Grant a record permission
Grants an actor (user or role) a permission mask on a record type, optionally scoped to a single record id. Returns the standard success envelope, not the created entity.
Authorization
bearerAuth In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Body of POST /v1/rbac.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/rbac" \ -H "Content-Type: application/json" \ -d '{}'{
"status": 200,
"message": "OK"
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 429,
"message": "Global rate limit exceeded",
"code": "Global rate limit exceeded",
"class": "temporary",
"retryable": true
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2026-08-27T15:04:05Z"
}RBAC Endpoint-Role Management
Previous Page
Grants an actor (user or role) the right to call a registered endpoint, with optional per-period rate limits. Idempotent on the `(api_endpoint_id, actor_id)` pair, and only on that pair: if a grant for it already exists, the stored row is returned unchanged with 201 and the rest of the request body is ignored — including `type` and every rate limit. So re-posting with a new `rate_limit_per_minute` answers 201 while the old limit stays in force, and posting `type: "role"` over an existing `user` grant returns the user row instead of creating a role grant. Use `POST /v1/rbac/api-permissions/{id}` to change an existing grant.