Multi-Role Feature

Update collection permissions for a role

Update collection-specific permissions for a role in a project. Accepts: OrgBearerAuth (for admin users), ProjectBearerAuth (JWT for authenticated users), or ApiKeyAuth (X-API-Key for programmatic access). Both ProjectBearerAuth and ApiKeyAuth are fully implemented.

AuthBearer (JWT)
GroupMulti-Role Feature
Rate limitSee Rate Limits
PATCH/api/projects/{projectId}/multi-role/roles/{roleSlug}/collections/{collectionId}/permissions

SDK setup

Create a client and set credentials (JWT and/or API key) before calling the API. Match the authentication type shown above.

import { Configuration, MultiRoleFeatureApi } from 'mudbase-sdk';

const configuration = new Configuration({
  basePath: 'https://cloud.mudbase.dev',
  accessToken: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfbW9yZ2FuX2RlIiwiZW1haWwiOiJtb3JnYW4uY2hlbkBub3J0aHdpbmQuZGV2IiwiZXhwIjoxODI1MTI5NjAwfQ.doc_preview_sig',
});

const multirolefeature = new MultiRoleFeatureApi(configuration);
import { Configuration, MultiRoleFeatureApi } from 'mudbase-sdk';

const configuration = new Configuration({
  basePath: 'https://cloud.mudbase.dev',
  accessToken: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfbW9yZ2FuX2RlIiwiZW1haWwiOiJtb3JnYW4uY2hlbkBub3J0aHdpbmQuZGV2IiwiZXhwIjoxODI1MTI5NjAwfQ.doc_preview_sig',
});

const multirolefeature = new MultiRoleFeatureApi(configuration);

Example request

Call this endpoint using the client from SDK setup. Use View HTTP for a raw cURL example.

const { data: result } = await multirolefeature.updateCollectionPermissions(
  "proj_gTXkbFHiwTlV",
  "superb-coal-gilo",
  "T3U46afcxPnCIgaO",
  {
    actions: "alarm override",
    conditions: "port compress",
    dataScope: "application generate",
    ownerField: "capacitor navigate"
  }
);
const { data: result } = await multirolefeature.updateCollectionPermissions(
  "proj_gTXkbFHiwTlV",
  "superb-coal-gilo",
  "T3U46afcxPnCIgaO",
  {
    actions: "alarm override",
    conditions: "port compress",
    dataScope: "application generate",
    ownerField: "capacitor navigate"
  }
);

Playground

live

Test this endpoint with your own credentials. Your requests will be sent to the live API.

Use the auth endpoints to obtain a JWT.

No Request Yet

Send a request to see the full inspector

Authentication

Requires JWT
Note
Include your JWT in the Authorization: Bearer YOUR_TOKEN header (user-facing apps, RBAC). View authentication guide →

Path Parameters

NameTypeRequiredDescription
projectIdstringYes
roleSlugstringYesRole slug (e.g. starter `customer` or a role you added).
collectionIdstringYes

Request Body

json
{
  "actions": [
    "create",
    "read",
    "update",
    "delete"
  ],
  "conditions": {
    "status": "active"
  },
  "dataScope": "own",
  "ownerField": "firewall compress"
}
{
  "actions": [
    "create",
    "read",
    "update",
    "delete"
  ],
  "conditions": {
    "status": "active"
  },
  "dataScope": "own",
  "ownerField": "firewall compress"
}

Responses

200Collection permissions updated
json
{
  "success": true,
  "message": "Collection permissions updated",
  "data": {
    "slug": "customer",
    "name": "Customer",
    "description": "Default app user role. Edit name/slug and assign create/read/update/delete per collection after you add schemas.",
    "isEnabled": true,
    "isCustom": true,
    "signupEndpoint": "customer",
    "requiresApproval": false,
    "requiresPayment": false,
    "requiresKYC": false,
    "defaultPermissions": [],
    "collectionPermissions": [
      {
        "collectionId": "696ba6e4f4a9422ac4be4f74",
        "collectionSlug": "posts",
        "actions": [
          "create",
          "read",
          "update",
          "delete"
        ],
        "conditions": {
          "status": "active"
        }
      }
    ]
  }
}
{
  "success": true,
  "message": "Collection permissions updated",
  "data": {
    "slug": "customer",
    "name": "Customer",
    "description": "Default app user role. Edit name/slug and assign create/read/update/delete per collection after you add schemas.",
    "isEnabled": true,
    "isCustom": true,
    "signupEndpoint": "customer",
    "requiresApproval": false,
    "requiresPayment": false,
    "requiresKYC": false,
    "defaultPermissions": [],
    "collectionPermissions": [
      {
        "collectionId": "696ba6e4f4a9422ac4be4f74",
        "collectionSlug": "posts",
        "actions": [
          "create",
          "read",
          "update",
          "delete"
        ],
        "conditions": {
          "status": "active"
        }
      }
    ]
  }
}
Edit this page on GitHub