curl --request POST \
--url https://{subdomain}.conveyour.com/api/roles \
--header 'Content-Type: application/json' \
--header 'x-conveyour-token: <api-key>' \
--data '
{
"name": "<string>",
"slug": "<string>",
"description": "<string>",
"permissions": [
"<string>"
],
"source_template": "<string>"
}
'const options = {
method: 'POST',
headers: {'x-conveyour-token': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
slug: '<string>',
description: '<string>',
permissions: ['<string>'],
source_template: '<string>'
})
};
fetch('https://{subdomain}.conveyour.com/api/roles', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const options = {
method: 'POST',
headers: {'x-conveyour-token': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
slug: '<string>',
description: '<string>',
permissions: ['<string>'],
source_template: '<string>'
})
};
fetch('https://{subdomain}.conveyour.com/api/roles', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{subdomain}.conveyour.com/api/roles"
payload = {
"name": "<string>",
"slug": "<string>",
"description": "<string>",
"permissions": ["<string>"],
"source_template": "<string>"
}
headers = {
"x-conveyour-token": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{subdomain}.conveyour.com/api/roles",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'slug' => '<string>',
'description' => '<string>',
'permissions' => [
'<string>'
],
'source_template' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-conveyour-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"status": "ok",
"message": "Role created",
"data": {
"id": "64a1b2c3d4e5f6a7b8c9d0e1",
"name": "Regional Manager",
"slug": "regional_manager",
"description": "Manages contacts and reports for a region.",
"permissions": [
"contacts",
"add_contacts",
"reports"
],
"type": "custom",
"is_editable": true
}
}{
"status": "failed",
"message": "Lacking necessary permission add_contacts",
"data": {
"permission": "add_contacts"
}
}Create a role
Creates a new custom role. Requires admin. Any permission keys that are not valid are silently dropped before saving. See Permission keys for the full list of valid values.
Create a custom role
Permission: Org admin only. Denials read Manage Roles.
Not callable with an API key. Requires an org admin. Service accounts cannot be assigned the admin role and their role cannot be changed, so every API key gets 403. Only a signed-in admin can call it.
curl --request POST \
--url https://{subdomain}.conveyour.com/api/roles \
--header 'Content-Type: application/json' \
--header 'x-conveyour-token: <api-key>' \
--data '
{
"name": "<string>",
"slug": "<string>",
"description": "<string>",
"permissions": [
"<string>"
],
"source_template": "<string>"
}
'const options = {
method: 'POST',
headers: {'x-conveyour-token': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
slug: '<string>',
description: '<string>',
permissions: ['<string>'],
source_template: '<string>'
})
};
fetch('https://{subdomain}.conveyour.com/api/roles', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));const options = {
method: 'POST',
headers: {'x-conveyour-token': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
slug: '<string>',
description: '<string>',
permissions: ['<string>'],
source_template: '<string>'
})
};
fetch('https://{subdomain}.conveyour.com/api/roles', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{subdomain}.conveyour.com/api/roles"
payload = {
"name": "<string>",
"slug": "<string>",
"description": "<string>",
"permissions": ["<string>"],
"source_template": "<string>"
}
headers = {
"x-conveyour-token": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{subdomain}.conveyour.com/api/roles",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'slug' => '<string>',
'description' => '<string>',
'permissions' => [
'<string>'
],
'source_template' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-conveyour-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"status": "ok",
"message": "Role created",
"data": {
"id": "64a1b2c3d4e5f6a7b8c9d0e1",
"name": "Regional Manager",
"slug": "regional_manager",
"description": "Manages contacts and reports for a region.",
"permissions": [
"contacts",
"add_contacts",
"reports"
],
"type": "custom",
"is_editable": true
}
}{
"status": "failed",
"message": "Lacking necessary permission add_contacts",
"data": {
"permission": "add_contacts"
}
}Authorizations
Your API key token. Contacts endpoints require a Server-only — Full API key — see Authentication.
Query Parameters
Team scope for the request, as one or more team ObjectIds. The brackets are required: PHP keeps only the last value for a repeated plain key, so teams=A&teams=B silently resolves to B alone. On requests with a JSON body you may send teams (no brackets) in the body instead.
Values that are not valid ObjectIds are silently ignored — a mistyped team ID behaves as if no team was sent. See the teams section of the API conventions guide.
Body
Human-readable name for the role. Must be unique within the org.
Machine-friendly identifier for the role. Must be unique within the org and in tag format (lowercase letters, numbers, and underscores).
A short description of what the role is for.
Array of permission keys granted by this role. Invalid keys are stripped. See Permission keys.
Slug of the system template this role was cloned from, if any.
Response
Success.
The common response envelope shared by all ConveYour endpoints.