Skip to content
Docs

Roles

Roles

List roles
GET/zones/{zoneId}/roles
Create role
POST/zones/{zoneId}/roles
Get role
GET/zones/{zoneId}/roles/{roleId}
Update role
PATCH/zones/{zoneId}/roles/{roleId}
Delete role
DELETE/zones/{zoneId}/roles/{roleId}
ModelsExpand Collapse
Role = object { id, created_at, identifier, 4 more }

A role that can be assigned to users within a zone.

id: string

Unique identifier of the role

created_at: string

Entity creation timestamp

formatdate-time
identifier: string

Role identifier: a lowercase slug (letters and digits separated by single hyphens or underscores), unique per owner type within a zone. Role identifiers surface in policy evaluation, so the slug restriction keeps them unambiguous in policy text.

minLength1
maxLength255
owner_type: "platform" or "customer"

Who owns this role. Platform-owned roles are managed by Keycard and cannot be modified or deleted via the API; customer-owned roles are user-created.

Accepts one of the following:
"platform"
"customer"
updated_at: string

Entity update timestamp

formatdate-time
zone_id: string

Zone this role belongs to

description: optional string

Human-readable description

maxLength1000
RoleCreate = object { identifier, description }

Schema for creating a new role

identifier: string

Role identifier: a lowercase slug (letters and digits separated by single hyphens or underscores), unique per owner type within a zone. Role identifiers surface in policy evaluation, so the slug restriction keeps them unambiguous in policy text.

minLength1
maxLength255
description: optional string

Human-readable description

maxLength1000
RoleUpdate = object { description }

Schema for updating an existing role. The role identifier is immutable.

description: optional string

Human-readable description (set to null to unset)

maxLength1000