A valid request URL is required to generate request examples{
"roles": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"key": "teacher",
"name": "Professor",
"is_system": true,
"permissions": [
"$team.manage",
"grades:write"
],
"current_version": 123,
"member_count": 123
}
],
"reserved_permissions": [
"$team.manage",
"$billing.manage",
"$keys.manage"
]
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}List customer roles
Requires customers:read. This environment’s role vocabulary, the two system roles first. member_count is how many memberships hold each one — a role with members cannot be deleted, so a screen offering the button needs the number before it offers it.
reserved_permissions on the envelope is the $… half of the vocabulary: the capabilities UserKit itself evaluates. It is published here so a role editor can offer them without shipping its own copy of the list. Your own permission strings are not enumerable by construction — they are whatever you type.
A valid request URL is required to generate request examples{
"roles": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"key": "teacher",
"name": "Professor",
"is_system": true,
"permissions": [
"$team.manage",
"grades:write"
],
"current_version": 123,
"member_count": 123
}
],
"reserved_permissions": [
"$team.manage",
"$billing.manage",
"$keys.manage"
]
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}Autorizações
A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange. Only a 401 means it is spent; not_a_member (403) is about the organization named in X-Organization-Id and leaves the token good for the others.
Cabeçalhos
The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing: the answer is not_a_member (403), which does not mean the session is over. Absent, the session's default organization answers, or — if that membership was revoked while the session was open — any other one the caller still holds.
Parâmetros de consulta
Which environment to act in. A view parameter, valid only on the staff surface — a machine credential never chooses its environment, it is resolved from the key.
live, test