governance module route (requires governance:rbac:admin)
POST
/v1/m/governance/rbac/roles
const url = 'https://example.com/v1/m/governance/rbac/roles';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"base_role":"","created_by":"example","description":"example","display_name":"example","excludes":["example"],"groups":["example"],"name":"example","permissions":["example"]}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/v1/m/governance/rbac/roles \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "base_role": "", "created_by": "example", "description": "example", "display_name": "example", "excludes": [ "example" ], "groups": [ "example" ], "name": "example", "permissions": [ "example" ] }'Creates one custom role; the caller must be a tenant admin, and a built-in role name is refused.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Header Parameters
Section titled “Header Parameters ” X-Olivares-Tenant
string format: uuid
Target tenant id; required when the principal can act in more than one tenant.
Request Body required
Section titled “Request Body required ” Media type application/json
object
excludes
groups
Any of:
Every name must identify an existing permission-group.
Array<string>
null
name
required
Must not collide with a built-in role name.
string
Responses
Section titled “ Responses ”OK
Media type application/json
object
Example generated
{}Bad request
Media type application/json
object
Example generated
{}Unauthenticated
Media type application/json
object
Example generated
{}Forbidden
Media type application/json
object
Example generated
{}Not found
Media type application/json
object
Example generated
{}Conflict / setup required
Media type application/json
object
Example generated
{}Rate limited
Media type application/json
object
Example generated
{}