Changes who a permission grants to, what it allows, or the resources it covers.
Changes who a permission grants to, what it allows, or the resources it covers. Access changes as soon as the write lands.
PUT /v1/iam/permissions/{owner}/{name}
| Address | https://api.hanzo.ai/v1/iam/permissions/{owner}/{name} |
| Method | PUT |
| Operation | put_iam_permissions_by_owner_by_name |
| Auth | Authorization: Bearer $HANZO_API_KEY |
Changes who a permission grants to, what it allows, or the resources it covers. Access changes as soon as the write lands. What the permission is called does not change, and neither does when it was created.
Request
26 fields, body application/json (required).
| Field | In | Type | Required | Description |
|---|---|---|---|---|
owner | path | string | yes | Identity — the (owner, name) natural key. |
name | path | string | yes | |
actions | body | string[] | — | |
adapter | body | string | — | |
approveTime | body | string | — | |
approver | body | string | — | |
createdAt | body | string (date-time) | — | |
createdTime | body | string | — | Descriptive metadata. |
deleted | body | boolean | — | |
description | body | string | — | |
displayName | body | string | — | |
domains | body | string[] | — | |
effect | body | string | — | |
groups | body | string[] | — | |
id | body | string | — | |
isEnabled | body | boolean | — | |
model | body | string | — | Authorization model, targets, and decision. |
name | body | string | — | |
owner | body | string | — | Identity — the (owner, name) natural key. |
resourceType | body | string | — | |
resources | body | string[] | — | |
roles | body | string[] | — | |
state | body | string | — | |
submitter | body | string | — | Submission / approval workflow. |
updatedAt | body | string (date-time) | — | |
users | body | string[] | — | Subjects the grant is evaluated for. |
Response
| Status | Body | Meaning |
|---|---|---|
200 | iam.Permission | ok |
200 body — 24 fields.
| Field | In | Type | Always | Description |
|---|---|---|---|---|
actions | body | string[] | — | |
adapter | body | string | — | |
approveTime | body | string | — | |
approver | body | string | — | |
createdAt | body | string (date-time) | — | |
createdTime | body | string | — | Descriptive metadata. |
deleted | body | boolean | — | |
description | body | string | — | |
displayName | body | string | — | |
domains | body | string[] | — | |
effect | body | string | — | |
groups | body | string[] | — | |
id | body | string | — | |
isEnabled | body | boolean | — | |
model | body | string | — | Authorization model, targets, and decision. |
name | body | string | — | |
owner | body | string | — | Identity — the (owner, name) natural key. |
resourceType | body | string | — | |
resources | body | string[] | — | |
roles | body | string[] | — | |
state | body | string | — | |
submitter | body | string | — | Submission / approval workflow. |
updatedAt | body | string (date-time) | — | |
users | body | string[] | — | Subjects the grant is evaluated for. |
Failure carries the platform error shape — see Errors.
Examples
hanzo has no subcommand for this operation — the CLI serves only what cloud's live route table confirms. Use HTTP or an SDK.
import { Configuration, IamApi } from 'hanzoai';
const api = new IamApi(new Configuration({ accessToken: process.env.HANZO_API_KEY }));
const { data } = await api.putIamPermissionsByOwnerByName({ owner: 'owner', name: 'name', actions: ["<actions>"], adapter: "<adapter>" });from hanzoai.cloud import ApiClient, Configuration
from hanzoai.cloud.api import IamApi
client = ApiClient(Configuration(access_token=os.environ["HANZO_API_KEY"]))
result = IamApi(client).put_iam_permissions_by_owner_by_name(owner='owner', name='name', actions=["<actions>"], adapter="<adapter>")cfg := cloud.NewConfiguration()
cfg.AddDefaultHeader("Authorization", "Bearer "+os.Getenv("HANZO_API_KEY"))
client := cloud.NewAPIClient(cfg)
resp, _, err := client.IamAPI.PutIamPermissionsByOwnerByName(context.Background()).Execute()
if err != nil {
return err
}use hanzo_cloud::apis::{configuration::Configuration, iam_api};
let mut cfg = Configuration::new();
cfg.bearer_access_token = std::env::var("HANZO_API_KEY").ok();
let result = iam_api::put_iam_permissions_by_owner_by_name(&cfg, Default::default()).await?;import ai.hanzo.cloud.ApiClient;
import ai.hanzo.cloud.api.IamApi;
ApiClient client = new ApiClient();
client.setRequestInterceptor(b -> b.header("Authorization", "Bearer " + System.getenv("HANZO_API_KEY")));
var result = new IamApi(client).putIamPermissionsByOwnerByName();The method above is the one at the current release of the document. [email protected] (npm) and [email protected] (PyPI) were generated from an earlier release, where this operation carried a different id, so it spells the method differently — regenerating the clients is what makes the two agree. SDKs →
curl -X PUT https://api.hanzo.ai/v1/iam/permissions/<owner>/<name> \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"actions": [
"<actions>"
],
"adapter": "<adapter>"
}'The door reaches iam through the iam tool, which names its 75 operations with its own verbs — this one among them, under a name only the door declares. describe explains any of them:
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "describe",
"arguments": {
"op": "list__well_known_jwks"
}
}
}'How is this guide?