curl --request POST \
--url https://api.arize.com/v2/role-bindings \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"role_id": "Um9sZToxOmFCY0Q=",
"user_id": "VXNlcjo0MjphQmNE",
"resource_type": "SPACE",
"resource_id": "U3BhY2U6MTpWNEth"
}
'import requests
url = "https://api.arize.com/v2/role-bindings"
payload = {
"role_id": "Um9sZToxOmFCY0Q=",
"user_id": "VXNlcjo0MjphQmNE",
"resource_type": "SPACE",
"resource_id": "U3BhY2U6MTpWNEth"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
role_id: 'Um9sZToxOmFCY0Q=',
user_id: 'VXNlcjo0MjphQmNE',
resource_type: 'SPACE',
resource_id: 'U3BhY2U6MTpWNEth'
})
};
fetch('https://api.arize.com/v2/role-bindings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.arize.com/v2/role-bindings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'role_id' => 'Um9sZToxOmFCY0Q=',
'user_id' => 'VXNlcjo0MjphQmNE',
'resource_type' => 'SPACE',
'resource_id' => 'U3BhY2U6MTpWNEth'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.arize.com/v2/role-bindings"
payload := strings.NewReader("{\n \"role_id\": \"Um9sZToxOmFCY0Q=\",\n \"user_id\": \"VXNlcjo0MjphQmNE\",\n \"resource_type\": \"SPACE\",\n \"resource_id\": \"U3BhY2U6MTpWNEth\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.arize.com/v2/role-bindings")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"role_id\": \"Um9sZToxOmFCY0Q=\",\n \"user_id\": \"VXNlcjo0MjphQmNE\",\n \"resource_type\": \"SPACE\",\n \"resource_id\": \"U3BhY2U6MTpWNEth\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.arize.com/v2/role-bindings")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"role_id\": \"Um9sZToxOmFCY0Q=\",\n \"user_id\": \"VXNlcjo0MjphQmNE\",\n \"resource_type\": \"SPACE\",\n \"resource_id\": \"U3BhY2U6MTpWNEth\"\n}"
response = http.request(request)
puts response.read_body{
"id": "Um9sZUJpbmRpbmc6MTphQmNE",
"role_id": "Um9sZToxOmFCY0Q=",
"user_id": "VXNlcjo0MjphQmNE",
"resource_type": "SPACE",
"resource_id": "U3BhY2U6MTpWNEth",
"created_at": "2024-06-01T10:00:00Z",
"updated_at": "2024-06-01T10:00:00Z"
}{
"status": 400,
"title": "Invalid request parameters",
"detail": "The 'name' field is required and must be a non-empty string.",
"instance": "/resource",
"type": "https://arize.com/docs/ax/rest-reference/errors#invalid-request"
}{
"status": 401,
"title": "Authentication required",
"detail": "You must be authenticated to access this resource.",
"instance": "/resource",
"type": "https://arize.com/docs/ax/rest-reference/errors#authentication-required"
}{
"status": 403,
"title": "Access forbidden",
"detail": "You do not have permission to access this resource.",
"instance": "/resource/12345",
"type": "https://arize.com/docs/ax/rest-reference/errors#access-forbidden"
}{
"status": 404,
"title": "Resource not found",
"detail": "The requested resource with ID '12345' was not found.",
"instance": "/resource/12345",
"type": "https://arize.com/docs/ax/rest-reference/errors#resource-not-found"
}{
"status": 409,
"title": "Resource conflict",
"detail": "A resource with the given identifier already exists.",
"instance": "/resource",
"type": "https://arize.com/docs/ax/rest-reference/errors#resource-conflict"
}{
"status": 422,
"title": "Unprocessable Entity",
"detail": "One or more fields failed validation.",
"instance": "/resource/12345",
"type": "https://arize.com/docs/ax/rest-reference/errors#unprocessable-entity"
}{
"status": 429,
"title": "Rate limit exceeded",
"detail": "You have exceeded the allowed number of requests. Please try again later.",
"instance": "/resource",
"type": "https://arize.com/docs/ax/rest-reference/errors#rate-limit-exceeded"
}Create a role binding
Create a new role binding that assigns a role to a user on a resource.
Payload Requirements
role_id,user_id,resource_type, andresource_idare required.resource_typemust beSPACEorPROJECT.resource_idmust be a unique identifier for the selectedresource_type.- Only one binding per user and resource is allowed. If the target user
already has any binding on the resource, the request returns
409 Conflict. - System-managed fields (
id,created_at,updated_at) are returned by the server and are rejected on input.
Valid example
{
"role_id": "Um9sZToxOlY0S2E=",
"user_id": "VXNlcjoxOmxQZzI=",
"resource_type": "PROJECT",
"resource_id": "TW9kZWw6MTpGdmxM"
}
Invalid example
{
"role_id": "Um9sZToxOlY0S2E=",
"user_id": "VXNlcjoxOmxQZzI=",
"resource_type": "PROJECT",
"resource_id": "U3BhY2U6MTp1Rk4x"
}
This fails because resource_id must encode a PROJECT ID when
resource_type is PROJECT.
Authorization
Requires ROLE_BINDING_CREATE permission on the resource. This grants
administrator-level authority on the resource, including the ability
to assign any role visible in the account. If authorization fails, the
endpoint returns 403, including when the resource is nonexistent or
outside the caller’s account. If the target user or role is outside the
caller’s account, the endpoint returns 404 after store validation.
Use PATCH /v2/role-bindings/{binding_id} to change the assigned role
for an existing binding.
curl --request POST \
--url https://api.arize.com/v2/role-bindings \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"role_id": "Um9sZToxOmFCY0Q=",
"user_id": "VXNlcjo0MjphQmNE",
"resource_type": "SPACE",
"resource_id": "U3BhY2U6MTpWNEth"
}
'import requests
url = "https://api.arize.com/v2/role-bindings"
payload = {
"role_id": "Um9sZToxOmFCY0Q=",
"user_id": "VXNlcjo0MjphQmNE",
"resource_type": "SPACE",
"resource_id": "U3BhY2U6MTpWNEth"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
role_id: 'Um9sZToxOmFCY0Q=',
user_id: 'VXNlcjo0MjphQmNE',
resource_type: 'SPACE',
resource_id: 'U3BhY2U6MTpWNEth'
})
};
fetch('https://api.arize.com/v2/role-bindings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.arize.com/v2/role-bindings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'role_id' => 'Um9sZToxOmFCY0Q=',
'user_id' => 'VXNlcjo0MjphQmNE',
'resource_type' => 'SPACE',
'resource_id' => 'U3BhY2U6MTpWNEth'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.arize.com/v2/role-bindings"
payload := strings.NewReader("{\n \"role_id\": \"Um9sZToxOmFCY0Q=\",\n \"user_id\": \"VXNlcjo0MjphQmNE\",\n \"resource_type\": \"SPACE\",\n \"resource_id\": \"U3BhY2U6MTpWNEth\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.arize.com/v2/role-bindings")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"role_id\": \"Um9sZToxOmFCY0Q=\",\n \"user_id\": \"VXNlcjo0MjphQmNE\",\n \"resource_type\": \"SPACE\",\n \"resource_id\": \"U3BhY2U6MTpWNEth\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.arize.com/v2/role-bindings")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"role_id\": \"Um9sZToxOmFCY0Q=\",\n \"user_id\": \"VXNlcjo0MjphQmNE\",\n \"resource_type\": \"SPACE\",\n \"resource_id\": \"U3BhY2U6MTpWNEth\"\n}"
response = http.request(request)
puts response.read_body{
"id": "Um9sZUJpbmRpbmc6MTphQmNE",
"role_id": "Um9sZToxOmFCY0Q=",
"user_id": "VXNlcjo0MjphQmNE",
"resource_type": "SPACE",
"resource_id": "U3BhY2U6MTpWNEth",
"created_at": "2024-06-01T10:00:00Z",
"updated_at": "2024-06-01T10:00:00Z"
}{
"status": 400,
"title": "Invalid request parameters",
"detail": "The 'name' field is required and must be a non-empty string.",
"instance": "/resource",
"type": "https://arize.com/docs/ax/rest-reference/errors#invalid-request"
}{
"status": 401,
"title": "Authentication required",
"detail": "You must be authenticated to access this resource.",
"instance": "/resource",
"type": "https://arize.com/docs/ax/rest-reference/errors#authentication-required"
}{
"status": 403,
"title": "Access forbidden",
"detail": "You do not have permission to access this resource.",
"instance": "/resource/12345",
"type": "https://arize.com/docs/ax/rest-reference/errors#access-forbidden"
}{
"status": 404,
"title": "Resource not found",
"detail": "The requested resource with ID '12345' was not found.",
"instance": "/resource/12345",
"type": "https://arize.com/docs/ax/rest-reference/errors#resource-not-found"
}{
"status": 409,
"title": "Resource conflict",
"detail": "A resource with the given identifier already exists.",
"instance": "/resource",
"type": "https://arize.com/docs/ax/rest-reference/errors#resource-conflict"
}{
"status": 422,
"title": "Unprocessable Entity",
"detail": "One or more fields failed validation.",
"instance": "/resource/12345",
"type": "https://arize.com/docs/ax/rest-reference/errors#unprocessable-entity"
}{
"status": 429,
"title": "Rate limit exceeded",
"detail": "You have exceeded the allowed number of requests. Please try again later.",
"instance": "/resource",
"type": "https://arize.com/docs/ax/rest-reference/errors#rate-limit-exceeded"
}Authorizations
Most Arize AI endpoints require authentication. For those endpoints that require authentication, include your API key in the request header using the format
Body
Body containing role binding creation parameters.
A universally unique identifier (base64-encoded opaque string).
"RW50aXR5OjEyMzQ1"
A universally unique identifier (base64-encoded opaque string).
"RW50aXR5OjEyMzQ1"
Resource type for the binding. Only SPACE and PROJECT are supported for
single-binding CRUD. resource_id must encode the same resource type.
SPACE, PROJECT A universally unique identifier (base64-encoded opaque string).
"RW50aXR5OjEyMzQ1"
Response
A role binding object.
Unique identifier for the role binding.
A universally unique identifier (base64-encoded opaque string).
"RW50aXR5OjEyMzQ1"
A universally unique identifier (base64-encoded opaque string).
"RW50aXR5OjEyMzQ1"
Resource type for the binding. Only SPACE and PROJECT are supported for
single-binding CRUD. resource_id must encode the same resource type.
SPACE, PROJECT A universally unique identifier (base64-encoded opaque string).
"RW50aXR5OjEyMzQ1"
Timestamp when the binding was created.
Timestamp when the binding was last updated.
Was this page helpful?