Register an API endpoint
Adds a route to the endpoint registry. Returns 200 with the created entity, not 201.
Authorization
bearerAuth In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Body of POST /v1/rbac/endpoints. An omitted active stores false. The server runs no field validation here: an omitted or unrecognised method reaches the http_method database enum and comes back as 500, not 400.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/rbac/endpoints" \ -H "Content-Type: application/json" \ -d '{ "endpoint": "/v1/accounts/%", "method": "GET" }'{
"endpoint": "/v1/accounts/%",
"method": "GET",
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"created_at": "2019-08-24T14:15:22Z",
"created_by": "ee824cad-d7a6-4f48-87dc-e8461a9201c4",
"modified_at": "2019-08-24T14:15:22Z",
"modified_by": "e8d4374d-93a1-4e98-a6c6-fdcf00c5059f",
"active": true,
"metadata": {}
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 429,
"message": "Global rate limit exceeded",
"code": "Global rate limit exceeded",
"class": "temporary",
"retryable": true
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2026-08-27T15:04:05Z"
}Update, not create: the path id names the existing API permission and the body replaces its actor, endpoint, type and rate limits. Returns 200.
Returns API permissions with their endpoint expanded, in the standard paginated envelope. Unrecognised query parameters are SILENTLY DROPPED. query.ParseQueryParameters switches on the parameter name and its default branch returns nil, so a typo such as ?lmit=50 or a parameter this endpoint does not support produces neither an error nor a warning — the request runs with the default paging and the caller sees a plausible but unfiltered page.