Skip to main content

Permissions

Preview and change a role's permissions and manage the inheritance rules, with an admin session.

Permission checking and inheritance rule management

Preview impact of a permission change on a role

POST/api/permissions/admin/servers/{serverId}/roles/{roleId}/impact

Read-only endpoint that returns how many members would be affected by adding or removing permissions from a role. Does not modify any data.

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
serverIdpathstringyesDiscord guild snowflake ID
roleIdpathstringyesDiscord role snowflake ID

Request body (JSON, required): ImpactPreviewDto schema.

Responses

StatusDescriptionBody
200Impact preview returned.ImpactPreviewResponseDto
400Invalid request body.
401Authentication required.
403System Admin access required.

Open in Swagger (opens in a new tab)

Get all permissions assigned to a role

GET/api/permissions/admin/servers/{serverId}/roles/{roleId}/permissions

Returns the list of permissions currently assigned to a specific role in a server.

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
serverIdpathstringyesDiscord guild snowflake ID
roleIdpathstringyesDiscord role snowflake ID

Responses

StatusDescriptionBody
200Role permissions list returned.RolePermissionsResponseDto
400Invalid path parameter format.
401Authentication required.
403System Admin access required.

Open in Swagger (opens in a new tab)

Add permissions to a role

POST/api/permissions/admin/servers/{serverId}/roles/{roleId}/permissions

Assigns one or more permissions to a role. Cache is invalidated immediately after the change.

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
serverIdpathstringyesDiscord guild snowflake ID
roleIdpathstringyesDiscord role snowflake ID

Request body (JSON, required): AssignPermissionsDto schema.

Responses

StatusDescriptionBody
200Updated role permissions list returned.RolePermissionsResponseDto
400Invalid request body.
401Authentication required.
403System Admin access required.

Open in Swagger (opens in a new tab)

Remove a permission from a role

DELETE/api/permissions/admin/servers/{serverId}/roles/{roleId}/permissions/{permissionId}

Removes a single permission from a role. Executive roles (global or highest-ranking) are protected from modification. Cache is invalidated immediately after the change.

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
serverIdpathstringyesDiscord guild snowflake ID
roleIdpathstringyesDiscord role snowflake ID
permissionIdpathstringyesPermission ID to remove

Responses

StatusDescriptionBody
200Permission removed successfully.
204
400Invalid path parameter format.
401Authentication required.
403System Admin access required, or role is protected from modification.

Open in Swagger (opens in a new tab)

List inheritance rules

GET/api/permissions/inheritance-rules

Returns all configured role inheritance rules.

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
sourceRoleIdquerystringnoFilter by source role ID.
enabledquerybooleannoFilter by enabled status.
targetScopequery"all" or "selected"noFilter by target scope type.
serverIdquerystringnoFilter rules that apply to this server (scope=all always matches; scope=selected matches when this server is among targetServerIds).

Responses

StatusDescriptionBody
200Inheritance rules list returned.
400Invalid parameter format.
401Authentication required.
403System Admin access required.

Open in Swagger (opens in a new tab)

Create or update an inheritance rule

POST/api/permissions/inheritance-rules

Upserts a permission inheritance rule that causes members holding a source role to also receive all permissions of a target role, optionally scoped to a specific server.

Authentication: Admin session token (Authorization: Bearer <token>)

Request body (JSON, required): UpsertInheritanceRuleDto schema.

Responses

StatusDescriptionBody
200Inheritance rule upsert result returned.
400Invalid request body.
401Authentication required.
403System Admin access required.

Open in Swagger (opens in a new tab)

Schemas

AssignPermissionsDto schema

FieldTypeRequiredDescription
permissionIdsarray of numberyesArray of permission IDs to assign to the role

ImpactPreviewDto schema

FieldTypeRequiredDescription
action"add" or "remove"yesWhether to preview adding or removing the permissions
permissionIdsarray of numberyesArray of permission IDs to preview impact for

ImpactPreviewResponseDto schema

FieldTypeRequiredDescription
affectedMembersnumberyesNumber of members affected by the change
memberIdsarray of stringyesDiscord IDs of affected members
roleHoldersnumberyesTotal number of members holding this role

PermissionItemDto schema

FieldTypeRequiredDescription
descriptionstringnoPermission description
idnumberyesPermission ID
keystringyesPermission key

RolePermissionsResponseDto schema

FieldTypeRequiredDescription
permissionsarray of PermissionItemDtoyes
roleIdstringyesDiscord role ID
roleNamestringyesRole name
serverIdstringyesServer ID

UpsertInheritanceRuleDto schema

FieldTypeRequiredDescription
enabledbooleannoDefault: true.
sourceRoleIdstringyesRole ID from main server
targetScope"all" or "selected"yes
targetServerIdsarray of stringnoRequired when targetScope = selected

Source: apps/api/openapi.json.