---
metadata:
  - name: generator
    content: Diplodoc Platform v5.62.0
  - property: og:type
    content: article
  - property: article:section
    content: API reference
  - property: og:title
    content: Change entity permissions
  - property: article:tag
    content: Technical reference
alternate:
  - https://yandex.ru/support/tracker/en/api/entities/patch-permissions.md
  - https://yandex.ru/support/tracker/ru/api/entities/patch-permissions.md
  - href: https://yandex.ru/support/tracker/en/api/entities/patch-permissions.md
    type: text/markdown
    title: Markdown version
  - href: https://yandex.ru/support/tracker/en/llms.txt
    rel: describedby
---
> **Documentation Index:** Fetch the complete configuration index at https://yandex.ru/support/tracker/en/llms.txt


# Change entity permissions

Use this request to grant or revoke direct permissions for a [goal](https://yandex.ru/support/tracker/en/goals/goals-start.md), [project](https://yandex.ru/support/tracker/en/manager/project-new.md), or [project portfolio](https://yandex.ru/support/tracker/en/manager/portfolio.md).

<div class="request_example yfm-code-floating-container method_patch">
    <p>PATCH</p>
    <pre><code>https://api.tracker.yandex.net/v3/entities/{entity_type}/{entity_ID}/permissions</code></pre>
    <button class="yfm-clipboard-button"><svg width="16" height="16" viewBox="0 0 24 24" class="yfm-clipboard-icon" data-animation="15">
    <path fill="currentColor" d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path>
    <path stroke="currentColor" fill="transparent" strokewidth="1.5" d="M9.5 13l3 3l5 -5" visibility="hidden">
        <animate id="visibileAnimation-15" attributeName="visibility" from="hidden" to="visible" dur="0.2s" fill="freeze" begin=""></animate>
        <animate id="hideAnimation-15" attributeName="visibility" from="visible" to="hidden" dur="1s" begin="visibileAnimation-15.end+1" fill="freeze"></animate>
    </path>
</svg>
</button>
</div>

<!-- source: en/api/_assets/style/methods.md -->

<!-- endsource: en/api/_assets/style/methods.md -->

## Query format {#query}

Before making a request, [get permission to access the API](https://yandex.ru/support/tracker/en/api/access.md).

Pass the `grant` and `revoke` objects at the top level of the request body. The API adds or removes the specified permissions and preserves all other access settings.

```json translate=no
PATCH /v3/entities/{entity_type}/{entity_ID}/permissions
Host: api.tracker.yandex.net
Authorization: OAuth API_TOKEN
Content-Type: application/json
X-Org-ID or X-Cloud-Org-ID: ORGANIZATION_ID

{
    "grant": {
        "READ": {
            "users": "username1"
        }
    },
    "revoke": {
        "GRANT": {
            "users": "username2"
        }
    }
}
```

<!-- source: en/api/_includes/headings.md -->
{% cut "Headers" %}

* `Host`: address of the node that provides the API.

* <!-- source: en/api/_includes/authorization.md -->
  `Authorization`: Authorization token about these formats:

    - `OAuth OAUTH_TOKEN`: For authorization using the OAuth 2.0 protocol. [Learn more](https://yandex.ru/support/tracker/en/api/access.md#about_OAuth)

    - `Bearer IAM_TOKEN`: For authorization using an IAM token, if a Yandex Identity Hub organization is linked to Tracker. [Learn more](https://yandex.ru/support/tracker/en/api/access.md#iam-token)
  <!-- endsource: en/api/_includes/authorization.md -->


* <!-- source: en/api/_includes/org-id.md -->
  # ID types {#types}


  `X-Org-ID` or `X-Cloud-Org-ID`: Organization ID.

  - Use the `X-Org-ID` header if a Tracker organization is linked to Yandex 360 for Business.

  - Use the `X-Cloud-Org-ID` header if a Tracker organization is linked to Yandex Identity Hub.


  # Finding the ID {#find-id}


  To get the organization ID, go to **Administration** → [**Organizations**](https://tracker.yandex.com/admin/orgs) and copy the value from the **ID** field.
  <!-- endsource: en/api/_includes/org-id.md -->


{% endcut %}
<!-- endsource: en/api/_includes/headings.md -->

<!-- source: en/api/_includes/resource-entity.md -->
{% cut "Resource" %}

| Parameter | Description | Data type |
-------- | -------- | ----------
| `entity_type` | Entity type:<ul><li>project</li><li>portfolio</li><li>goal</li></ul> | String |
| `entity_ID` | Entity ID. To get the ID, see the [entity list](search-entities.md). You can use the `id` or `shortId` parameter as the ID. | String |

{% endcut %}
<!-- endsource: en/api/_includes/resource-entity.md -->

You can use the `id` or `shortId` value for the `{entity_ID}` parameter.

{% cut "Request body parameters" %}

<!-- source: en/api/_includes/entity-permissions.md -->
| Parameter | Description | Data type |
| -------- | -------- | ---------- |
| [grant](#read-grant-write-request) | Permissions to grant | Object |
| [revoke](#read-grant-write-request) | Permissions to revoke | Object |
<!-- endsource: en/api/_includes/entity-permissions.md -->

`grant` and `revoke` **object fields** {#read-grant-write-request}

<!-- source: en/api/_includes/entity-permissions.md -->
| Parameter | Description | Data type |
| -------- | -------- | ---------- |
| [READ](#principals) | Users, groups, and roles to grant or revoke view access to the entity | Object |
| [GRANT](#principals) | Users, groups, and roles to grant or revoke access management permissions | Object |
| [WRITE](#principals) | Users, groups, and roles to grant or revoke edit access to the entity | Object |
<!-- endsource: en/api/_includes/entity-permissions.md -->

`READ`, `GRANT`, and `WRITE` **object fields** {#principals}

<!-- source: en/api/_includes/entity-permissions.md -->
#|
|| Parameter | Description | Data type ||
|| users | User IDs or usernames | String or array of strings ||
|| groups | Group IDs | Number or array of numbers ||
|| roles | Entity roles: `AUTHOR`, `OWNER`, `CLIENT`, `FOLLOWER`, `MEMBER` | String or array of strings ||
|#
<!-- endsource: en/api/_includes/entity-permissions.md -->

{% endcut %}

{% note warning "" %}

Don't pass the `permissionSources` parameter in the request body: the API returns a `400` error. To update inherited permissions, use the [Change extended entity access settings](https://yandex.ru/support/tracker/en/api/entities/patch-access.md) request.

{% endnote %}

## Response format {#answer}

{% list tabs %}

- Request executed successfully

   <!-- source: en/api/_includes/answer-200.md -->
   If the request is successful, the API returns a response with code `200 OK`.
   <!-- endsource: en/api/_includes/answer-200.md -->

   The API returns an object with the resulting access permissions. The `READ`, `GRANT`, and `WRITE` properties are at the top level. The response doesn't include `acl`, `permissionSources`, or `parentEntities`.

   <!-- source: en/api/_includes/entity-permissions.md -->
   ```json translate=no
   {
       "READ": {
           "users": [],
           "groups": [],
           "roles": []
       },
       "GRANT": {
           "users": [],
           "groups": [],
           "roles": ["AUTHOR", "OWNER"]
       },
       "WRITE": {
           "users": [],
           "groups": [],
           "roles": ["CLIENT", "AUTHOR", "FOLLOWER", "OWNER", "MEMBER"]
       }
   }
   ```
   <!-- endsource: en/api/_includes/entity-permissions.md -->

- Request failed

   If the request is processed incorrectly, the API returns a response with an error code:

   <!-- source: en/api/_includes/answer-error-400.md -->
   400
   :   One or more request parameters have an invalid value.
   <!-- endsource: en/api/_includes/answer-error-400.md -->

   <!-- source: en/api/_includes/answer-error-401.md -->
   401
   :   The user is not authorized. Make sure that actions described in the [API access](https://yandex.ru/support/tracker/en/api/access.md) section are performed.
   <!-- endsource: en/api/_includes/answer-error-401.md -->

   <!-- source: en/api/_includes/answer-error-403.md -->
   403
   :   You are not authorized to perform this action. You can check what rights you have in the Tracker interface. The same rights are required to perform an action via the API and interface.
   <!-- endsource: en/api/_includes/answer-error-403.md -->

   <!-- source: en/api/_includes/answer-error-404.md -->
   404
   :   The requested object was not found. You may have specified an invalid object ID or key.
   <!-- endsource: en/api/_includes/answer-error-404.md -->

{% endlist %}
