Set one principal's access policy
Full-policy replacement for one principal. mode selected keeps the legacy per-device grant list; mode all covers every device with opt-out excludedDevices and excludedFunctions. Only the workspace owner can grant role administrator or set delegatedFrom ancestry; delegated administrators may update operator policies for other principals and can never modify their own policy.
/v1/access-policiesAuthorizationBearer token (Clerk owner session) · headerrequiredOwner identity required.
application/jsonprincipalstringrequiredmodestringallselectedexcludedDevicesstring[]excludedFunctionsobject[]Show propertiesHide properties
objectdeviceIdstring | nullrequiredShow propertiesHide properties
stringnullcapabilitystringrequiredrolestringoperatoradministratorexpiresAtinteger | nullShow propertiesHide properties
integernulldelegatedFromstringSuccessful response
dataAccessPolicyrequiredShow propertiesHide properties
principalstringrequiredmodestringrequiredselected keeps the legacy per-device grant list; all covers every workspace device with opt-out exclusions.
allselectedexcludedDevicesstring[]requiredexcludedFunctionsobject[]requiredShow propertiesHide properties
objectdeviceIdstring | nullrequiredcapabilitystringrequiredrolestringrequiredoperatoradministratorexpiresAtinteger | nullrequireddelegatedFromstringParent policy principal this policy was delegated from; a child is always intersected with the live parent chain, so delegated credentials can never escape parent exclusions, expiry or role changes.
Invalid request or validation failure
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringMissing or invalid credential
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringInsufficient access or grant
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringResource not found
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringRequest body exceeds the 16 KiB limit
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringRate limit or workspace capacity limit
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringInternal error
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestringService or required integration is not configured
errorobjectrequiredShow propertiesHide properties
codestringrequiredmessagestringissuesobject[]Show propertiesHide properties
objectpathstringmessagestring