API SpecificationPRIVATEApplications
Create Role
Creates a new role for an application. Roles can be assigned to users and scopes.
Required scopes: auth:roles:edit
Authorization
BearerAuth AuthorizationBearer <token>
JWT access token for internal API access. Requires 'private' scope for most endpoints, 'admin' scope for administrative operations.
In: header
Header Parameters
Connect-Protocol-Version*number
Define the version of the Connect protocol
Value in
1Connect-Timeout-Ms?number
Define the timeout, in ms
Request Body
application/json
applicationId?string
Length
1 <= length <= 64role?
[key: string]?never
Response Body
application/json
application/json
curl -X POST "https://auth.xeonr.io/xeonr.auth.private.v1.ApplicationsService/CreateRole" \ -H "Connect-Protocol-Version: 1" \ -H "Content-Type: application/json" \ -d '{}'{
"application": {
"applicationId": "app_prod_myapp",
"name": "My Application",
"slug": "my-application",
"websiteUrl": "https://myapp.example.com",
"createdAt": "2023-01-15T01:30:15.01Z",
"updatedAt": "2023-01-15T01:30:15.01Z",
"enabledIdps": [
"github",
"discord"
],
"scopes": [
{
"name": "read:users",
"description": "Read access to user data",
"isInternal": true,
"isSensitive": true,
"role": {
"name": "admin",
"iacManaged": true,
"roleType": "ROLE_TYPE_UNSPECIFIED",
"description": "string"
},
"isDelegatable": true,
"isServiceAccountOnly": true,
"isOrgOnly": true,
"iacManaged": true
}
],
"automaticEnrollment": true,
"audience": [
"https://api.example.com"
],
"roles": [
{
"name": "admin",
"iacManaged": true,
"roleType": "ROLE_TYPE_UNSPECIFIED",
"description": "string"
}
],
"supportsScopedRequests": true,
"applicationCustomConfig": {
"jsonSchema": {
"property1": {},
"property2": {}
},
"uiSchema": {
"property1": {},
"property2": {}
}
},
"public": true,
"resourceTypes": [
{
"type": "bucket",
"jsonSchema": {
"property1": {},
"property2": {}
},
"displayTitleField": "title",
"displayDescriptionField": "description",
"iacManaged": true
}
],
"validationCallbackUrl": "https://uploads.example.com/api/auth/validate",
"iacManaged": true,
"supportsTeams": true,
"automaticTeamBinding": true
}
}{
"code": "not_found",
"message": "string",
"details": [
{
"type": "string",
"value": "string",
"debug": {}
}
]
}Create Resource Type POST
Registers a new resource type for Rich Authorization Requests (RFC 9396). The type name will be used as {app_slug}:{type} in authorization_details. **Required scopes:** `auth:apps:edit`
Delete Application POST
Permanently deletes an application and all associated data including enrollments and scopes. **Required scopes:** `auth:apps:edit`