A valid request URL is required to generate request examples{
"role": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"is_system": true,
"permissions": [
"organization:update"
]
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}Create a role
Requires roles:manage. Custom roles are never is_system, so they stay renamable and deletable. An unknown permission is refused rather than silently ignored.
Creating a role beyond the system ones is the one act on this surface a plan may refuse (custom_roles_not_included, 402). Everything else stays available on every plan: listing roles, tailoring what a system role allows, and editing, reassigning or deleting a role that already exists — a plan may stop new roles being created, never take away the ones an organization already made.
A valid request URL is required to generate request examples{
"role": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"is_system": true,
"permissions": [
"organization:update"
]
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}Autorizações
A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange. Only a 401 means it is spent; not_a_member (403) is about the organization named in X-Organization-Id and leaves the token good for the others.
Cabeçalhos
The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing: the answer is not_a_member (403), which does not mean the session is over. Absent, the session's default organization answers, or — if that membership was revoked while the session was open — any other one the caller still holds.
Corpo
The complete set. Duplicates are collapsed; an unknown value is refused.
A fine-grained capability. The catalogue lives in Go; which role holds which lives in the database.
organization:update, organization:delete, members:read, members:write, roles:read, roles:manage, api_keys:read, api_keys:write, customers:read, customers:write Resposta
Created.
Show child attributes
Show child attributes