Skip to main content
POST
SDK — define a customer role for a business account

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

environmentId
string
required

ID of the environment

Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

businessAccountId
string
required

ID of the business account

Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

Body

application/json

SDK defineRole body. A customer role always inherits a built-in one, which is what lets capability lookups and existing rules resolve through it.

role
string
required

Lowercase letters, numbers, hyphens and underscores.

inherits
enum<string>
required
Available options:
admin,
viewer
autoExecute
boolean
default:true

Whether the change applies the moment its quorum is met, or waits for an explicit execute. Read only on the first call, where it is stamped into the intent you sign; after that the signed intent is the authority. Defaults to true, because a change holding all its consent while waiting for a button press tends to be forgotten, and the deadline covers execution too.

intent
object

The initiator's proposal, signed with their session key. Built by the API, not the client — sign these exact bytes verbatim, because re-serializing can change them and invalidate the signature. autoExecute is inside the signed bytes, so an approver consents to it and nothing can flip it afterwards.

intentSignature
string

Response

Role defined; the new document version returned

The new version of the signed authorization document.

version
integer
required
Last modified on September 9, 2026