# Create a role

`POST https://evohub.io/api/v1/roles`

Part of the [Organization API](https://docs-dev.evohub.io/organization.md) reference · operationId `createRole`.

Creates a custom role. Every permission must be in the catalog and held by the key.

**Permission (API-key scope):** `identity:role:write`.

## Authorization

Any one of:

- `bearerAuth` (identity:role:write)
- `apiKeyHeader` (identity:role:write)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Request body (required)

Content type: `application/json`

Type: `RoleWrite`

- `name` (string, required, min length 1, max length 100)
- `description` (string)
- `permissions` (array of string): Each must be in the catalog (else 400 `UNKNOWN_PERMISSION`) and held by the key (else 403).

## Responses

### 201 — The role.

Content type: `application/json`

Type: `object`

- `data` (Role, required)
  - `id` (string, required)
  - `org_id` (string, required)
  - `name` (string, required)
  - `description` (string)
  - `permissions` (array of string, required): Permission names from the catalog (`GET /api/v1/permissions`).
  - `built_in` (string, one of `admin`, `member`, `viewer`): Set on the three default roles, which cannot be deleted and only an administrator edits.
  - `created_at` (string (date-time), required)
  - `updated_at` (string (date-time), required)
- `success` (boolean, required, value `true`)

### 400 — Not JSON (`INVALID_BODY`), no name or one over 100 characters (`VALIDATION_ERROR`), or a permission not in the catalog (`UNKNOWN_PERMISSION`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 403 — The key lacks the scope (`FORBIDDEN`); the change would grant a permission the key does not hold (`FORBIDDEN`, naming it); or only an administrator may do it (`ADMIN_ONLY`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 409 — A role with that name exists (`ROLE_NAME_TAKEN`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

## Example request

```bash
curl -X POST 'https://evohub.io/api/v1/roles' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer <TOKEN>' \
  -d '{
  "name": "Incident responder",
  "description": "Answers alerts and runs incidents",
  "permissions": [
    "oncall:alert:read",
    "oncall:alert:respond",
    "oncall:incident:write"
  ]
}'
```
