags in your Docker deployments.

If using Docker to install and run InfluxDB, the latest tag will point to InfluxDB 3 Core. To avoid unexpected upgrades, use specific version tags in your Docker deployments. For example, if using Docker to run InfluxDB v2, replace the latest version tag with a specific version tag in your Docker pull command–for example:

docker pull influxdb:2