Skip to content

Grant a role to a principal

POST
/principals/{id}/grants
curl --request POST \
--url https://example.com/api/v1/principals/example/grants \
--header 'Content-Type: application/json' \
--data '{ "role": "example", "scope_id": "example", "scope_kind": "all", "scope_op": "subtree" }'

Assigns a role at a scope to a principal. Gated by principal_grant:create (all-scope). Refused (403) when the granted role’s capabilities exceed the granter’s own (no promoting anyone, including yourself, to a higher tier such as owner). A duplicate is 409, an unknown role or bad scope 422.

id
required

The principal, addressed by its uuid or a human username

string

The principal, addressed by its uuid or a human username

Media type application/json
object
$schema

A URL to the JSON Schema for this object.

string format: uri
role
required

A role id (viewer, operator, admin, owner, or a custom role)

string
>= 1 characters
scope_id

The scope root id; omit for the all scope

string
scope_kind
required

The scope kind; ‘all’ confers the whole estate

string
Allowed values: all location system component group
scope_op

How the scope root matches the tree: subtree (root + descendants, the default), subtree_excl_root (descendants only for update/delete, root kept for read/create), or self (the root row only). Moot for the all scope.

string
Allowed values: subtree subtree_excl_root self

Created

Media type application/json
object
$schema

A URL to the JSON Schema for this object.

string format: uri
group_id

Set when this grant is inherited from a group the principal belongs to (the group’s id); absent for a direct grant, which is the only kind revocable from the principal.

string
group_name

The source group’s label, present when the grant is inherited.

string
id
string
role
required
string
scope_id
string
scope_kind
required
string
scope_op

How the scope root matches the tree: subtree (root + descendants), subtree_excl_root (descendants only for update/delete, root kept for read/create), or self (the root row only). Empty means subtree. Moot for the all scope.

string
Allowed values: subtree subtree_excl_root self
Example
{
"$schema": "/api/v1/schemas/GrantBody.json",
"scope_op": "subtree"
}

Error

Media type application/problem+json
object
$schema

A URL to the JSON Schema for this object.

string format: uri
detail

A human-readable explanation specific to this occurrence of the problem.

string
errors

Optional list of individual error details

Array<object> | null
object
location

Where the error occurred, e.g. ‘body.items[3].tags’ or ‘path.thing-id’

string
message

Error message text

string
value

The value at the given location

instance

A URI reference that identifies the specific occurrence of the problem.

string format: uri
status

HTTP status code

integer format: int64
title

A short, human-readable summary of the problem type. This value should not change between occurrences of the error.

string
type

A URI reference to human-readable documentation for the error.

string format: uri
default: about:blank
Example
{
"$schema": "/api/v1/schemas/ErrorModel.json",
"detail": "Property foo is required but is missing.",
"instance": "https://example.com/error-log/abc123",
"status": 400,
"title": "Bad Request",
"type": "about:blank"
}