Roles
Model
Fields
Field | Type | Description |
|---|---|---|
object | "role" | |
id | string | |
name | string | |
team_id | string | |
scopes | | The permissions the role grants: each resource mapped to its allowed actions (read, write,
delete). |
List Roles
Endpoint
Retrieve a list of roles for the current team.
GET
/v1/roles Query Parameters
Field | Type | Description |
|---|---|---|
order_by | string | Field used to order the roles. Defaults to "name". Accepted values: "name". |
limit | number | Defaults to 25. Minimum: 1. Maximum: 200. |
after | string | Cursor from pagination.next_cursor of a previous response. Returns the resources after that page. |
before | string | Cursor from pagination.prev_cursor of a previous response. Returns the resources before that page. |
sort | string | Defaults to "asc". Accepted values: "asc","desc". |
Comments
afterandbeforeare mutually exclusive.
Response
200
{
message: string;
data: Role[];
status: 200;
error: null;
pagination: Pagination;
endpoint: string;
} Retrieve Role
Endpoint
Retrieve a single role.
GET
/v1/roles/:role_id Path Parameters
Field | Type | Description |
|---|---|---|
role_id | string | Unique identifier of the role. |
Response
200
{
message: string;
data: Role;
status: 200;
error: null;
pagination: null;
endpoint: string;
} Create Role
Endpoint
Create a new role for the current team.
POST
/v1/roles Request Body
Field | Type | Requirement | Description |
|---|---|---|---|
id | string | Optional | Custom identifier for the role. One is generated when omitted. |
name | string | Required | Display name for the role. Minimum length: 2. Maximum length: 60. |
scopes | | Optional | Scope names mapped to their permitted actions. Allowed scope keys: "users", "roles", "keys", "records", "projects", "metrics", "views", "billing", "pages", "monitors", "alerts", "chats", "secrets", "servers", "ingest_keys", "sources", "domains", "facets", "drains", "pulls", "checks", "logs". Allowed action values: "read", "write", "delete". |
Comments
idcannot berole_owner, which is reserved.- Omit
idand one is generated for you. - You can assign only scopes that your own authorization has.
- The built-in
role_ownerrole cannot be created, updated, or deleted. - Human roles must include
projects:read.
Response
201
{
message: string;
data: Role;
status: 201;
error: null;
pagination: null;
endpoint: string;
} Update Role
Endpoint
Update an existing role.
POST
/v1/roles/:role_id Path Parameters
Field | Type | Description |
|---|---|---|
role_id | string | Unique identifier of the role. |
Request Body
Field | Type | Requirement | Description |
|---|---|---|---|
name | string | Optional | Display name for the role. Minimum length: 2. Maximum length: 60. |
scopes | | Optional | Scope names mapped to their permitted actions. Allowed scope keys: "users", "roles", "keys", "records", "projects", "metrics", "views", "billing", "pages", "monitors", "alerts", "chats", "secrets", "servers", "ingest_keys", "sources", "domains", "facets", "drains", "pulls", "checks", "logs". Allowed action values: "read", "write", "delete". |
Comments
- A role's
idcannot be changed. Every user assignment points at it, so a rename would orphan them. - You can assign only scopes that your own authorization has.
- The built-in
role_ownerrole cannot be created, updated, or deleted. - Human roles must include
projects:read.
Response
200
{
message: string;
data: Role;
status: 200;
error: null;
pagination: null;
endpoint: string;
} Delete Role
Endpoint
Delete a role from the current team.
DELETE
/v1/roles/:role_id Path Parameters
Field | Type | Description |
|---|---|---|
role_id | string | Unique identifier of the role. |
Comments
- Roles with assigned users cannot be deleted. Reassign those users before deleting the role.
- The built-in
role_ownerrole cannot be created, updated, or deleted.
Response
200
{
message: string;
data: null;
status: 200;
error: null;
pagination: null;
endpoint: string;
} Referenced Types
Scopes
Record<string, ("read" | "write" | "delete")[]> Scope names mapped to their permitted actions. Allowed scope keys: "users", "roles", "keys", "records", "projects", "metrics", "views", "billing", "pages", "monitors", "alerts", "chats", "secrets", "servers", "ingest_keys", "sources", "domains", "facets", "drains", "pulls", "checks", "logs". Allowed action values: "read", "write", "delete".
Scope
users
roles
keys
records
projects
metrics
views
billing
pages
monitors
alerts
chats
secrets
servers
ingest_keys
sources
domains
facets
drains
pulls
checks
logs
ScopeValue
read
write
delete