# Allow creating and management of authentication backends (AppRole, LDAP, etc.) path "sys/auth/*" { capabilities = ["create", "update", "delete", "read", "list"] }