//RBAC API

RBAC V2 API

The Role-Based Access Control (RBAC) system has been promoted to the Rust-native Control Plane, providing sub-millisecond policy resolution.

Native Endpoints (Recommended)

GET /api/roles

Lists all available roles in the system.

GET /api/roles/permissions

Lists all possible permissions that can be assigned.

GET /api/roles/:role_id/permissions

Returns the specific permissions assigned to a role.

PUT /api/roles/:role_id/permissions

Replaces the permissions for a role with a new set.

Input: ~~~json { "permissions": [1, 5, 10] } ~~~

V2 Compatibility Routes

GET /api/v2/products/:productId/permissions

Retrieves the list of available permissions for a product.

Output: ~~~json { "data": [{ "id": 1, "name": "user:create" }] } ~~~

POST /api/v2/products/:productId/roles

Creates a new custom role for a product.

Input: ~~~json { "name": "Editor", "permissions": [{ "id": 1 }] } ~~~

Output: ~~~json { "data": { "id": 2, "name": "Editor" } } ~~~

GET /api/v2/organizations/:org_uuid/products/:productId/roles

Lists roles that can be assigned within an organization.

Output: ~~~json { "data": [{ "id": 2, "name": "Editor" }] } ~~~

PUT /api/v2/organizations/:org_uuid/users/:user_uuid/role

Assigns a role to a user.

Input: ~~~json { "roleId": 2 } ~~~

Output: ~~~json { "message": "Role assigned" } ~~~