Change entity permissions

Use this request to grant or revoke direct permissions for a goal, project, or project portfolio.

PATCH

https://api.tracker.yandex.net/v3/entities/{entity_type}/{entity_ID}/permissions

Query format

Before making a request, get permission to access the API.

Pass the grant and revoke objects at the top level of the request body. The API adds or removes the specified permissions and preserves all other access settings.

PATCH /v3/entities/{entity_type}/{entity_ID}/permissions
Host: api.tracker.yandex.net
Authorization: OAuth API_TOKEN
Content-Type: application/json
X-Org-ID or X-Cloud-Org-ID: ORGANIZATION_ID

{
    "grant": {
        "READ": {
            "users": "username1"
        }
    },
    "revoke": {
        "GRANT": {
            "users": "username2"
        }
    }
}
Headers
  • Host: address of the node that provides the API.

  • Authorization: Authorization token about these formats:

    • OAuth OAUTH_TOKEN: For authorization using the OAuth 2.0 protocol. Learn more

    • Bearer IAM_TOKEN: For authorization using an IAM token, if a Yandex Identity Hub organization is linked to Tracker. Learn more

  • ID types

    X-Org-ID or X-Cloud-Org-ID: Organization ID.

    • Use the X-Org-ID header if a Tracker organization is linked to Yandex 360 for Business.

    • Use the X-Cloud-Org-ID header if a Tracker organization is linked to Yandex Identity Hub.

    Finding the ID

    To get the organization ID, go to Administration → Organizations and copy the value from the ID field.

Resource
Parameter Description Data type
entity_type Entity type:
  • project
  • portfolio
  • goal
String
entity_ID Entity ID. To get the ID, see the entity list. You can use the id or shortId parameter as the ID. String

You can use the id or shortId value for the {entity_ID} parameter.

Request body parameters
Parameter Description Data type
grant Permissions to grant Object
revoke Permissions to revoke Object

grant and revoke object fields

Parameter Description Data type
READ Users, groups, and roles to grant or revoke view access to the entity Object
GRANT Users, groups, and roles to grant or revoke access management permissions Object
WRITE Users, groups, and roles to grant or revoke edit access to the entity Object

READ, GRANT, and WRITE object fields

Parameter

Description

Data type

users

User IDs or usernames

String or array of strings

groups

Group IDs

Number or array of numbers

roles

Entity roles: AUTHOR, OWNER, CLIENT, FOLLOWER, MEMBER

String or array of strings

Don't pass the permissionSources parameter in the request body: the API returns a 400 error. To update inherited permissions, use the Change extended entity access settings request.

Response format

If the request is successful, the API returns a response with code 200 OK.

The API returns an object with the resulting access permissions. The READ, GRANT, and WRITE properties are at the top level. The response doesn't include acl, permissionSources, or parentEntities.

{
    "READ": {
        "users": [],
        "groups": [],
        "roles": []
    },
    "GRANT": {
        "users": [],
        "groups": [],
        "roles": ["AUTHOR", "OWNER"]
    },
    "WRITE": {
        "users": [],
        "groups": [],
        "roles": ["CLIENT", "AUTHOR", "FOLLOWER", "OWNER", "MEMBER"]
    }
}

If the request is processed incorrectly, the API returns a response with an error code:

400
One or more request parameters have an invalid value.
401
The user is not authorized. Make sure that actions described in the API access section are performed.
403
You are not authorized to perform this action. You can check what rights you have in the Tracker interface. The same rights are required to perform an action via the API and interface.
404
The requested object was not found. You may have specified an invalid object ID or key.