Update a record permission
Replaces the permission mask and the active flag of an existing record permission. Only these two fields are read from the body; the actor, record type and record id cannot be changed. Both are a full replacement: an omitted field is written as its zero value, so send both — see RecordPermissionUpdateInput.
Authorization
bearerAuth In: header
Path Parameters
Record permission id
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Body of PUT /v1/rbac/{permission_id}. A FULL REPLACEMENT of the two writable fields, not a patch: both are assigned onto the stored row from the decoded body and both Go fields are non-pointer, so an omitted field is written as its zero value. Sending only {"Permission": "CRUD"} answers 200 and silently sets active to false. The capitalised Permission key is the Go field name — that field carries no json tag — but it is NOT the only accepted spelling: apireply.DecodeJSONInput uses encoding/json, whose field matching prefers an exact match and then falls back to a case-insensitive one, so "permission" is decoded just as well. The property is declared capitalised here because that is the canonical name; be aware that a strict spec validator will reject a lowercase body the server accepts.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X PUT "https://example.com/v1/rbac/497f6eca-6276-4993-bfeb-53cbbbba6f08" \ -H "Content-Type: application/json" \ -d '{ "Permission": "CRUD", "active": true }'{
"status": 200,
"message": "OK"
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 429,
"message": "Global rate limit exceeded",
"code": "Global rate limit exceeded",
"class": "temporary",
"retryable": true
}{
"status": 400,
"code": "common.invalid_input",
"message": "Invalid input data",
"details": [
{
"field": "actor_id",
"rule": "required",
"param": "string",
"message": "actor_id is required"
}
],
"class": "validation",
"retryable": false
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2026-08-27T15:04:05Z"
}Returns every record type a record permission can be granted on. The response is a bare array, not the paginated envelope.
Replaces the route, method, active flag and metadata of a registered endpoint. The path id wins over any id in the body. This is a full replacement: an omitted field is written as its zero value, so send every field — see APIEndpointReplaceInput.