Practically speaking, the CheckAccess endpoint is annoying for use in administrative actions, because it requires the right Content-Type headers. Philosophically, the endpoint only inspects, so it should not use the POST method. Change-Id: I5270b683f51f2876785ba84e762b7ecedbceea21