[Yandex Cloud documentation](../../../index.md) > [Yandex Cloud Functions](../../index.md) > [Step-by-step guides](../index.md) > Managing function access permissions > Making a function public

# Making a function public

To allow any user to invoke a function without providing an authorization header, make it public.

{% list tabs group=instructions %}

- Management console {#console}

    1. In the [management console](https://console.yandex.cloud), navigate to the folder containing the function.
    1. Navigate to **Cloud Functions**.
    1. Select the function you want to make public.
    1. On the **Overview** page, enable **Public function**.
    
- CLI {#cli}

    If you do not have the Yandex Cloud CLI yet, [install and initialize it](../../../cli/quickstart.md#install).

    The folder used by default is the one specified when [creating](../../../cli/operations/profile/profile-create.md) the CLI profile. To change the default folder, use the `yc config set folder-id <folder_ID>` command. You can also specify a different folder for any command using `--folder-name` or `--folder-id`. If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.

    To make a function public, run this command:
    
    ```bash
    yc serverless function allow-unauthenticated-invoke <function_name>
    ```

    Result:

    ```text
    done (1s)
    ```

- Terraform {#tf}

  With [Terraform](https://www.terraform.io/), you can quickly create a cloud infrastructure in Yandex Cloud and manage it using configuration files. These files store the infrastructure description written in HashiCorp Configuration Language (HCL). If you change the configuration files, Terraform automatically detects which part of your configuration is already deployed, and what should be added or removed.
  
  Terraform is distributed under the [Business Source License](https://github.com/hashicorp/terraform/blob/main/LICENSE). The [Yandex Cloud provider for Terraform](https://github.com/yandex-cloud/terraform-provider-yandex) is distributed under the [MPL-2.0](https://www.mozilla.org/en-US/MPL/2.0/) license.
  
  For more information about the provider resources, see the guides on the [Terraform](https://www.terraform.io/docs/providers/yandex/index.html) website or [its mirror](../../../terraform/index.md).

  If you do not have Terraform yet, [install it and configure the Yandex Cloud provider](../../../tutorials/infrastructure-management/terraform-quickstart.md#install-terraform).
  
  
  To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), [authenticate](../../../terraform/authentication.md) using the appropriate method.

  To make a function public:

  1. Describe the function access permissions in the configuration file:

     ```hcl
     resource "yandex_function_iam_binding" "function-iam" {
       function_id = "<function_ID>"
       role        = "functions.functionInvoker"
       members = [
         "system:allUsers",
       ]
     }
     ```

     Where:

     * `function_id`: Function ID. To find out the function ID, [get the list of functions](function-list.md) in the folder.
     * `role`: Role you need to assign.
     * `members`: List of users to assign the role to.

        To make a function public, assign the `functions.functionInvoker` role to all unauthorized users (the `All users` [public group](../../../iam/concepts/access-control/public-group.md)).

     For more on the properties of the `yandex_function_iam_binding` resource, see [this provider guide](../../../terraform/resources/function_iam_binding.md).

  1. Validate your configuration using this command:

     ```bash
     terraform validate
     ```

     If the configuration is valid, you will get this message:

     ```text
     Success! The configuration is valid.
     ```

  1. Run this command:

     ```bash
     terraform plan
     ```

     You will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration. 

  1. Apply the configuration changes:

     ```bash
     terraform apply
     ```

  1. Confirm the changes: type `yes` into the terminal and press **Enter**.

     You can check the assignment of the function role using the [management console](https://console.yandex.cloud) or this [CLI](../../../cli/quickstart.md) command:

     ```bash
     yc serverless function list-access-bindings <function_name>
     ```

- API {#api}

   To make a function public, use the [setAccessBindings](../../functions/api-ref/Function/setAccessBindings.md) REST API method for the [Function](../../functions/api-ref/Function/index.md) resource or the [FunctionService/SetAccessBindings](../../functions/api-ref/grpc/Function/setAccessBindings.md) gRPC API call.

{% endlist %}