Create a role binding
Create a new role binding that assigns a role to a user on a resource.
Payload Requirements
role_id,user_id,resource_type, andresource_idare required.resource_typemust beSPACEorPROJECT.resource_idmust be a unique identifier for the selectedresource_type.- Only one binding per user and resource is allowed. If the target user
already has any binding on the resource, the request returns
409 Conflict. - System-managed fields (
id,created_at,updated_at) are returned by the server and are rejected on input.
Valid example
{
"role_id": "Um9sZToxOlY0S2E=",
"user_id": "VXNlcjoxOmxQZzI=",
"resource_type": "PROJECT",
"resource_id": "TW9kZWw6MTpGdmxM"
}
Invalid example
{
"role_id": "Um9sZToxOlY0S2E=",
"user_id": "VXNlcjoxOmxQZzI=",
"resource_type": "PROJECT",
"resource_id": "U3BhY2U6MTp1Rk4x"
}
This fails because resource_id must encode a PROJECT ID when
resource_type is PROJECT.
Authorization
Requires ROLE_BINDING_CREATE permission on the resource. This grants
administrator-level authority on the resource, including the ability
to assign any role visible in the account. If authorization fails, the
endpoint returns 403, including when the resource is nonexistent or
outside the caller’s account. If the target user or role is outside the
caller’s account, the endpoint returns 404 after store validation.
Use PATCH /v2/role-bindings/{binding_id} to change the assigned role
for an existing binding.
Authorizations
Most Arize AI endpoints require authentication. For those endpoints that require authentication, include your API key in the request header using the format
Body
Body containing role binding creation parameters.
A universally unique identifier (base64-encoded opaque string).
"RW50aXR5OjEyMzQ1"
A universally unique identifier (base64-encoded opaque string).
"RW50aXR5OjEyMzQ1"
Resource type for the binding. Only SPACE and PROJECT are supported for
single-binding CRUD. resource_id must encode the same resource type.
SPACE, PROJECT A universally unique identifier (base64-encoded opaque string).
"RW50aXR5OjEyMzQ1"
Response
A role binding object.
Unique identifier for the role binding.
A universally unique identifier (base64-encoded opaque string).
"RW50aXR5OjEyMzQ1"
A universally unique identifier (base64-encoded opaque string).
"RW50aXR5OjEyMzQ1"
Resource type for the binding. Only SPACE and PROJECT are supported for
single-binding CRUD. resource_id must encode the same resource type.
SPACE, PROJECT A universally unique identifier (base64-encoded opaque string).
"RW50aXR5OjEyMzQ1"
Timestamp when the binding was created.
Timestamp when the binding was last updated.