curl --request PUT \
--url https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"changes": [
{
"key": "<string>"
}
]
}
'import requests
url = "https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions"
payload = { "changes": [{ "key": "<string>" }] }
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({changes: [{key: '<string>'}]})
};
fetch('https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'changes' => [
[
'key' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions"
payload := strings.NewReader("{\n \"changes\": [\n {\n \"key\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"changes\": [\n {\n \"key\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"changes\": [\n {\n \"key\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"set": {
"id": "<string>",
"name": "<string>",
"kind": "member_default",
"team": {
"id": "<string>",
"name": "<string>"
},
"allowedCount": 0,
"createdAt": "2023-11-07T05:31:56Z",
"archivedAt": "2023-11-07T05:31:56Z",
"permissions": [
{
"key": "<string>",
"status": "allow",
"locked": true,
"lastChangedAt": "2023-11-07T05:31:56Z",
"lastChangedBy": {
"memberId": "<string>",
"name": "<string>",
"email": "<string>"
},
"lastChangeSource": "user"
}
],
"appliesTo": {
"kind": "everyone",
"memberCount": 0
}
}
}{
"error": "invalid_request",
"details": [
{
"message": "<string>",
"path": [
"<string>"
]
}
],
"message": "<string>",
"capability": "<string>"
}{
"error": "unauthorized"
}{
"error": "forbidden",
"reason": "<string>",
"message": "<string>"
}{
"error": "organization_not_found",
"feature": "<string>",
"message": "<string>"
}{
"error": "permission_set_archived",
"message": "<string>",
"permissionSetId": "<string>"
}Change permissions in a set
Turns permissions on (allow) or off (deny) in one set. Only keys whose status actually changes are recorded; every change is kept in the set’s history. Only the owner and admins can change Admin permissions. Permissions locked on for admins can’t be turned off in Admin permissions, you can only turn on permissions you have yourself (except turning a permission back on in Member or Admin permissions where it is on by default), and archived sets can’t be changed. The linked team can’t be changed. Returns the set’s new state. Requires permissions.manage (only the owner has it by default), a recent sign-in, and the Permissions feature.
curl --request PUT \
--url https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"changes": [
{
"key": "<string>"
}
]
}
'import requests
url = "https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions"
payload = { "changes": [{ "key": "<string>" }] }
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({changes: [{key: '<string>'}]})
};
fetch('https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'changes' => [
[
'key' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions"
payload := strings.NewReader("{\n \"changes\": [\n {\n \"key\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"changes\": [\n {\n \"key\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.openworklabs.com/v1/permissions/sets/{permissionSetId}/permissions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"changes\": [\n {\n \"key\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"set": {
"id": "<string>",
"name": "<string>",
"kind": "member_default",
"team": {
"id": "<string>",
"name": "<string>"
},
"allowedCount": 0,
"createdAt": "2023-11-07T05:31:56Z",
"archivedAt": "2023-11-07T05:31:56Z",
"permissions": [
{
"key": "<string>",
"status": "allow",
"locked": true,
"lastChangedAt": "2023-11-07T05:31:56Z",
"lastChangedBy": {
"memberId": "<string>",
"name": "<string>",
"email": "<string>"
},
"lastChangeSource": "user"
}
],
"appliesTo": {
"kind": "everyone",
"memberCount": 0
}
}
}{
"error": "invalid_request",
"details": [
{
"message": "<string>",
"path": [
"<string>"
]
}
],
"message": "<string>",
"capability": "<string>"
}{
"error": "unauthorized"
}{
"error": "forbidden",
"reason": "<string>",
"message": "<string>"
}{
"error": "organization_not_found",
"feature": "<string>",
"message": "<string>"
}{
"error": "permission_set_archived",
"message": "<string>",
"permissionSetId": "<string>"
}Authorizations
Organization API key passed as the x-api-key header. The raw key is the header value; do not prefix it with Bearer.
Path Parameters
Den TypeID with 'pms_' prefix and a 26-character base32 suffix.
30Body
Requested status per key. Each key at most once. Keys already at the requested status are left unchanged.
1 - 500 elementsShow child attributes
Show child attributes
Response
Permissions updated; the set's current state is returned.
Show child attributes
Show child attributes
Was this page helpful?