Grant a role to a principal
const url = 'https://example.com/api/v1/principals/example/grants';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"role":"example","scope_id":"example","scope_kind":"all","scope_op":"subtree"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/api/v1/principals/example/grants \ --header 'Content-Type: application/json' \ --data '{ "role": "example", "scope_id": "example", "scope_kind": "all", "scope_op": "subtree" }'Assigns a role at a scope to a principal. Gated by principal_grant:create (all-scope). Refused (403) when the granted role’s capabilities exceed the granter’s own (no promoting anyone, including yourself, to a higher tier such as owner). A duplicate is 409, an unknown role or bad scope 422.
Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”The principal, addressed by its uuid or a human username
The principal, addressed by its uuid or a human username
Request Body required
Section titled “Request Body required ”object
A URL to the JSON Schema for this object.
A role id (viewer, operator, admin, owner, or a custom role)
The scope root id; omit for the all scope
The scope kind; ‘all’ confers the whole estate
How the scope root matches the tree: subtree (root + descendants, the default), subtree_excl_root (descendants only for update/delete, root kept for read/create), or self (the root row only). Moot for the all scope.
Responses
Section titled “ Responses ”Created
object
A URL to the JSON Schema for this object.
Set when this grant is inherited from a group the principal belongs to (the group’s id); absent for a direct grant, which is the only kind revocable from the principal.
The source group’s label, present when the grant is inherited.
How the scope root matches the tree: subtree (root + descendants), subtree_excl_root (descendants only for update/delete, root kept for read/create), or self (the root row only). Empty means subtree. Moot for the all scope.
Example
{ "$schema": "/api/v1/schemas/GrantBody.json", "scope_op": "subtree"}default
Section titled “default ”Error
object
A URL to the JSON Schema for this object.
A human-readable explanation specific to this occurrence of the problem.
Optional list of individual error details
object
Where the error occurred, e.g. ‘body.items[3].tags’ or ‘path.thing-id’
Error message text
The value at the given location
A URI reference that identifies the specific occurrence of the problem.
HTTP status code
A short, human-readable summary of the problem type. This value should not change between occurrences of the error.
A URI reference to human-readable documentation for the error.
Example
{ "$schema": "/api/v1/schemas/ErrorModel.json", "detail": "Property foo is required but is missing.", "instance": "https://example.com/error-log/abc123", "status": 400, "title": "Bad Request", "type": "about:blank"}