---
title: "Replace one group's permissions"
description: "Writes what this ONE group may do, leaving every other group untouched: permissions are per group and never cross, so there is no ordering to get right and nothing to shadow."
canonical: "https://gtable.app/docs/builder-api/groups/set-permissions"
updated: "2026-10-05"
---

# Replace one group's permissions

`PUT https://studio.gtable.app/v1/apps/{appId}/groups/{groupId}/permissions`

Writes what this ONE group may do, leaving every other group untouched: permissions are per group and never cross, so there is no ordering to get right and nothing to shadow.

Send every table the group should reach; a table you leave out becomes inaccessible to it. Simulate first if you are unsure who is affected. Send the `revision` groups.get gave you as `baseRevision`, and a save made after somebody else changed this group is refused with 409 rather than erasing their change.

Requires the `schema:write` scope. Operation `groups.setPermissions`. MCP tool `groups_setPermissions`. CLI, once published: `gtable groups set-permissions`.

## Path parameters

| Name      | Type   | Required | Description |
| --------- | ------ | -------- | ----------- |
| `appId`   | string | yes      |             |
| `groupId` | string | yes      |             |

## Headers

| Name              | Type   | Required | Description                                                                                                                                                                                                                                                        |
| ----------------- | ------ | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `Idempotency-Key` | string | no       | Any unique string. Sending the same key with the same request again returns the first response (marked `Idempotency-Replayed: true`) instead of running it twice. Reusing it for a different request is refused with 409. Kept for 24 hours. Up to 255 characters. |

## Request body

| Field          | Type           | Required | Description |
| -------------- | -------------- | -------- | ----------- |
| `tables`       | "\*" or object | yes      |             |
| `baseRevision` | string         | no       |             |
