MonetaryAI / Docs
API ReferenceUsers and roles

Replace a role's complete access list

Send permission IDs from the catalogue and the last read lockVersion. An empty list denies all configurable APIs. Unknown/duplicate IDs are rejected. Changes apply to already-issued bearer tokens on their next request. The last permanent access administrator cannot be locked out; OWNER remains protected. Company permission: `replaceCompanyRolePermissions`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.

PUT
/api/v1/settings/roles/{code}/permissions

Authorization

bearerAuth
headerAuthorizationBearer <token>

Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.

Path Parameters

code*string

Request Body

application/json
  1. body
lockVersion*integer
Formatint32
Range0 <= value
permissions*array<>
Items0 <= items <= 1000

Response Body

Role permissions replaced; returns the incremented lockVersion

*/*
  1. response
code?string
defaultPermissions?boolean
id?string
Formatuuid
lockVersion?integer
Formatint32
name?string
permissions?array<string>
curl -X PUT 'https://api.monetaryai.uz/api/v1/settings/roles/string/permissions' \  -H 'Content-Type: application/json' \  -d '{  "lockVersion": 0,  "permissions": []}'
{  "code": "string",  "defaultPermissions": true,  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",  "lockVersion": 0,  "name": "string",  "permissions": [    "string"  ]}