Organization API › Roles
Update a role
Replaces the role's name, description and permissions: send all three
(name is required; a permissions left out keeps the list). Every holder's
access changes at once. Permissions added must be held by the key; a default
role is edited only by an administrator (ADMIN_ONLY).
Permission (API-key scope): identity:role:write.
Authorization
bearerAuth(identity:role:write)apiKeyHeader(identity:role:write)
Parameters
Path parameters
idstring requiredThe id of the member (usr_…), team (team_…), role (role_…), invitation (inv_…) or organization (org_…) the path names.
Request body required
namestring requireddescriptionstringpermissionsarray of stringEach must be in the catalog (else 400UNKNOWN_PERMISSION) and held by the key (else 403).
Responses
200
The role.
dataRole requiredShow Role properties
idstring requiredorg_idstring requirednamestring requireddescriptionstringpermissionsarray of string requiredPermission names from the catalog (GET /api/v1/permissions).built_instringSet on the three default roles, which cannot be deleted and only an administrator edits.created_atstring (date-time) requiredupdated_atstring (date-time) required
successboolean required
400
Not JSON, no name, or an unknown permission (INVALID_BODY, VALIDATION_ERROR, UNKNOWN_PERMISSION).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
401
No API key was sent, or it is unknown, revoked or expired (UNAUTHORIZED).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
403
The key lacks the scope (FORBIDDEN); the change would grant a permission the key does not hold (FORBIDDEN, naming it); or only an administrator may do it (ADMIN_ONLY).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
404
No such role in the organization (NOT_FOUND).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
409
Another role has that name (ROLE_NAME_TAKEN).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
429
Too many requests (RATE_LIMITED). Wait Retry-After seconds.
Retry-AfterintegerSeconds to wait.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
500
Something went wrong on EvoHub's side (INTERNAL_ERROR). Retry later.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
Example request
curl -X PATCH 'https://evohub.io/api/v1/roles/string' \
-H 'Content-Type: application/json' \
-H 'Authorization: Bearer <TOKEN>' \
-d '{
"name": "Incident responder",
"description": "Answers alerts, runs incidents and writes postmortems",
"permissions": [
"oncall:alert:read",
"oncall:alert:respond",
"oncall:incident:write",
"oncall:postmortem:write"
]
}'