Grafana Permissions API

Permissions with `folderId=-1` are the default permissions for users with the Viewer and Editor roles. Permissions can be set for a user, a team or a role (Viewer or Editor). Permissions cannot be set for Admins - they always have access to everything.

Operations 4

GET /dashboards/uid/{uid}/permissions Gets all existing permissions for the given dashboard #
POST /dashboards/uid/{uid}/permissions Updates permissions for a dashboard #
GET /folders/{folder_uid}/permissions Gets all existing permissions for the folder with the given `uid` #
POST /folders/{folder_uid}/permissions Updates permissions for a folder. #

Documentation

📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/
📖
Authentication
https://grafana.com/docs/grafana/latest/developers/http_api/authentication/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/dashboard/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/dashboard_versions/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/dashboard_permissions/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/dashboard_public/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/folder/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/folder_dashboard_search/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/folder_permissions/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/data_source/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/datasource_permissions/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/datasource_lbac_rules/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/alerting_provisioning/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/annotations/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/org/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/user/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/team/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/team_sync/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/preferences/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/access_control/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/serviceaccount/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/sso-settings/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/admin/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/licensing/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/reporting/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/query_and_resource_caching/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/library_element/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/correlations/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/snapshot/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/short_url/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/query_history/

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/grafana-com-permissions-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

grafana-com-permissions-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: 'The Grafana backend exposes an HTTP API, the same API is used by the frontend to do

    everything from saving dashboards, creating users and updating data sources.'
  title: Grafana HTTP API. Permissions API
  contact:
    name: Grafana Labs
    url: https://grafana.com
    email: hello@grafana.com
  version: 0.0.1
servers:
- url: /api
security:
- basic: []
- api_key: []
tags:
- description: Permissions with `folderId=-1` are the default permissions for users with the Viewer and Editor roles. Permissions can be set for a user, a team or a role (Viewer or Editor). Permissions cannot be set for Admins - they always have access to everything.
  name: Permissions
paths:
  /dashboards/uid/{uid}/permissions:
    get:
      description: 'Use: /apis/dashboard.grafana.app/v1/namespaces/{ns}/dashboards/{uid}/access'
      tags:
      - Permissions
      summary: Gets all existing permissions for the given dashboard
      operationId: getDashboardPermissionsListByUID
      deprecated: true
      parameters:
      - name: uid
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          $ref: '#/components/responses/getDashboardPermissionsListResponse'
        '401':
          $ref: '#/components/responses/unauthorisedError'
        '403':
          $ref: '#/components/responses/forbiddenError'
        '404':
          $ref: '#/components/responses/notFoundError'
        '500':
          $ref: '#/components/responses/internalServerError'
    post:
      description: This operation will remove existing permissions if they’re not included in the request.
      tags:
      - Permissions
      summary: Updates permissions for a dashboard
      operationId: updateDashboardPermissionsByUID
      deprecated: true
      parameters:
      - description: The dashboard UID
        name: uid
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          $ref: '#/components/responses/okResponse'
        '400':
          $ref: '#/components/responses/badRequestError'
        '401':
          $ref: '#/components/responses/unauthorisedError'
        '403':
          $ref: '#/components/responses/forbiddenError'
        '404':
          $ref: '#/components/responses/notFoundError'
        '500':
          $ref: '#/components/responses/internalServerError'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateDashboardACLCommand'
        required: true
  /folders/{folder_uid}/permissions:
    get:
      tags:
      - Permissions
      summary: Gets all existing permissions for the folder with the given `uid`
      operationId: getFolderPermissionList
      deprecated: true
      parameters:
      - name: folder_uid
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          $ref: '#/components/responses/getFolderPermissionListResponse'
        '401':
          $ref: '#/components/responses/unauthorisedError'
        '403':
          $ref: '#/components/responses/forbiddenError'
        '404':
          $ref: '#/components/responses/notFoundError'
        '500':
          $ref: '#/components/responses/internalServerError'
    post:
      tags:
      - Permissions
      summary: Updates permissions for a folder.
      operationId: updateFolderPermissions
      parameters:
      - name: folder_uid
        in: path
        required: true
        schema:
          type: string
      responses:
        '200':
          $ref: '#/components/responses/okResponse'
        '401':
          $ref: '#/components/responses/unauthorisedError'
        '403':
          $ref: '#/components/responses/forbiddenError'
        '404':
          $ref: '#/components/responses/notFoundError'
        '500':
          $ref: '#/components/responses/internalServerError'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateDashboardACLCommand'
        required: true
components:
  schemas:
    DashboardACLUpdateItem:
      type: object
      properties:
        permission:
          $ref: '#/components/schemas/DashboardaccessPermissionType'
        role:
          type: string
          enum:
          - None
          - Viewer
          - Editor
          - Admin
        teamId:
          type: integer
          format: int64
        userId:
          type: integer
          format: int64
    DashboardaccessPermissionType:
      type: integer
      format: int64
    DashboardACLInfoDTO:
      type: object
      properties:
        created:
          type: string
          format: date-time
        dashboardId:
          type: integer
          format: int64
        folderId:
          description: 'Deprecated: use FolderUID instead'
          type: integer
          format: int64
          x-deprecated: true
        folderUid:
          type: string
        inherited:
          type: boolean
        isFolder:
          type: boolean
        permission:
          $ref: '#/components/schemas/DashboardaccessPermissionType'
        permissionName:
          type: string
        role:
          type: string
          enum:
          - None
          - Viewer
          - Editor
          - Admin
        slug:
          type: string
        team:
          type: string
        teamAvatarUrl:
          type: string
        teamEmail:
          type: string
        teamId:
          type: integer
          format: int64
        teamUid:
          type: string
        title:
          type: string
        uid:
          type: string
        updated:
          type: string
          format: date-time
        url:
          type: string
        userAvatarUrl:
          type: string
        userEmail:
          type: string
        userId:
          type: integer
          format: int64
        userLogin:
          type: string
        userUid:
          type: string
    ErrorResponseBody:
      type: object
      required:
      - message
      properties:
        error:
          description: Error An optional detailed description of the actual error. Only included if running in developer mode.
          type: string
        message:
          description: a human readable version of the error
          type: string
        status:
          description: 'Status An optional status to denote the cause of the error.


            For example, a 412 Precondition Failed error may include additional information of why that error happened.'
          type: string
    SuccessResponseBody:
      type: object
      properties:
        message:
          type: string
    UpdateDashboardACLCommand:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/DashboardACLUpdateItem'
  responses:
    unauthorisedError:
      description: UnauthorizedError is returned when the request is not authenticated.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponseBody'
    internalServerError:
      description: InternalServerError is a general error indicating something went wrong internally.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponseBody'
    getFolderPermissionListResponse:
      description: (empty)
      content:
        application/json:
          schema:
            type: array
            items:
              $ref: '#/components/schemas/DashboardACLInfoDTO'
    badRequestError:
      description: BadRequestError is returned when the request is invalid and it cannot be processed.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponseBody'
    getDashboardPermissionsListResponse:
      description: (empty)
      content:
        application/json:
          schema:
            type: array
            items:
              $ref: '#/components/schemas/DashboardACLInfoDTO'
    forbiddenError:
      description: ForbiddenError is returned if the user/token has insufficient permissions to access the requested resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponseBody'
    okResponse:
      description: An OKResponse is returned if the request was successful.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/SuccessResponseBody'
    notFoundError:
      description: NotFoundError is returned when the requested resource was not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponseBody'
  securitySchemes:
    api_key:
      type: apiKey
      name: Authorization
      in: header
    basic:
      type: http
      scheme: basic