Permission rules
Replace the whole permission document
Replaces every group and every permission at once.
PUT/v1/apps/{appId}/rules
This is the call for adding or removing a GROUP; to change what one group may do, prefer groups.setPermissions, which cannot touch the others by accident. Send the revision rules.get gave you as baseRevision, and a save made after somebody else changed the document is refused with 409 rather than erasing their change.
Requires the schema:write scope. Operation rules.set. MCP tool rules_set. CLI, once published: gtable rules set.
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
appId | string | yes |
Headers
| Name | Type | Required | Description |
|---|---|---|---|
Idempotency-Key | string | no | Any unique string. Sending the same key with the same request again returns the first response (marked Idempotency-Replayed: true) instead of running it twice. Reusing it for a different request is refused with 409. Kept for 24 hours. Up to 255 characters. |
Request body
| Field | Type | Required | Description |
|---|---|---|---|
version | 2 | yes | |
groups | object[] | yes | 1 to 100 items. |
permissions | object[] | yes | Up to 100 items. |
baseRevision | string | no |
Response
Success
dataobjectrequiredRefused
errorobjectrequired