Custom roles
Create custom role
Create a new custom role
Authorization
ApiKey read, writeAuthorization<token>
In: header
Scope: read, write
Request Body
application/json
name*string
A human-friendly name for the custom role
key*string
The custom role key
description?string
Description of custom role
policy*array<>
Resource statements for custom role
basePermissions?RoleType
Base permissions to use for this role. Defaults to no_access (older roles defaulted to reader). Recommended to set this to no_access in all cases.
Value in
- "reader"
- "no_access"
resourceCategory?ResourceCategory
The category of resources this role is intended to manage. Can be organization, project, or any. This field is immutable.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/api/v2/roles" \ -H "Content-Type: application/json" \ -d '{ "basePermissions": "reader", "description": "An example role for members of the ops team", "key": "role-key-123abc", "name": "Ops team", "policy": [ { "actions": [ "updateOn" ], "effect": "allow", "resources": [ "proj/*:env/production:flag/*" ] } ] }'{ "_id": "1234a56b7c89d012345e678f", "_links": { "property1": { "href": "string", "type": "string" }, "property2": { "href": "string", "type": "string" } }, "_access": { "denied": [ { "action": "string", "reason": { "resources": [ "proj/*:env/*;qa_*:/flag/*" ], "notResources": [ "string" ], "actions": [ "*" ], "notActions": [ "string" ], "effect": "allow", "role_name": "string" } } ], "allowed": [ { "action": "string", "reason": { "resources": [ "proj/*:env/*;qa_*:/flag/*" ], "notResources": [ "string" ], "actions": [ "*" ], "notActions": [ "string" ], "effect": "allow", "role_name": "string" } } ] }, "description": "This custom role is just an example", "key": "example-custom-role", "name": "Example custom role", "policy": [ { "resources": [ "proj/*:env/*;qa_*:/flag/*" ], "notResources": [ "string" ], "actions": [ "*" ], "notActions": [ "string" ], "effect": "allow" } ], "basePermissions": "reader", "resourceCategory": "string", "assignedTo": { "membersCount": 0, "teamsCount": 0 }, "_presetBundleVersion": 0, "_presetStatements": [ { "resources": [ "proj/*:env/*;qa_*:/flag/*" ], "notResources": [ "string" ], "actions": [ "*" ], "notActions": [ "string" ], "effect": "allow" } ]}