# Grafana Access Control API

**Canonical:** https://apis.io/apis/grafana-com/grafana-com-access-control-api/  
**Provider:** Grafana — https://apis.io/providers/grafana-com/  
**Base URL:** /api  
**Documentation:** https://grafana.com/docs/grafana/latest/developers/http_api/

Grafana Access Control API is one of 49 APIs that [Grafana](https://apis.io/providers/grafana-com/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. Tagged areas include Access Control. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and authentication docs.

The API can be used to create, update, get and list roles, and create or remove built-in role assignments. To use the API, you would need to enable fine-grained access control. This only available in Grafana Enterprise. The API does not currently work with an API Token. So in order to use these API endpoints you will have to use Basic auth.

## Operations (25)

| Method | Path | Summary |
|---|---|---|
| GET | `/access-control/roles` | Get all roles |
| POST | `/access-control/roles` | Create a new custom role |
| GET | `/access-control/roles/{roleUID}` | Get a role |
| PUT | `/access-control/roles/{roleUID}` | Update a custom role |
| DELETE | `/access-control/roles/{roleUID}` | Delete a custom role |
| GET | `/access-control/roles/{roleUID}/assignments` | Get role assignments |
| PUT | `/access-control/roles/{roleUID}/assignments` | Set role assignments |
| GET | `/access-control/status` | Get status |
| POST | `/access-control/teams/roles/search` | List roles assigned to multiple teams |
| GET | `/access-control/teams/{teamId}/roles` | Get team roles |
| PUT | `/access-control/teams/{teamId}/roles` | Update team role |
| POST | `/access-control/teams/{teamId}/roles` | Add team role |
| DELETE | `/access-control/teams/{teamId}/roles/{roleUID}` | Remove team role |
| POST | `/access-control/users/roles/search` | List roles assigned to multiple users |
| GET | `/access-control/users/{userId}/roles` | List roles assigned to a user |
| PUT | `/access-control/users/{userId}/roles` | Set user role assignments |
| POST | `/access-control/users/{userId}/roles` | Add a user role assignment |
| DELETE | `/access-control/users/{userId}/roles/{roleUID}` | Remove a user role assignment |
| GET | `/access-control/{resource}/description` | Get a description of a resource's access control properties |
| GET | `/access-control/{resource}/{resourceID}` | Get permissions for a resource |
| POST | `/access-control/{resource}/{resourceID}` | Set resource permissions |
| POST | `/access-control/{resource}/{resourceID}/builtInRoles/{builtInRole}` | Set resource permissions for a built-in role |
| POST | `/access-control/{resource}/{resourceID}/teams/{teamID}` | Set resource permissions for a team |
| POST | `/access-control/{resource}/{resourceID}/users/{userID}` | Set resource permissions for a user |
| POST | `/admin/provisioning/access-control/reload` | You need to have a permission with action `provisioning:reload` with scope… |

## Machine-readable artifacts (32)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/grafana-com/refs/heads/main/openapi/grafana-com-access-control-api-openapi.yml
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/
- **Authentication** — https://grafana.com/docs/grafana/latest/developers/http_api/authentication/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/dashboard/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/dashboard_versions/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/dashboard_permissions/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/dashboard_public/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/folder/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/folder_dashboard_search/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/folder_permissions/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/data_source/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/datasource_permissions/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/datasource_lbac_rules/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/alerting_provisioning/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/annotations/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/org/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/user/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/team/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/team_sync/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/preferences/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/access_control/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/serviceaccount/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/sso-settings/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/admin/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/licensing/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/reporting/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/query_and_resource_caching/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/library_element/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/correlations/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/snapshot/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/short_url/
- **Documentation** — https://grafana.com/docs/grafana/latest/developers/http_api/query_history/

## Other Grafana APIs (12)

- [Grafana Cloud API](https://apis.io/apis/grafana-com/grafana-cloud-api/)
- [Grafana Loki HTTP API](https://apis.io/apis/grafana-com/loki-http-api/)
- [Grafana Mimir HTTP API](https://apis.io/apis/grafana-com/mimir-http-api/)
- [Grafana Tempo HTTP API](https://apis.io/apis/grafana-com/tempo-http-api/)
- [Grafana Pyroscope HTTP API](https://apis.io/apis/grafana-com/pyroscope-http-api/)
- [Grafana k6 Cloud API](https://apis.io/apis/grafana-com/k6-cloud-api/)
- [Grafana OnCall API](https://apis.io/apis/grafana-com/oncall-api/)
- [Grafana Synthetic Monitoring API](https://apis.io/apis/grafana-com/synthetic-monitoring-api/)
- [Grafana Admin API](https://apis.io/apis/grafana-com/grafana-com-admin-api/)
- [Grafana Admin Ldap API](https://apis.io/apis/grafana-com/grafana-com-admin-ldap-api/)
- [Grafana Admin Provisioning API](https://apis.io/apis/grafana-com/grafana-com-admin-provisioning-api/)
- [Grafana Admin Users API](https://apis.io/apis/grafana-com/grafana-com-admin-users-api/)

## Tags

Access Control

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/grafana-com/grafana-com-access-control-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/grafana-com/.
