PermuteDocs
Go to Permute

Apps · appsAccessSet

Set app access settings

Requires app admin permission and the current access version. Permute sign-in uses existing user permissions and app grants. Password mode serves published frontend files only; all hosted queries and actions are denied. Passwords are hashed, never returned or versioned. Changes take effect immediately and invalidate existing sessions without publishing app content. A password must be supplied whenever password mode is saved; switching to Permute sign-in clears it.

PUT/v1/apps/{applicationId}/access
betaapiKeyworkspace

When to use

Choose Permute sign-in or a shared-password demo, or rotate the demo password.

For agents

Requires app admin. Password demos expose published frontend files, including older releases, to anyone with the password. Use mocked data only; hosted queries and Business Actions are blocked. Changes invalidate sessions immediately. Read the current version before saving; never retry a conflict without reviewing the changed settings.

Example

typescript
import { PermuteClient } from '@permute/sdk';

const orgClient = new PermuteClient({
  apiKey: process.env.PERMUTE_API_KEY!,
});

const client = orgClient.withWorkspace(process.env.PERMUTE_WORKSPACE_ID!);

const result = await client.apps.setAccess('appl_abcdefghijklmnopqrstuvwx', {
  "mode": "password",
  "password": "example-demo-password",
  "expectedVersion": 0
});

Request body

json
{
  "mode": "password",
  "password": "example-demo-password",
  "expectedVersion": 0
}

Response

json
{
  "data": {
    "mode": "password",
    "version": 1,
    "canManage": true
  }
}