How to define all allowed actions for API endpoints?

I finally solved it using the user-permissions role service.
Iterated through the permissions while updating the permissions for each api