Organization API › Roles
Create a role
Creates a custom role. Every permission must be in the catalog and held by the key.
Permission (API-key scope): identity:role:write.
Authorization
bearerAuth(identity:role:write)apiKeyHeader(identity:role:write)
Request body required
namestring requireddescriptionstringpermissionsarray of stringEach must be in the catalog (else 400UNKNOWN_PERMISSION) and held by the key (else 403).
Responses
201
The role.
dataRole requiredShow Role properties
idstring requiredorg_idstring requirednamestring requireddescriptionstringpermissionsarray of string requiredPermission names from the catalog (GET /api/v1/permissions).built_instringSet on the three default roles, which cannot be deleted and only an administrator edits.created_atstring (date-time) requiredupdated_atstring (date-time) required
successboolean required
400
Not JSON (INVALID_BODY), no name or one over 100 characters (VALIDATION_ERROR), or a permission not in the catalog (UNKNOWN_PERMISSION).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
401
No API key was sent, or it is unknown, revoked or expired (UNAUTHORIZED).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
403
The key lacks the scope (FORBIDDEN); the change would grant a permission the key does not hold (FORBIDDEN, naming it); or only an administrator may do it (ADMIN_ONLY).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
409
A role with that name exists (ROLE_NAME_TAKEN).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
429
Too many requests (RATE_LIMITED). Wait Retry-After seconds.
Retry-AfterintegerSeconds to wait.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
500
Something went wrong on EvoHub's side (INTERNAL_ERROR). Retry later.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
Example request
curl -X POST 'https://evohub.io/api/v1/roles' \
-H 'Content-Type: application/json' \
-H 'Authorization: Bearer <TOKEN>' \
-d '{
"name": "Incident responder",
"description": "Answers alerts and runs incidents",
"permissions": [
"oncall:alert:read",
"oncall:alert:respond",
"oncall:incident:write"
]
}'