Omni User group model roles API

Manage model and connection role assignments for user groups

OpenAPI Specification

omni-user-group-model-roles-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Omni AI User group model roles API
  description: "The Omni REST API provides programmatic access to your Omni instance for managing users, documents, queries, schedules, and more.  \n"
  version: 1.0.0
  contact:
    name: Omni Support
    url: https://docs.omni.co
servers:
- url: https://{instance}.omniapp.co/api
  description: Production
  variables:
    instance:
      default: blobsrus
      description: Your production Omni instance subdomain
- url: https://{instance}.playground.exploreomni.dev/api
  description: Playground
  variables:
    instance:
      default: blobsrus
      description: Your playground Omni instance subdomain
security:
- bearerAuth: []
- orgApiKey: []
tags:
- name: User group model roles
  description: Manage model and connection role assignments for user groups
paths:
  /v1/user-groups/{userGroupId}/model-roles:
    post:
      tags:
      - User group model roles
      summary: Assign or update user group model role
      description: 'Assigns or updates a model role for a user group. If the user group already has a role for the specified model, this endpoint will update it to the new role. All members of the user group will inherit this role.


        Model roles control what actions user group members can perform on models and connections. To manage user groups, see the [User group APIs](/api/user-groups).

        '
      security:
      - bearerAuth: []
      operationId: assignUserGroupModelRole
      parameters:
      - name: userGroupId
        in: path
        required: true
        schema:
          type: string
        description: The ID of the user group to assign or update a model role for.
        example: mEhXj6ZI
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
              - roleName
              properties:
                connectionId:
                  type: string
                  format: uuid
                  description: 'The ID of the connection that the model belongs to:


                    - **Required** if `modelId` is not provided

                    - **Optional** if `modelId` is provided, as it will be inferred from the model

                    '
                modelId:
                  type: string
                  format: uuid
                  description: 'The ID of the model to assign the role for:


                    - **Optional** when assigning `CONNECTION_ADMIN` or [custom roles](/administration/users/custom-roles) with `CONNECTION_ADMIN` as the base role

                    - **Required** for other role types

                    '
                roleName:
                  type: string
                  description: 'The role to assign. Available roles include:


                    - `VIEWER` - Can view the model

                    - `QUERIER` - Can view and query the model

                    - `QUERY_TOPICS` - Can query specific topics. Equivalent to **Restricted Querier.**

                    - `MODELER` - Can edit and model the data

                    - `CONNECTION_ADMIN` - Full administrative access to the connection

                    - `NO_ACCESS` - No access to the model

                    - [Custom roles](/administration/users/custom-roles) defined for your organization

                    '
            example:
              connectionId: bc1f9c9f-208d-48a2-9ae3-ff80f2c79fed
              modelId: 7d3e4f5a-6b7c-8d9e-0f1a-2b3c4d5e6f7a
              roleName: QUERIER
      responses:
        '200':
          description: Model role assigned or updated successfully.
          content:
            application/json:
              schema:
                type: object
                properties:
                  userGroupId:
                    type: string
                    description: The ID of the user group.
                  connectionId:
                    type: string
                    format: uuid
                    description: The ID of the connection.
                  modelId:
                    type: string
                    format: uuid
                    description: The ID of the model.
                  roleName:
                    type: string
                    description: The assigned role name.
              example:
                userGroupId: mEhXj6ZI
                connectionId: bc1f9c9f-208d-48a2-9ae3-ff80f2c79fed
                modelId: 7d3e4f5a-6b7c-8d9e-0f1a-2b3c4d5e6f7a
                roleName: QUERIER
        '400':
          description: 'Bad Request. Possible error messages include:


            - `Invalid JSON`

            - `Invalid model ID`

            - `Invalid connection ID`

            - `Method not allowed`

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: 'Not Found. Possible error messages include:


            - `User group not found in organization`

            - `Model does not exist`

            - `Connection does not exist`

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          description: 'Unprocessable Entity. Possible error messages include:


            - `Invalid role`

            - `Model does not belong to connection`

            - `Only shared and shared_extension models can be assigned model roles`

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          $ref: '#/components/responses/TooManyRequests'
    get:
      tags:
      - User group model roles
      summary: Retrieve user group model roles
      description: 'Retrieves the model role assignments for a user group.

        '
      security:
      - bearerAuth: []
      operationId: getUserGroupModelRoles
      parameters:
      - name: userGroupId
        in: path
        required: true
        schema:
          type: string
        description: The ID of the user group to retrieve model roles for.
        example: mEhXj6ZI
      - name: modelId
        in: query
        schema:
          type: string
          format: uuid
        description: Filter results to a specific model ID. If not provided, returns roles for all models the user group has access to.
        example: 7d3e4f5a-6b7c-8d9e-0f1a-2b3c4d5e6f7a
      - name: connectionId
        in: query
        schema:
          type: string
          format: uuid
        description: Filter results to models from a specific connection. If not provided, returns roles for all connections.
        example: bc1f9c9f-208d-48a2-9ae3-ff80f2c79fed
      responses:
        '200':
          description: User group model roles retrieved successfully.
          content:
            application/json:
              schema:
                type: object
                properties:
                  userGroupId:
                    type: string
                    description: The ID of the user group.
                  results:
                    type: array
                    description: Array of role assignments for the user group.
                    items:
                      type: object
                      properties:
                        modelId:
                          type: string
                          format: uuid
                          description: The ID of the model.
                        connectionId:
                          type: string
                          format: uuid
                          description: The ID of the connection.
                        roleName:
                          type: string
                          description: The role assigned to the user group for this model.
                        baseRole:
                          type: string
                          description: The base role assigned to the user group.
              example:
                userGroupId: mEhXj6ZI
                results:
                - baseRole: QUERIER
                  roleName: QUERIER
                  connectionId: bc1f9c9f-208d-48a2-9ae3-ff80f2c79fed
                  modelId: 7d3e4f5a-6b7c-8d9e-0f1a-2b3c4d5e6f7a
        '404':
          description: User group not found in organization.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                detail: User group not found in organization
                status: 404
        '429':
          $ref: '#/components/responses/TooManyRequests'
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
          description: HTTP response code for the error
          example: <response_code>
        message:
          type: string
          description: Detailed error description
          example: <error_reason>
  responses:
    TooManyRequests:
      description: Too Many Requests - Rate limit exceeded (60 requests/minute)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'Can be either an [Organization API Key](/api/authentication#organization-api-keys) or [Personal Access Token (PAT)](/api/authentication#token-types).


        Include in the `Authorization` header as: `Bearer YOUR_TOKEN`

        '
    orgApiKey:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'Requires an [Organization API Key](/api/authentication#organization-api-keys). Personal Access Tokens (PATs) are not supported for this endpoint.


        Include in the `Authorization` header as: `Bearer ORGANIZATION_API_KEY`

        '