Skip to content
openlaunch
Esc
↑↓navigate↵open⌘Jpreview

Set one principal's access policy

Full-policy replacement for one principal. mode selected keeps the legacy per-device grant list; mode all covers every device with opt-out excludedDevices and excludedFunctions. Only the workspace owner can grant role administrator or set delegatedFrom ancestry; delegated administrators may update operator policies for other principals and can never modify their own policy.

POST/v1/access-policies
Authorization
AuthorizationBearer token (Clerk owner session) · headerrequired

Owner identity required.

Request body
requiredapplication/json
principalstringrequired
min length 1 · max length 128 · matches ^\S+$
modestring
default: "all"
Allowed:allselected
excludedDevicesstring[]
max items 1000 · default: []
excludedFunctionsobject[]
max items 1000 · default: []
Show properties
Array of object
deviceIdstring | nullrequired
Show properties
Any of:
string
string
null
null
capabilitystringrequired
min length 1 · max length 64 · matches ^[a-z][a-z0-9_]*(?:\.[a-z][a-z0-9_]*)*$
rolestring
default: "operator"
Allowed:operatoradministrator
expiresAtinteger | null
default: null
Show properties
Any of:
integer
integer
null
null
delegatedFromstring
min length 1 · max length 128 · matches ^\S+$
Responses
200

Successful response

dataAccessPolicyrequired
Show properties
principalstringrequired
modestringrequired

selected keeps the legacy per-device grant list; all covers every workspace device with opt-out exclusions.

Allowed:allselected
excludedDevicesstring[]required
excludedFunctionsobject[]required
Show properties
Array of object
deviceIdstring | nullrequired
capabilitystringrequired
rolestringrequired
Allowed:operatoradministrator
expiresAtinteger | nullrequired
delegatedFromstring

Parent policy principal this policy was delegated from; a child is always intersected with the live parent chain, so delegated credentials can never escape parent exclusions, expiry or role changes.

400

Invalid request or validation failure

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
401

Missing or invalid credential

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
403

Insufficient access or grant

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
404

Resource not found

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
413

Request body exceeds the 16 KiB limit

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
429

Rate limit or workspace capacity limit

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
500

Internal error

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
503

Service or required integration is not configured

errorobjectrequired
Show properties
codestringrequired
messagestring
issuesobject[]
Show properties
Array of object
pathstring
messagestring
Try it
Server
Authorization
Bodyapplication/json
Request
curl -X POST 'https://www.openlaunch.dev/v1/access-policies' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "principal": "connection:00000000-0000-4000-8000-000000000001",
  "mode": "all",
  "excludedDevices": [],
  "excludedFunctions": [],
  "role": "operator",
  "expiresAt": null
}'
Response
{
  "data": {
    "principal": "string",
    "mode": "all",
    "excludedDevices": [
      "string"
    ],
    "excludedFunctions": [
      {
        "deviceId": "string",
        "capability": "string"
      }
    ],
    "role": "operator",
    "expiresAt": 0,
    "delegatedFrom": "string"
  }
}