Set role permissions
Atomically replaces all permissions directly assigned to a role. An empty permissions array removes every permission from the role. Permissions that do not exist are created when the caller has permission to create them.
Required Permissions
Your root key must have:
rbac.*.add_permission_to_rolerbac.*.remove_permission_from_role
When any requested permission slug does not exist, it must also have:
rbac.*.create_permission
Authorizations
Unkey uses bearer tokens for authentication. Public integrations use root keys, while the dashboard proxy uses short-lived JWTs. To authenticate, include the token in the Authorization header of each request:
Root keys have specific permissions attached to them, controlling what operations they can perform. Legacy permissions use tuple strings like api.*.create_key; resource permissions use Unkey Resource Names plus actions, like unkey:v1:ws_123:keyspaces/*#create_key.
Security best practices:
- Keep root keys secure and never expose them in client-side code
- Use different root keys for different environments
- Rotate keys periodically, especially after team member departures
- Create keys with minimal necessary permissions following least privilege principle
- Monitor key usage with audit logs.
Body
The ID of the role whose directly assigned permissions will be replaced.
3 - 255^[a-zA-Z0-9_-]+$"proj_1234abcd"
The complete set of permission slugs to assign directly to the role. Missing permissions are created when authorized. An empty array clears all direct permissions.
1 - 128^[a-zA-Z0-9_:\-\.\*]+$Response
Permissions set successfully.
Metadata object included in every API response. This provides context about the request and is essential for debugging, audit trails, and support inquiries. The requestId is particularly important when troubleshooting issues with the Unkey support team.
Complete list of permissions now directly assigned to the role.