---
title: "Add permission to role"
method: POST
path: "/api/roles/{role_id}/permissions"
tags: ["Permissions"]
---

# Add permission to role

`POST /api/roles/{role_id}/permissions`

Add a single permission to a role.

Same privileged-grant policy as the per-user paths (2026-08-13). Roles were
the last outright refusal to fall: the argument for keeping them absolute was
blast radius, and the answer is to SHOW the blast radius — the 409 names how
many people hold the role — rather than to refuse an operation Multigest staff
legitimately need.

## Path parameters

- `role_id` integer, required

## Headers

- `x-api-token` string, nullable

## Request body

- PermissionAssign
  - `permission_id` integer, required
  - `grant_privileged_role` boolean

## Response `200`

Successful Response

- unknown

## Other responses

- `422` — Validation Error

---

[API](https://skmtc.dev/multigest/apis/multigest-protected-api.md) · [All operations](https://skmtc.dev/multigest/apis/multigest-protected-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/multigest/multigest-protected-api/revisions/4b44eb76b3ee/schema)
