Create a role

Define a new role — a name and the list of what it allows. A permission names an area and what may be done in it: read, create, update, delete. A door scanner might get `objects` read and `ebus.actions` create, and nothing else. You cannot create a role that can do more than you can. That is what keeps an admin from quietly building themselves an owner. Role names have to be unique within the organization, ignoring case, and cannot be changed afterwards. Requires the `organizations.roles.create` permission.

POST
/organizations/{organizationId}/roles
AuthorizationBearer <token>

The access token returned after a successful sign-in, sent as Authorization: Bearer <access_token>.

It identifies the person and the organization they are working in, and it lasts about fifteen minutes. When it runs out, use their refresh token at POST /auth/refresh-token instead of asking them to sign in again.

In: header

Path Parameters

organizationId*string

Identifier of the organization. Each endpoint states whether it must be the caller's active organization or may be used without authentication.

Request Body

application/json

The role to create.

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://api.dual.network/organizations/665f1c2d4b1a2c3d4e5f6aa0/roles" \  -H "Content-Type: application/json" \  -d '{    "name": "scanner",    "description": "Scans and redeems tickets at the door.",    "permissions": [      {        "resource": "objects",        "crud": {          "read": true,          "create": false,          "update": false,          "delete": false        }      },      {        "resource": "ebus.actions",        "crud": {          "read": true,          "create": true,          "update": false,          "delete": false        }      }    ]  }'
{
  "id": "665f1c2d4b1a2c3d4e5f6a7b"
}
{
  "code": 3,
  "message": "Key: 'limit' Error:Field validation for 'limit' failed on the 'lte' tag"
}

{
  "code": 16,
  "message": "no auth provided"
}

{
  "code": 5,
  "message": "object not found"
}
{
  "code": 13,
  "message": "internal error"
}