Version
POST

Create a role

/v1/roles in the Roles API.

curl -X POST https://api.subscriby.net/v1/roles \  -H "Authorization: Bearer $SUBSCRIBY_TOKEN" \  -H "Idempotency-Key: $(uuidgen)" \  -H "Content-Type: application/json" \  -d '{        "team_id": "a83f0d51-4c92-4b7e-8615-2fd9e70a3c86",        "code": "support-agent",        "name": "Support Agent",        "description": "Answers tickets, cannot touch billing",        "permissions": ["support-conversation:view-any", "support-conversation:update"]      }'

Choose the code deliberately. code is the stable identifier permissions are addressed by. It must be unique within the team and cannot be changed afterwards: renaming one would detach every assignment that referenced it. Only name, description and the permission set are mutable.

permissions accepts codes from the permission catalog in entity:action form. An unknown code is refused rather than silently dropped, so a typo fails loudly instead of creating a role that grants less than you think. Omit the field for a role that grants nothing yet.

Answers 201 with the role and emits role.created.

POST
/v1/roles

Requires ability

The token must hold this ability, or the call is refused with 403.

Fires one event

Delivered to every endpoint subscribed to it once the change is made.

MCP tool

Runs the same action from an agent, behind the same ability.

Idempotent

Send the header on every call; the same key replays the original response for 24 hours.

Authorization

bearerToken
AuthorizationBearer <token>

A personal access token minted on the dashboard under Settings, then Tokens, sent as Authorization: Bearer sbt_live_…. The token carries the abilities each endpoint lists under Requires ability and is frozen to one team.

In: header

Header Parameters

Idempotency-Key*string

A key unique to this operation, such as a fresh UUID. The same key replays the original 2xx response for 24 hours (with Idempotent-Replay: true), so a retry after a timeout never repeats the write; the same key with a different body is refused with 409.

Formatuuid

Request body

JSONWhat the request carries

A role's team, code, name, description and permissions. On create team_id, code and name are required; on update team_id and code are prohibited (a role is neither moved nor renamed by code) and every other field is optional.

Responses

201Created

The role resource as a 201.

400Bad request

Every write needs an Idempotency-Key header. Send a fresh UUID per distinct operation.

401Unauthorized

The request carries no bearer token, or one that is revoked, malformed, or minted for another environment (an sbt_test_ token on production).

403Forbidden

The token is valid but does not carry the ability this endpoint requires; error.context.required_ability names the one to grant. An endpoint that also checks who owns a row or which tier the account is on answers FORBIDDEN, TEAM_TIER_REQUIRED or CONNECTOR_TIER_REQUIRED with the same status, and says so in its own description. On this endpoint: TEAM_TIER_REQUIRED: below the Growth tier; nothing changes.

404Not found

When team_id is not one of the caller's teams.

409Conflict

The key was already used in the last 24 hours with a different request body.

422Validation failed

The payload broke a rule, and error.fields maps each offending key to its messages. A refusal from the domain, such as a plan that cannot go on sale or a member who cannot be removed, uses the same code with error.message saying why and no fields. On this endpoint: VALIDATION_FAILED: when a role with that code already exists in the team (error.context.code names it), or a permission code is unknown.

425Too early

The first request with this key is still running; retry in a few seconds and the original response is replayed.

429Too many requests

The token has spent its 300 requests a minute or 10,000 an hour; Retry-After says when the next one is accepted.

How is this guide?

Last updated on