PermuteDocs
Go to Permute

Apps · appsGrantsSet

Set or revoke an app resource grant

Requires app admin permission and the shared target grant-management authority (target admin or the applicable workspace/organization admin). Supports resource-type wildcards, table grants, and expiry. Supply resourceType when resourceId is *. Cross-workspace targets are rejected. Set level to null to revoke the matching resource/type/table grant. Grants apply to every published revision immediately on subsequent authorization checks. Saving, publishing, and restoring revisions never recreate grants. These grants do not expose additional platform routes through app sessions.

PUT/v1/apps/{applicationId}/grants/{resourceId}
betaapiKeyworkspace

When to use

Approve or revoke an app’s resource or subsystem access.

For agents

Requires app admin and the shared target grant-management authority. Use level: null to revoke with app admin alone. Grants never give the user additional permissions or expose raw access to an action’s underlying sources. For all resources of a type, use resourceId * and an explicit resourceType, such as dataset. Optional subResourceId and expiresAt use the normal permission semantics. A grant does not expose additional app-session APIs. Existing apps require explicit grants before their data API calls can run.

Example

typescript
import { PermuteClient } from '@permute/sdk';

const orgClient = new PermuteClient({
  apiKey: process.env.PERMUTE_API_KEY!,
});

const client = orgClient.withWorkspace(process.env.PERMUTE_WORKSPACE_ID!);

const result = await client.apps.setGrant('appl_abcdefghijklmnopqrstuvwx', 'actn_abcdefghijklmnopqrstuvwx', {
  "level": "write"
});

Request body

json
{
  "level": "write"
}

Response

json
{
  "data": {
    "items": [
      {
        "resourceId": "actn_abcdefghijklmnopqrstuvwx",
        "resourceType": "businessAction",
        "level": "write",
        "expiresAt": null
      }
    ],
    "canManage": true
  }
}