Skip to main content
POST
Error

Autorizações

Authorization
string
header
obrigatório

A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange. Only a 401 means it is spent; not_a_member (403) is about the organization named in X-Organization-Id and leaves the token good for the others.

Cabeçalhos

X-Organization-Id
string

The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing: the answer is not_a_member (403), which does not mean the session is over. Absent, the session's default organization answers, or — if that membership was revoked while the session was open — any other one the caller still holds.

Parâmetros de caminho

id
string<uuid>
obrigatório

The role.

versionId
string<uuid>
obrigatório

The version to make live.

Parâmetros de consulta

environment
enum<string>
padrão:live

Which environment to act in. A view parameter, valid only on the staff surface — a machine credential never chooses its environment, it is resolved from the key.

Opções disponíveis:
live,
test

Resposta

The role, now granting what that version granted.

A role inside a customer, in one environment. permissions mixes the two vocabularies: $… entries are the capabilities UserKit evaluates, everything else is yours and reaches your backend through the contact's JWT.

id
string<uuid>
key
string

The stored literal. Immutable.

Exemplo:

"teacher"

name
string
Exemplo:

"Professor"

is_system
boolean

owner and member, seeded into every environment. Not deletable; name and permissions still editable.

permissions
string[]
Exemplo:
current_version
integer

Which version of the permission set is live. An edit bumps it; a restore moves it back.

member_count
integer<int64>

Memberships holding this role. A role with any cannot be deleted.