---
title: "PATCH /files/{fileId}/permissions/{permissionId}"
method: PATCH
path: "/files/{fileId}/permissions/{permissionId}"
tags: ["permissions"]
---

# PATCH /files/{fileId}/permissions/{permissionId}

`PATCH /files/{fileId}/permissions/{permissionId}`

Updates a permission with patch semantics. For more information, see [Share files, folders, and drives](https://developers.google.com/workspace/drive/api/guides/manage-sharing). **Warning:** Concurrent permissions operations on the same file aren't supported; only the last update is applied.

## Path parameters

- `fileId` string, required
- `permissionId` string, required

## Query parameters

- `enforceExpansiveAccess` boolean
- `removeExpiration` boolean
- `supportsAllDrives` boolean
- `supportsTeamDrives` boolean
- `transferOwnership` boolean
- `useDomainAdminAccess` boolean

## Request body

- Permission — A permission for a file. A permission grants a user, group, domain, or the world access to a file or a folder hierarchy. For more information, see [Share files, folders, and drives](https://developers.google.com/workspace/drive/api/guides/manage-sharing). By default, permission requests only return a subset of fields. Permission `kind`, `ID`, `type`, and `role` are always returned. To retrieve specific fields, see [Return specific fields](https://developers.google.com/workspace/drive/api/guides/fields-parameter). Some resource methods (such as `permissions.update`) require a `permissionId`. Use the `permissions.list` method to retrieve the ID for a file, folder, or shared drive.
  - `allowFileDiscovery` boolean — Whether the permission allows the file to be discovered through search. This is only applicable for permissions of type `domain` or `anyone`.
  - `displayName` string — Output only. The "pretty" name of the value of the permission. The following is a list of examples for each type of permission: * `user` - User's full name, as defined for their Google Account, such as "Dana A." * `group` - Name of the Google Group, such as "The Company Administrators." * `domain` - String domain name, such as "cymbalgroup.com." * `anyone` - No `displayName` is present.
  - `expirationTime` string, date-time — The time at which this permission will expire (RFC 3339 date-time). Expiration times have the following restrictions: - They can only be set on user and group permissions - The time must be in the future - The time cannot be more than a year in the future
  - `photoLink` string — Output only. A link to the user's profile photo, if available.
  - `inheritedPermissionsDisabled` boolean — When `true`, only organizers, owners, and users with permissions added directly on the item can access it.
  - `kind` string — Output only. Identifies what kind of resource this is. Value: the fixed string `"drive#permission"`.
  - `domain` string — Output only. The domain to which this permission refers.
  - `view` string — Indicates the view for this permission. Only populated for permissions that belong to a view. The only supported values are `published` and `metadata`: * `published`: The permission's role is `publishedReader`. * `metadata`: The item is only visible to the `metadata` view because the item has limited access and the scope has at least read access to the parent. The `metadata` view is only supported on folders. For more information, see [Views](https://developers.google.com/workspace/drive/api/guides/ref-roles#views).
  - `emailAddress` string — Output only. The email address of the user or group to which this permission refers.
  - `role` string — The role granted by this permission. Supported values include: * `owner` * `organizer` * `fileOrganizer` * `writer` * `commenter` * `reader` For more information, see [Roles and permissions](https://developers.google.com/workspace/drive/api/guides/ref-roles).
  - `deleted` boolean — Output only. Whether the account associated with this permission has been deleted. This field only pertains to permissions of type `user` or `group`.
  - `teamDrivePermissionDetails` object[] — Output only. Deprecated: Output only. Use `permissionDetails` instead.
    - `inheritedFrom` string — Deprecated: Output only. Use `permissionDetails/inheritedFrom` instead.
    - `inherited` boolean — Deprecated: Output only. Use `permissionDetails/inherited` instead.
    - `teamDrivePermissionType` string — Deprecated: Output only. Use `permissionDetails/permissionType` instead.
    - `role` string — Deprecated: Output only. Use `permissionDetails/role` instead.
  - `type` string — The type of the grantee. Supported values include: * `user` * `group` * `domain` * `anyone` When creating a permission, if `type` is `user` or `group`, you must provide an `emailAddress` for the user or group. If `type` is `domain`, you must provide a `domain`. If `type` is `anyone`, no extra information is required.
  - `pendingOwner` boolean — Whether the account associated with this permission is a pending owner. Only populated for permissions of type `user` for files that aren't in a shared drive.
  - `id` string — Output only. The ID of this permission. This is a unique identifier for the grantee, and is published in the [User resource](https://developers.google.com/workspace/drive/api/reference/rest/v3/User) as `permissionId`. IDs should be treated as opaque values.
  - `permissionDetails` object[] — Output only. Details of whether the permissions on this item are inherited or are directly on this item.
    - `inheritedFrom` string — Output only. The ID of the item from which this permission is inherited. This is only populated for items in shared drives.
    - `inherited` boolean — Output only. Whether this permission is inherited. This field is always populated. This is an output-only field.
    - `permissionType` string — Output only. The permission type for this user. Supported values include: * `file` * `member`
    - `role` string — Output only. The primary role for this user. Supported values include: * `owner` * `organizer` * `fileOrganizer` * `writer` * `commenter` * `reader` For more information, see [Roles and permissions](https://developers.google.com/workspace/drive/api/guides/ref-roles).

## Response `200`

Successful response

---

[API](https://skmtc.dev/google/apis/drive.md) · [All operations](https://skmtc.dev/google/apis/drive/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/google/drive/revisions/f3444ff3fae2/schema)
