//RBAC API
RBAC V2 API
The Role-Based Access Control (RBAC) system has been promoted to the Rust-native Control Plane, providing sub-millisecond policy resolution.
Native Endpoints (Recommended)
GET /api/roles
Lists all available roles in the system.GET /api/roles/permissions
Lists all possible permissions that can be assigned.GET /api/roles/:role_id/permissions
Returns the specific permissions assigned to a role.PUT /api/roles/:role_id/permissions
Replaces the permissions for a role with a new set.Input: ~~~json { "permissions": [1, 5, 10] } ~~~
V2 Compatibility Routes
GET /api/v2/products/:productId/permissions
Retrieves the list of available permissions for a product.Output: ~~~json { "data": [{ "id": 1, "name": "user:create" }] } ~~~
POST /api/v2/products/:productId/roles
Creates a new custom role for a product.Input: ~~~json { "name": "Editor", "permissions": [{ "id": 1 }] } ~~~
Output: ~~~json { "data": { "id": 2, "name": "Editor" } } ~~~
GET /api/v2/organizations/:org_uuid/products/:productId/roles
Lists roles that can be assigned within an organization.Output: ~~~json { "data": [{ "id": 2, "name": "Editor" }] } ~~~
PUT /api/v2/organizations/:org_uuid/users/:user_uuid/role
Assigns a role to a user.Input: ~~~json { "roleId": 2 } ~~~
Output: ~~~json { "message": "Role assigned" } ~~~