Error
A valid request URL is required to generate request examples{
"role": {
"id": 123,
"name": "<string>",
"description": "<string>",
"is_system_role": true,
"dac": "own-data",
"created_by_user_id": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>"
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>"
}
}RBAC
Update role (deprecated path)
deprecated
Partial update. Omitted fields preserve the current value.
Notable: omitting dac preserves the current scope (does not default to all-data).
PUT
/
api
/
roles
/
{role_id}
Error
A valid request URL is required to generate request examples{
"role": {
"id": 123,
"name": "<string>",
"description": "<string>",
"is_system_role": true,
"dac": "own-data",
"created_by_user_id": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>"
}
}{
"event_id": "<string>",
"type": "<string>",
"is_bifrost_error": true,
"status_code": 123,
"error": {
"type": "<string>",
"code": "<string>",
"message": "<string>",
"param": "<string>",
"event_id": "<string>"
},
"extra_fields": {
"provider": "anthropic",
"model_requested": "<string>",
"request_type": "<string>"
}
}This path is deprecated and will be removed in the following major release.
Use
/api/governance/rbac/roles/{role_id} instead.This endpoint is available in Bifrost Enterprise only.
Authorizations
ManagementBearerAuthBasicAuth
Management API authentication for /api/* endpoints. Use the Authorization header
with Bearer <token>, where <token> is one of:
- a Bifrost management API key,
- a dashboard session token issued by
POST /api/session/login, - base64 of
<admin-username>:<admin-password>(legacy equivalent ofBasicAuth).
Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs -
the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.
Path Parameters
Body
application/json
Partial update. Omitted fields preserve the current value.
descriptionis a nullable string: omitting it preserves the existing description; sending an empty string clears it.dacdefaults to the existing value when omitted, preventing accidental scope escalation.
If supplied (and different from current), must match the role-name regex.
Maximum string length:
255Data access scope. Determines which rows members of the role can see.
own-data- Only rows the member personally owns.team-data- Own rows plus rows owned by any team they belong to.all-data- No row filtering.
Available options:
own-data, team-data, all-data Response
Role updated
Show child attributes
Show child attributes
Was this page helpful?

