Skip to main content
PUT
Error
This path is deprecated and will be removed in the following major release. Use /api/governance/rbac/roles/{role_id} instead.
This endpoint is available in Bifrost Enterprise only.

Authorizations

Authorization
string
header
required

Management API authentication for /api/* endpoints. Use the Authorization header with Bearer <token>, where <token> is one of:

  • a Bifrost management API key,
  • a dashboard session token issued by POST /api/session/login,
  • base64 of <admin-username>:<admin-password> (legacy equivalent of BasicAuth).

Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs - the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.

Path Parameters

role_id
integer
required

Body

application/json

Partial update. Omitted fields preserve the current value.

  • description is a nullable string: omitting it preserves the existing description; sending an empty string clears it.
  • dac defaults to the existing value when omitted, preventing accidental scope escalation.
name
string

If supplied (and different from current), must match the role-name regex.

Maximum string length: 255
description
string | null
dac
enum<string>

Data access scope. Determines which rows members of the role can see.

  • own-data - Only rows the member personally owns.
  • team-data - Own rows plus rows owned by any team they belong to.
  • all-data - No row filtering.
Available options:
own-data,
team-data,
all-data

Response

Role updated

role
object