Braintrust Roles API

The Roles API from Braintrust — 2 operation(s) for roles.

OpenAPI Specification

braintrust-roles-api-openapi.yml Raw ↑
openapi: 3.1.1
info:
  version: 1.0.0
  title: Braintrust Acls Roles API
  description: 'API specification for the backend data server. The API is hosted globally at

    https://api.braintrust.dev or in your own environment.


    You can access the OpenAPI spec for this API at https://github.com/braintrustdata/braintrust-openapi.'
  license:
    name: Apache 2.0
servers:
- url: https://api.braintrust.dev
security:
- bearerAuth: []
- {}
tags:
- name: Roles
paths:
  /v1/role:
    post:
      tags:
      - Roles
      security:
      - bearerAuth: []
      - {}
      operationId: postRole
      description: Create a new role. If there is an existing role with the same name as the one specified in the request, will return the existing role unmodified
      summary: Create role
      requestBody:
        description: Any desired information about the new role object
        required: false
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateRole'
      responses:
        '200':
          description: Returns the new role object
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Role'
        '400':
          description: The request was unacceptable, often due to missing a required parameter
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '401':
          description: No valid API key provided
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '403':
          description: The API key doesn’t have permissions to perform the request
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '429':
          description: Too many requests hit the API too quickly. We recommend an exponential backoff of your requests
          headers:
            Retry-After:
              schema:
                type: string
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '500':
          description: Something went wrong on Braintrust's end. (These are rare.)
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
    put:
      tags:
      - Roles
      security:
      - bearerAuth: []
      - {}
      operationId: putRole
      description: Create or replace role. If there is an existing role with the same name as the one specified in the request, will replace the existing role with the provided fields
      summary: Create or replace role
      requestBody:
        description: Any desired information about the new role object
        required: false
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateRole'
      responses:
        '200':
          description: Returns the new role object
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Role'
        '400':
          description: The request was unacceptable, often due to missing a required parameter
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '401':
          description: No valid API key provided
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '403':
          description: The API key doesn’t have permissions to perform the request
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '429':
          description: Too many requests hit the API too quickly. We recommend an exponential backoff of your requests
          headers:
            Retry-After:
              schema:
                type: string
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '500':
          description: Something went wrong on Braintrust's end. (These are rare.)
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
    get:
      operationId: getRole
      tags:
      - Roles
      description: List out all roles. The roles are sorted by creation date, with the most recently-created roles coming first
      summary: List roles
      security:
      - bearerAuth: []
      - {}
      parameters:
      - $ref: '#/components/parameters/AppLimitParam'
      - $ref: '#/components/parameters/StartingAfter'
      - $ref: '#/components/parameters/EndingBefore'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/RoleName'
      - $ref: '#/components/parameters/OrgName'
      responses:
        '200':
          description: Returns a list of role objects
          content:
            application/json:
              schema:
                type: object
                properties:
                  objects:
                    type: array
                    items:
                      $ref: '#/components/schemas/Role'
                    description: A list of role objects
                required:
                - objects
                additionalProperties: false
        '400':
          description: The request was unacceptable, often due to missing a required parameter
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '401':
          description: No valid API key provided
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '403':
          description: The API key doesn’t have permissions to perform the request
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '429':
          description: Too many requests hit the API too quickly. We recommend an exponential backoff of your requests
          headers:
            Retry-After:
              schema:
                type: string
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '500':
          description: Something went wrong on Braintrust's end. (These are rare.)
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
  /v1/role/{role_id}:
    get:
      operationId: getRoleId
      tags:
      - Roles
      description: Get a role object by its id
      summary: Get role
      security:
      - bearerAuth: []
      - {}
      parameters:
      - $ref: '#/components/parameters/RoleIdParam'
      responses:
        '200':
          description: Returns the role object
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Role'
        '400':
          description: The request was unacceptable, often due to missing a required parameter
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '401':
          description: No valid API key provided
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '403':
          description: The API key doesn’t have permissions to perform the request
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '429':
          description: Too many requests hit the API too quickly. We recommend an exponential backoff of your requests
          headers:
            Retry-After:
              schema:
                type: string
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '500':
          description: Something went wrong on Braintrust's end. (These are rare.)
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
    patch:
      operationId: patchRoleId
      tags:
      - Roles
      description: Partially update a role object. Specify the fields to update in the payload. Any object-type fields will be deep-merged with existing content. Currently we do not support removing fields or setting them to null.
      summary: Partially update role
      security:
      - bearerAuth: []
      - {}
      parameters:
      - $ref: '#/components/parameters/RoleIdParam'
      requestBody:
        description: Fields to update
        required: false
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PatchRole'
      responses:
        '200':
          description: Returns the role object
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Role'
        '400':
          description: The request was unacceptable, often due to missing a required parameter
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '401':
          description: No valid API key provided
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '403':
          description: The API key doesn’t have permissions to perform the request
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '429':
          description: Too many requests hit the API too quickly. We recommend an exponential backoff of your requests
          headers:
            Retry-After:
              schema:
                type: string
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '500':
          description: Something went wrong on Braintrust's end. (These are rare.)
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
    delete:
      operationId: deleteRoleId
      tags:
      - Roles
      description: Delete a role object by its id
      summary: Delete role
      security:
      - bearerAuth: []
      - {}
      parameters:
      - $ref: '#/components/parameters/RoleIdParam'
      responses:
        '200':
          description: Returns the deleted role object
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Role'
        '400':
          description: The request was unacceptable, often due to missing a required parameter
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '401':
          description: No valid API key provided
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '403':
          description: The API key doesn’t have permissions to perform the request
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '429':
          description: Too many requests hit the API too quickly. We recommend an exponential backoff of your requests
          headers:
            Retry-After:
              schema:
                type: string
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
        '500':
          description: Something went wrong on Braintrust's end. (These are rare.)
          content:
            text/plain:
              schema:
                type: string
            application/json:
              schema:
                nullable: true
components:
  parameters:
    EndingBefore:
      schema:
        $ref: '#/components/schemas/EndingBefore'
      required: false
      description: 'Pagination cursor id.


        For example, if the initial item in the last page you fetched had an id of `foo`, pass `ending_before=foo` to fetch the previous page. Note: you may only pass one of `starting_after` and `ending_before`'
      name: ending_before
      in: query
    StartingAfter:
      schema:
        $ref: '#/components/schemas/StartingAfter'
      required: false
      description: 'Pagination cursor id.


        For example, if the final item in the last page you fetched had an id of `foo`, pass `starting_after=foo` to fetch the next page. Note: you may only pass one of `starting_after` and `ending_before`'
      name: starting_after
      in: query
    AppLimitParam:
      schema:
        $ref: '#/components/schemas/AppLimitParam'
      required: false
      description: Limit the number of objects to return
      name: limit
      in: query
    Ids:
      schema:
        $ref: '#/components/schemas/Ids'
      required: false
      description: Filter search results to a particular set of object IDs. To specify a list of IDs, include the query param multiple times
      name: ids
      in: query
    RoleName:
      schema:
        $ref: '#/components/schemas/RoleName'
      required: false
      description: Name of the role to search for
      name: role_name
      in: query
      allowReserved: true
    RoleIdParam:
      schema:
        $ref: '#/components/schemas/RoleIdParam'
      required: true
      description: Role id
      name: role_id
      in: path
    OrgName:
      schema:
        $ref: '#/components/schemas/OrgName'
      required: false
      description: Filter search results to within a particular organization
      name: org_name
      in: query
      allowReserved: true
  schemas:
    OrgName:
      type: string
      description: Filter search results to within a particular organization
    AclObjectType:
      type: string
      enum:
      - organization
      - project
      - experiment
      - dataset
      - prompt
      - prompt_session
      - group
      - role
      - org_member
      - project_log
      - org_project
      description: The object type that the ACL applies to
    Role:
      type: object
      properties:
        id:
          type: string
          format: uuid
          description: Unique identifier for the role
        org_id:
          type: string
          nullable: true
          format: uuid
          description: 'Unique id for the organization that the role belongs under


            A null org_id indicates a system role, which may be assigned to anybody and inherited by any other role, but cannot be edited.


            It is forbidden to change the org after creating a role'
        user_id:
          type: string
          nullable: true
          format: uuid
          description: Identifies the user who created the role
        created:
          type: string
          nullable: true
          format: date-time
          description: Date of role creation
        name:
          type: string
          description: Name of the role
        description:
          type: string
          nullable: true
          description: Textual description of the role
        deleted_at:
          type: string
          nullable: true
          format: date-time
          description: Date of role deletion, or null if the role is still active
        member_permissions:
          type: array
          nullable: true
          items:
            type: object
            properties:
              permission:
                $ref: '#/components/schemas/Permission'
              restrict_object_type:
                $ref: '#/components/schemas/AclObjectType'
                nullable: true
            required:
            - permission
          description: (permission, restrict_object_type) tuples which belong to this role
        member_roles:
          type: array
          nullable: true
          items:
            type: string
            format: uuid
          description: 'Ids of the roles this role inherits from


            An inheriting role has all the permissions contained in its member roles, as well as all of their inherited permissions'
      required:
      - id
      - name
      description: 'A role is a collection of permissions which can be granted as part of an ACL


        Roles can consist of individual permissions, as well as a set of roles they inherit from'
    CreateRole:
      type: object
      properties:
        name:
          type: string
          minLength: 1
          description: Name of the role
        description:
          type: string
          nullable: true
          description: Textual description of the role
        member_permissions:
          type: array
          nullable: true
          items:
            type: object
            properties:
              permission:
                $ref: '#/components/schemas/Permission'
              restrict_object_type:
                $ref: '#/components/schemas/AclObjectType'
                nullable: true
            required:
            - permission
          description: (permission, restrict_object_type) tuples which belong to this role
        member_roles:
          type: array
          nullable: true
          items:
            type: string
            format: uuid
          description: 'Ids of the roles this role inherits from


            An inheriting role has all the permissions contained in its member roles, as well as all of their inherited permissions'
        org_name:
          type: string
          nullable: true
          description: For nearly all users, this parameter should be unnecessary. But in the rare case that your API key belongs to multiple organizations, you may specify the name of the organization the role belongs in.
      required:
      - name
    AppLimitParam:
      type: integer
      nullable: true
      minimum: 0
      description: Limit the number of objects to return
    Ids:
      anyOf:
      - type: string
        format: uuid
      - type: array
        items:
          type: string
          format: uuid
      description: Filter search results to a particular set of object IDs. To specify a list of IDs, include the query param multiple times
    RoleName:
      type: string
      description: Name of the role to search for
    StartingAfter:
      type: string
      format: uuid
      description: 'Pagination cursor id.


        For example, if the final item in the last page you fetched had an id of `foo`, pass `starting_after=foo` to fetch the next page. Note: you may only pass one of `starting_after` and `ending_before`'
    Permission:
      type: string
      enum:
      - create
      - read
      - update
      - delete
      - create_acls
      - read_acls
      - update_acls
      - delete_acls
      description: 'Each permission permits a certain type of operation on an object in the system


        Permissions can be assigned to to objects on an individual basis, or grouped into roles'
    RoleIdParam:
      type: string
      format: uuid
      description: Role id
    EndingBefore:
      type: string
      format: uuid
      description: 'Pagination cursor id.


        For example, if the initial item in the last page you fetched had an id of `foo`, pass `ending_before=foo` to fetch the previous page. Note: you may only pass one of `starting_after` and `ending_before`'
    PatchRole:
      type: object
      properties:
        description:
          type: string
          nullable: true
          description: Textual description of the role
        name:
          type: string
          nullable: true
          minLength: 1
          description: Name of the role
        add_member_permissions:
          type: array
          nullable: true
          items:
            type: object
            properties:
              permission:
                $ref: '#/components/schemas/Permission'
              restrict_object_type:
                $ref: '#/components/schemas/AclObjectType'
                nullable: true
            required:
            - permission
          description: A list of permissions to add to the role
        remove_member_permissions:
          type: array
          nullable: true
          items:
            type: object
            properties:
              permission:
                $ref: '#/components/schemas/Permission'
              restrict_object_type:
                $ref: '#/components/schemas/AclObjectType'
                nullable: true
            required:
            - permission
          description: A list of permissions to remove from the role
        add_member_roles:
          type: array
          nullable: true
          items:
            type: string
            format: uuid
          description: A list of role IDs to add to the role's inheriting-from set
        remove_member_roles:
          type: array
          nullable: true
          items:
            type: string
            format: uuid
          description: A list of role IDs to remove from the role's inheriting-from set
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API key or JWT
      description: 'Most Braintrust endpoints are authenticated by providing your API key as a header `Authorization: Bearer [api_key]` to your HTTP request. You can create an API key in the Braintrust [organization settings page](https://www.braintrustdata.com/app/settings?subroute=api-keys).'