Prerequisites
For role-based access control (RBAC) to work properly, you must enable it for your API using either the Dashboard or the Management API. The Authorization Core functionality is different from the Authorization Extension. For a comparison, read Authorization Core vs. Authorization Extension.Use the Dashboard
- Go to Dashboard > User Management > Users and click the name of the user.
-
Click the Permissions view, then click the trash can icon next to the permission you want to remove, and confirm.
Use the Management API
Make aDELETE
call to the Delete User Permissions endpoint. Be sure to replace USER_ID
, MGMT_API_ACCESS_TOKEN
, API_ID
, and PERMISSION_NAME
placeholder values with your user ID, Management API , API ID(s), and permission name(s), respectively.
Value | Description |
---|---|
USER_ID | Τhe ID of the user to be updated. |
MGMT_API_ACCESS_TOKEN | Access Token for the Management API with the scope update:users . |
API_ID | ID(s) of the API(s) associated with the permission(s) you would like to remove for the specified user. |
PERMISSION_NAME | Name(s) of the permission(s) you would like to remove for the specified user. |