Replace a role's complete access list
Send permission IDs from the catalogue and the last read lockVersion. An empty list denies all configurable APIs. Unknown/duplicate IDs are rejected. Changes apply to already-issued bearer tokens on their next request. The last permanent access administrator cannot be locked out; OWNER remains protected. Company permission: `replaceCompanyRolePermissions`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
code*stringapplication/json- body
lockVersion*integerint320 <= valuepermissions*array<>0 <= items <= 1000Role permissions replaced; returns the incremented lockVersion
*/*- response
code?stringdefaultPermissions?booleanid?stringuuidlockVersion?integerint32name?stringpermissions?array<string>curl -X PUT 'https://api.monetaryai.uz/api/v1/settings/roles/string/permissions' \ -H 'Content-Type: application/json' \ -d '{ "lockVersion": 0, "permissions": []}'{ "code": "string", "defaultPermissions": true, "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "lockVersion": 0, "name": "string", "permissions": [ "string" ]}Restore a role's default access POST
Versioned reset to documented defaults; custom changes in other companies are untouched. Company permission: `resetCompanyRolePermissions`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.
Edit a company user's name, role and status PUT
Replaces company-local display name, optional contact email, one default role and ACTIVE/SUSPENDED status using lockVersion. Login email/password and global profile are never changed. Self edits and owner edits are forbidden. Existing temporary/special grants are revoked; suspension also revokes refresh sessions. Other company memberships are untouched. Company permission: `updateCompanyUser`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.