## Assign

**post** `/zones/{zoneId}/applications/{applicationId}/roles`

Assigns a role to the application. Provide exactly one of role_id or role_identifier; when role_identifier is used, owner_type is required to disambiguate roles that share an identifier across owner types (and must be omitted with role_id). An optional (scope_type, scope_id) pair scopes the grant; only platform roles on the org zone may carry a scope, and a `zone` scope must reference a different zone in the same organization.

### Path Parameters

- `zoneId: string`

- `applicationId: string`

### Body Parameters

- `owner_type: optional "platform" or "customer"`

  Owner type of the role to assign. Required with role_identifier (an identifier is unique only per owner type); must be omitted with role_id.

  - `"platform"`

  - `"customer"`

- `role_id: optional string`

  ID of the role to assign. Provide exactly one of role_id or role_identifier; owner_type must be omitted when role_id is used.

- `role_identifier: optional string`

  Role identifier: a lowercase slug (letters and digits separated by single hyphens or underscores), unique per owner type within a zone. Role identifiers surface in policy evaluation, so the slug restriction keeps them unambiguous in policy text.

- `scope_id: optional string`

  The ID of the resource to scope the grant to. Provide together with scope_type, or omit both for an unscoped assignment. When scope_type is `zone`, this must reference a different zone in the same organization.

- `scope_type: optional string`

  The kind of resource to scope the grant to (e.g. `zone`). Provide together with scope_id, or omit both for an unscoped assignment (applies to the owning zone itself). Only platform roles on the org zone may carry a scope.

### Returns

- `RoleAssignment = object { id, created_at, principal_id, 8 more }`

  Represents a role assigned to a principal within a zone

  - `id: string`

    Unique identifier of the role assignment

  - `created_at: string`

    Entity creation timestamp

  - `principal_id: string`

    ID of the principal the role is assigned to (a user, application, or group ID).

  - `principal_type: string`

    The kind of principal the role is assigned to: `user`, `application`, or `group`. A role assigned to a `group` is inherited by that group's members.

  - `role_id: string`

    ID of the assigned role

  - `role_identifier: string`

    Role identifier: a lowercase slug (letters and digits separated by single hyphens or underscores), unique per owner type within a zone. Role identifiers surface in policy evaluation, so the slug restriction keeps them unambiguous in policy text.

  - `role_owner_type: "platform" or "customer"`

    Owner type of the assigned role. Disambiguates roles that share an identifier across owner types.

    - `"platform"`

    - `"customer"`

  - `updated_at: string`

    Entity update timestamp

  - `zone_id: string`

    Zone this assignment belongs to

  - `scope_id: optional string`

    The ID of the scoped resource. Null when the assignment is unscoped.

  - `scope_type: optional string`

    The kind of resource this grant is scoped to (e.g. `zone`). Null when the assignment is unscoped (applies to the owning zone itself).

### Example

```http
curl https://api.keycard.ai/zones/$ZONE_ID/applications/$APPLICATION_ID/roles \
    -X POST \
    -H "Authorization: Bearer $KEYCARD_API_API_KEY"
```
