Set the permissions of an API key
POST/api-keys/:api_key_id/permissions
Adds, changes or removes permission entries of an API key; entries that the request does not name are unchanged. An entry replaces the entry with the same object type and object identifier, and a permission of 0 removes the entry. Foundation4 applies all entries in one transaction, so a refused entry leaves every entry unchanged.
Permissions. Write on the API key. Each granted permission must be contained in the calling key's permission on the object type or on the object. When the calling key's allow-list on pipelines is not *, the granted classifications must be in the calling key's allow-list for the pipeline.
Scoped keys describes the request with an example.
Request
Responses
- 200
- 401
- 403
- 404
- 422
The permission entries were applied. The response has no body.
The authentication headers are missing or invalid, or the API key is inactive or expired. Errors lists the messages.
The request grants a permission or classification that the calling key does not hold (Unauthorized: access level ... required for Api Key with id ...), or the license does not permit changes (Invalid license: ...).
No API key with this identifier exists, or the calling key lacks write permission on the API key (Api Key with id <id> not found).
The body does not match the request schema, for example a permission value outside 0 to 7 or an unknown object type. The response body is plain text.