Give Capability To Principal
Grant one or more capabilities to a principal: a user, a role, or a whole tenant.
Granting to the tenant reaches every current and future member; granting to a role reaches its members; granting to a user reaches that person in the given tenant only. The same endpoint serves all three because a capability row is (principal, tenant, capability) regardless of what the principal is.
The caller needs the grant_capabilities capability in the target tenant, and must hold every capability they grant: granting passes on what the caller has, never more. The tenant owner holds everything, which is how the first grant gets made. The caller is recorded as the granter of each new grant.
Several capabilities can be granted in one call by repeating the capability parameter. The batch is all or nothing: an unknown name rejects the whole request and nothing is written. Granting is idempotent.
Error Codes
- 400 Bad Request: A capability is not in the catalog
- 403 Forbidden: Caller lacks grant_capabilities in the target tenant, or the principal or tenant does not exist. These answer the same, so the endpoint cannot be used to discover which ids are real. Also when the caller does not hold a capability they try to grant, or the principal is a user who is not a member of the tenant (that one says so: add the user to the tenant first)
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Query Parameters
Capability to grant. Must be in the capability catalog. Repeat the parameter to grant several at once: ?capability=a&capability=b.
Tenant the grant is scoped to when the principal is a user. Defaults to the caller's current tenant. Ignored for a role or a tenant, whose own tenant is always used.
Response
Successful Response