Skip to main content
POST
Create Custom Role

Authentication and permissions

Token requirements: User-based token (OAuth) or Organization-scoped API key. Send a bearer access token for one of these identities. The permissions and resource restrictions below also apply.
Permissions joined by + are all required; or separates alternatives. Full-access keys still cannot call endpoints marked unsupported. Team keys must allow every team checked by the request. OAuth access depends on the user’s roles and resource access.
  • Default request: With a user OAuth token, you also need Edit Team Settings on the role’s team, and you can grant only actions you already hold there.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

team_id
string
required

The team that owns the role. A custom role can only be assigned on its own team.

Body

application/json
name
string
required

Unique among the team's custom roles.

baseRole
enum<string>
required

The built-in role the custom role extends. A member holding the custom role has everything the base role grants plus granted_actions.

Available options:
TEAM_USER_ROLE_UNSPECIFIED,
TEAM_USER_ROLE_AGENT,
TEAM_USER_ROLE_MANAGER,
TEAM_USER_ROLE_BUILDER,
TEAM_USER_ROLE_VIEWER,
TEAM_USER_ROLE_CONTRIBUTOR,
TEAM_USER_ROLE_DRAFTER,
TEAM_USER_ROLE_READONLY_AGENT,
TEAM_USER_ROLE_APP_BUILDER,
TEAM_USER_ROLE_APP_VIEWER,
TEAM_USER_ROLE_PERSONAL_TEAM_OWNER
description
string
grantedActions
string[]

Action slugs the role grants on top of its base role. Only grantable actions are accepted; an unknown or non-grantable slug rejects the request.

Response

200 - application/json

Success

data
data · object