Skip to content

governance module route (requires governance:rbac:admin)

POST
/v1/m/governance/rbac/grants
curl --request POST \
--url https://example.com/v1/m/governance/rbac/grants \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "created_by": "example", "id": "example", "note": "example", "role": "example", "role_custom": true, "scope_class": "example", "scope_ref": "example", "scope_tree": "tenant", "subject_kind": "user", "subject_ref": "example" }'

Creates one scoped RBAC grant from the posted document.

X-Olivares-Tenant
string format: uuid

Target tenant id; required when the principal can act in more than one tenant.

Media type application/json
object
created_by
Any of:

Output field accepted by the DTO but ignored on create.

string
id
Any of:

Output field accepted by the DTO but ignored on create.

string
note
Any of:

Capped at 4096 bytes.

string
role
required

Must resolve to a built-in role unless role_custom is true, then to a custom role.

string
/.*\S.*/
role_custom
Any of:
boolean
scope_class
Any of:

When non-empty, must be a scopeable resource kind compatible with the selected tree.

string
scope_ref
Any of:

Must be empty for tenant and identify an existing anchor for every other scope tree.

string
scope_tree
required
string
Allowed values: tenant workspace agent_group folder
subject_kind
required
string
Allowed values: user role group
subject_ref
required

User/group identifier, or a built-in role name when subject_kind is role.

string
/.*\S.*/

OK

Media type application/json
object
Example generated
{}

Bad request

Media type application/json
object
Example generated
{}

Unauthenticated

Media type application/json
object
Example generated
{}

Forbidden

Media type application/json
object
Example generated
{}

Not found

Media type application/json
object
Example generated
{}

Conflict / setup required

Media type application/json
object
Example generated
{}

Rate limited

Media type application/json
object
Example generated
{}