> ## Documentation Index
> Fetch the complete documentation index at: https://ona.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Allow Port Access

> Deprecated: Use local validation with the environment state cache instead.

`Unary` · [`Environments`](/docs/api-reference/generated/environment/overview)

<Warning>This method is deprecated.</Warning>

Deprecated: Use local validation with the environment state cache instead.

Checks if the authenticated caller can access a specific port on an environment.
This is called by the Runner Proxy to validate access tokens against current state.
The caller's identity is extracted from the JWT in the request context.

### Examples

* Check port access:

  Verifies if the caller can access port 8080 on an environment.

  ```yaml theme={null}
  environmentId: "07e03a28-65a5-4d98-b532-8ea67b188048"
  port: 8080
  ```

## Endpoint

```text theme={null}
POST /api/gitpod.v1.EnvironmentService/AllowPortAccess
```

Send a Bearer token as described in [Authentication](/docs/api-reference#authenticate-requests). If your organization uses a custom management-plane domain, replace `https://app.ona.com` with that domain.

## Request example

<CodeGroup>
  ```bash cURL theme={null}
  export ONA_HOST=https://app.ona.com
  export ONA_API_KEY=<your-token>

  curl --request POST \
    --url "$ONA_HOST/api/gitpod.v1.EnvironmentService/AllowPortAccess" \
    --header "Authorization: Bearer $ONA_API_KEY" \
    --header "Content-Type: application/json" \
    --data '{
    "environmentId": "<environment-id>"
  }'
  ```

  ```python Python theme={null}
  import gitpod.v1.environment_pb2 as environment_pb2
  from ona_sdk import create_client_from_env

  ona = create_client_from_env()
  request = environment_pb2.AllowPortAccessRequest(
      environment_id="<environment-id>",
  )
  response = ona.services.environment.allow_port_access(request)
  print(response)
  ```

  ```typescript TypeScript theme={null}
  import { create } from "@bufbuild/protobuf";
  import { createClientFromEnv } from "@gitpod/sdk";
  import { AllowPortAccessRequestSchema } from "@gitpod/sdk/gitpod/v1/environment_pb";

  async function main() {
    const ona = createClientFromEnv();
    const request = create(AllowPortAccessRequestSchema, {
      environmentId: "<environment-id>",
    });
    const response = await ona.services.environment.allowPortAccess(request);
    console.log(response);
  }

  main().catch(console.error);
  ```

  ```go Go theme={null}
  package main

  import (
  	"context"
  	"fmt"
  	"log"

  	"connectrpc.com/connect"
  	"github.com/gitpod-io/gitpod-sdk-go/sdk"
  	gitpodpb "github.com/gitpod-io/gitpod-sdk-go/v1"
  )

  func main() {
  	ona, err := sdk.NewFromEnv()
  	if err != nil {
  		log.Fatal(err)
  	}

  	request := connect.NewRequest(&gitpodpb.AllowPortAccessRequest{
  		EnvironmentId: "<environment-id>",
  	})
  	response, err := ona.Services.Environment.AllowPortAccess(context.Background(), request)
  	if err != nil {
  		log.Fatal(err)
  	}
  	fmt.Println(response.Msg)
  }
  ```

  ```json Request body theme={null}
  {
    "environmentId": "<environment-id>"
  }
  ```
</CodeGroup>

## Request

`gitpod.v1.AllowPortAccessRequest`

| Field           | Type    | Required | Description                                                                                      |
| --------------- | ------- | -------- | ------------------------------------------------------------------------------------------------ |
| `environmentId` | string  | No       | environment\_id specifies the environment to check access for. Constraints: `string.uuid=true`.  |
| `port`          | integer | No       | port specifies the port number to check access for. Constraints: `int32.gte=1, int32.lte=65535`. |

## Response

`gitpod.v1.AllowPortAccessResponse`

| Field     | Type    | Required | Description                                                           |
| --------- | ------- | -------- | --------------------------------------------------------------------- |
| `allowed` | boolean | No       | allowed indicates whether the caller is permitted to access the port. |
