> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.getunleash.io/api/create-role/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.getunleash.io/_mcp/server. # Create a new role POST https://app.unleash-instance.example.com/api/admin/roles Content-Type: application/json **Enterprise feature** Create a new custom role for Role-Based Access Control Reference: https://docs.getunleash.io/api/create-role ## Authentication - `Authorization` header (required) — API key needed to access this API - `Authorization` header (bearer token, required) — API key needed to access this API, in Bearer token format ## Request ### Body (application/json) This endpoint expects a createRoleWithPermissionsSchema. - `createRoleWithPermissionsSchema` ## Response ### 200 roleWithVersionSchema - `version` (integer, required) — The version of this schema - `roles` (roleSchema, required) — A single role ## Errors ### 400 Bad Request Error The request data does not match what we expect. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 401 Unauthorized Error Authorization information is missing or invalid. Provide a valid API token as the `authorization` header, e.g. `authorization:*.*.my-admin-token`. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 403 Forbidden Error The provided user credentials are valid, but the user does not have the necessary permissions to perform this operation - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 409 Conflict Error The provided resource can not be created or updated because it would conflict with the current state of the resource or with an already existing resource, respectively. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ## Types ### CreateRoleWithPermissionsSchema0 - `name` (string, required) — The name of the custom role - `description` (string, optional) — A more detailed description of the custom role and what use it's intended for - `type` (enum, optional) — [Custom root roles](https://docs.getunleash.io/concepts/rbac#custom-root-roles) (type=root-custom) are root roles with a custom set of permissions. [Custom project roles](https://docs.getunleash.io/concepts/rbac#custom-project-roles) (type=custom) contain a specific set of permissions for project resources. - Allowed values: `root-custom`, `custom` - `permissions` (list of CreateRoleWithPermissionsSchemaOneOf0PermissionsItems, optional) — A list of permissions assigned to this role ### CreateRoleWithPermissionsSchema1 - `name` (string, required) — The name of the custom role - `description` (string, optional) — A more detailed description of the custom role and what use it's intended for - `type` (enum, optional) — [Custom project roles](https://docs.getunleash.io/concepts/rbac#custom-project-roles) contain a specific set of permissions for project resources. - Allowed values: `custom` - `permissions` (list of CreateRoleWithPermissionsSchemaOneOf1PermissionsItems, optional) — A list of permissions assigned to this role ### roleSchema A role holds permissions to allow Unleash to decide what actions a role holder is allowed to perform - `id` (integer, required) — The role id - `type` (string, required) — A role can either be a global root role (applies to all projects) or a project role - `name` (string, required) — The name of the role - `description` (string, optional) — A more detailed description of the role and what use it's intended for - `project` (string, optional, nullable) — What project the role belongs to ### CreateRoleWithPermissionsSchemaOneOf0PermissionsItems - `name` (string, required) — The name of the permission - `environment` (string, optional, nullable) — The environments of the permission if the permission is environment specific ### CreateRoleWithPermissionsSchemaOneOf1PermissionsItems - `id` (double, required) — The id of the permission - `name` (string, optional) — The name of the permission - `environment` (string, optional, nullable) — The environments of the permission if the permission is environment specific ## Examples **Request** ```json { "name": "external-contributors" } ``` **Response** ```json { "version": 1, "roles": { "id": 9, "type": "root", "name": "Editor", "description": "Users with the editor role have access to most features in Unleash but can not manage users and roles in the global scope. Editors will be added as project owners when creating projects and get superuser rights within the context of these projects. Users with the editor role will also get access to most permissions on the default project by default.", "project": "default" } } ``` **SDK Code** ```python import requests url = "https://app.unleash-instance.example.com/api/admin/roles" payload = { "name": "external-contributors" } headers = { "Authorization": "", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://app.unleash-instance.example.com/api/admin/roles'; const options = { method: 'POST', headers: {Authorization: '', 'Content-Type': 'application/json'}, body: '{"name":"external-contributors"}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://app.unleash-instance.example.com/api/admin/roles" payload := strings.NewReader("{\n \"name\": \"external-contributors\"\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Authorization", "") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://app.unleash-instance.example.com/api/admin/roles") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = '' request["Content-Type"] = 'application/json' request.body = "{\n \"name\": \"external-contributors\"\n}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://app.unleash-instance.example.com/api/admin/roles") .header("Authorization", "") .header("Content-Type", "application/json") .body("{\n \"name\": \"external-contributors\"\n}") .asString(); ``` ```php request('POST', 'https://app.unleash-instance.example.com/api/admin/roles', [ 'body' => '{ "name": "external-contributors" }', 'headers' => [ 'Authorization' => '', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://app.unleash-instance.example.com/api/admin/roles"); var request = new RestRequest(Method.POST); request.AddHeader("Authorization", ""); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"name\": \"external-contributors\"\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "Authorization": "", "Content-Type": "application/json" ] let parameters = ["name": "external-contributors"] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://app.unleash-instance.example.com/api/admin/roles")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```