Skip to content
Roboto
Esc
↑↓navigate↵open⌘Jpreview

Edit view access

Grant or revoke access to a View.

Adding and removing are authorized separately, following edit_collection_access: a request doing both must satisfy both, and one doing neither is a no-op that needs neither.

Unlike edit_collection_access, the gate also depends on which relation is being changed. associated_group is not an ordinary grant — the org’s all-members group carries can_view_views, so adding or removing it is what makes a View org-visible or private, and that is reserved to the author. Every other editable relation stays on can_add_access / can_remove_access, which is what lets an editor hand out access, edit rights included, without also controlling who can see the View.

Gating the whole call on can_change_accessibility would not work: one request may mix an ordinary grant with a sharing change, and an editor has to keep being able to make the former. So the two are checked independently and a request needs whichever apply to it.

Authorizing here rather than in the service means a request that fails any of these checks writes nothing. generic_edit_access applies its adds before it validates the removes, so a partially-authorized request must not reach it.

Access control

  • Restricted tokens need the API scope api.everything_else
PUT/v1/views/id/{view_id}/access
Authorization
AuthorizationBearer token · headerrequired
Path parameters
view_idstringrequired
Header parameters
X-Roboto-Org-Idstring
X-Roboto-User-Idstring
Request body
requiredapplication/json
addAuthZTupleRecord[]
Show properties
Array of AuthZTupleRecord
userstringrequired
relationstringrequired
objstringrequired
removeAuthZTupleRecord[]
Show properties
Array of AuthZTupleRecord
userstringrequired
relationstringrequired
objstringrequired
Responses
200

OK

dataobjectrequired

Response payload for a request to describe fine-grained access to a Roboto resource

Show properties
relationsAuthZTupleRecord[]required
Show properties
Array of AuthZTupleRecord
userstringrequired
relationstringrequired
objstringrequired
group_permissionsobject
400

Thrown when the conversation context (messages, system prompt, tool results) exceeds the model's context window limit.

The token estimate and the model's context limit are not carried on the exception, so a caller cannot read usage numbers off it.

errorobject
Show properties
error_codenumber
messagestring
stack_tracestring | null
401

Thrown when authentication fails

errorobject
Show properties
error_codenumber
messagestring
stack_tracestring | null
403

Thrown if an operation would exceed a user or org level limit.

errorobject
Show properties
error_codenumber
messagestring
stack_tracestring | null
404

Thrown if a user is attempting to perform an action unrecognized by the Roboto platform.

errorobject
Show properties
error_codenumber
messagestring
stack_tracestring | null
409

Thrown if there is a conflict between a resource you're creating and another existing resource

errorobject
Show properties
error_codenumber
messagestring
stack_tracestring | null
410

Thrown if a resource is missing or expired.

errorobject
Show properties
error_codenumber
messagestring
stack_tracestring | null
500

An error the platform reported that this SDK release cannot resolve to a specific exception class.

Reported for an element of a :py:class:~roboto.http.BatchResponse whose error names a code this release defines no class for, or that arrived without a code, without a message, or as text that is not an error envelope at all. It carries whatever code and message the platform sent, so a caller handling the failure still learns what went wrong; when no message could be read, the message is the error's raw text.

The error envelope carries no status code, so http_status_code reports the 500 inherited from :py:class:RobotoDomainException rather than the status the failure actually had.

errorobject
Show properties
error_codenumber
messagestring
stack_tracestring | null
501

Thrown by shimmed out APIs which have not yet been implemented

errorobject
Show properties
error_codenumber
messagestring
stack_tracestring | null
503

Thrown when a service is unavailable, such as when it's under heavy load and can't accept new requests. This is expected to be transient and ought to be retried.

errorobject
Show properties
error_codenumber
messagestring
stack_tracestring | null
504

Thrown when the service times out while processing a request. This is exepcted to be transient and ought to be retried.

errorobject
Show properties
error_codenumber
messagestring
stack_tracestring | null
507

Thrown when the server cannot complete the request because the response payload exceeds a storage or transport capacity limit (e.g., Lambda response size). This is NOT expected to be transient and should NOT be retried.

errorobject
Show properties
error_codenumber
messagestring
stack_tracestring | null
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X PUT 'https://api.roboto.ai/v1/views/id/string/access' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "add": [
    {
      "user": "string",
      "relation": "string",
      "obj": "string"
    }
  ],
  "remove": [
    {
      "user": "string",
      "relation": "string",
      "obj": "string"
    }
  ]
}'
Response
{
  "data": {
    "relations": [
      {
        "user": "string",
        "relation": "string",
        "obj": "string"
      }
    ],
    "group_permissions": {
      "property1": [
        "string"
      ],
      "property2": [
        "string"
      ]
    }
  }
}