> ## Documentation Index
> Fetch the complete documentation index at: https://docs.instacloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get service access impact

> **Token scope:** `account` · `org` · `project` — read-only tokens allowed.

Preview what changing a service's public access would break, without changing anything. Postgres: closing public access (public=false) lists compute services that will lose the database (on the legacy compute plane, which cannot use the private network lane, or on insta-compute but still bound to the public DATABASE_URL) plus the external clients, CI and local development that will no longer be able to connect. Advisory only — the change is never blocked.



## OpenAPI

````yaml /openapi/project.json get /projects/{projectId}/services/{serviceId}/access/impact
openapi: 3.1.0
info:
  title: InstaCloud API — Project level
  version: 0.1.0
  description: >-
    Endpoints under `/projects/{projectId}`: branches, services, deploys,
    secrets, databases, storage, cron, observability, governance. Callable with
    any token whose binding covers the project.


    Generated from the platform's own OpenAPI document
    (https://api.instacloud.com/openapi.json); see the [API
    overview](/reference/api/overview) for authentication and token scopes.
servers:
  - url: https://api.instacloud.com
    description: InstaCloud
security:
  - bearerAuth: []
tags:
  - name: Projects
    description: Projects inside an organization.
  - name: Branches
    description: >-
      Branch environments of a project: isolated database, storage and compute
      per branch.
  - name: Services
    description: 'Services on a branch: compute, postgres, storage and managed databases.'
  - name: Deploy
    description: Deploy an image or a source to a compute service.
  - name: Compute
    description: Build output of a compute service.
  - name: Secrets
    description: User secrets, service credentials and how they bind into compute env.
  - name: Database
    description: Postgres databases, extensions, credentials and ad-hoc SQL.
  - name: Storage
    description: Objects in a storage service.
  - name: Backups
    description: Database backups and restores.
  - name: Cron
    description: Scheduled HTTP calls against a service or an external URL.
  - name: Observability
    description: Logs, metrics, deploy events and database insight.
  - name: Governance
    description: Per-project agent policy and the approval queue.
  - name: Audit
    description: The project's event timeline, including agent-ingested events.
  - name: Domains
    description: >-
      Domains bought through InstaCloud, bring-your-own zones and their DNS
      records.
  - name: Billing
    description: Usage, cycles, invoices and credits.
  - name: Templates
    description: Deploy a template into a project.
paths:
  /projects/{projectId}/services/{serviceId}/access/impact:
    get:
      tags:
        - Services
      summary: Get service access impact
      description: >-
        **Token scope:** `account` · `org` · `project` — read-only tokens
        allowed.


        Preview what changing a service's public access would break, without
        changing anything. Postgres: closing public access (public=false) lists
        compute services that will lose the database (on the legacy compute
        plane, which cannot use the private network lane, or on insta-compute
        but still bound to the public DATABASE_URL) plus the external clients,
        CI and local development that will no longer be able to connect.
        Advisory only — the change is never blocked.
      operationId: getServiceAccessImpact
      parameters:
        - schema:
            type: boolean
          in: query
          name: public
          required: true
          description: the access mode being considered
        - schema:
            format: uuid
            type: string
          in: path
          name: projectId
          required: true
        - schema:
            format: uuid
            type: string
          in: path
          name: serviceId
          required: true
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessImpact'
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    AccessImpact:
      description: >-
        What changing a service's public access will break. Advisory: the change
        is never blocked on it.
      type: object
      properties:
        warnings:
          description: >-
            human-readable consequences of the change, most specific first;
            empty when nothing breaks
          type: array
          items:
            type: string
        services:
          description: >-
            compute services bound to this database that will lose their
            connection
          type: array
          items:
            type: object
            properties:
              id:
                format: uuid
                type: string
              name:
                description: compute service name
                type: string
              provider:
                $ref: '#/components/schemas/ComputeProvider'
              envName:
                description: the env var the compute reads the database from
                type: string
              sourceName:
                description: >-
                  the credential it is bound to (DATABASE_URL |
                  DATABASE_PRIVATE_URL)
                type: string
              reason:
                description: >-
                  provider-cannot-use-private-lane: the compute runs on the
                  legacy compute plane, which has no path to the private network
                  lane. bound-to-public-url: an insta-compute service still
                  bound to DATABASE_URL — rebind it to DATABASE_PRIVATE_URL and
                  redeploy.
                type: string
                enum:
                  - provider-cannot-use-private-lane
                  - bound-to-public-url
            required:
              - id
              - name
              - envName
              - sourceName
              - reason
      required:
        - warnings
        - services
    Error:
      type: object
      properties:
        error:
          type: string
      required:
        - error
    ComputeProvider:
      description: >-
        Compute plane actually backing a compute resource, derived from its
        provider_ref rather than its kind. Absent when it cannot be determined
        from the row — clients must then assert no provider rather than assume
        one from `kind`.
      type: string
      enum:
        - fly
        - insta-compute
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Session access JWT or an API token (`insta_<prefix>_<secret>`).

````