Remove role inheritance

Remove the inheritance relationship between a specified role and a direct parent role. The role no longer inherits the parent role’s permissions through this relationship.

DELETE https://moi.matrixorigin.cn/newmoi/workspaces/{workspace_id}/iam/roles/{role_id}/parents/{parent_role_id}

Preparation before calling

First select the roles to identify the child and parent roles. Then view role inheritance to confirm that they currently have a direct inheritance relationship. Prepare a personal access token with the required permission in the target workspace and the target workspace ID.

Request parameters

curl -X DELETE "https://moi.matrixorigin.cn/newmoi/workspaces/$WORKSPACE_ID/iam/roles/$ROLE_ID/parents/$PARENT_ROLE_ID" \
  -H "X-API-Key: $AI_STUDIO_API_KEY" \
  -H "X-Workspace-ID: $WORKSPACE_ID" \
  -H "Content-Type: application/json" \
  -d "{
    \"parent_role_id\": \"$PARENT_ROLE_ID\",
    \"expected_child_lifecycle_version\": 1,
    \"expected_parent_lifecycle_version\": 1,
    \"expected_role_graph_version\": \"graph-v1\",
    \"request_id\": \"req-001\"
  }"

Path parameters

Parameter

Type

Required

Description

workspace_id

string

Yes

Target workspace ID.

role_id

string

Yes

Child role whose inheritance is removed.

parent_role_id

string

Yes

Parent role to remove.

Request body

Parameter

Type

Required

Description

parent_role_id

string

Yes

Parent role ID. Must match parent_role_id in the path.

expected_child_lifecycle_version

integer

Yes

Current child role lifecycle version. Must be greater than 0.

expected_parent_lifecycle_version

integer

Yes

Current parent role lifecycle version. Must be greater than 0.

expected_role_graph_version

string

Yes

Current role graph version.

request_id

string

Yes

Caller-generated idempotency request ID.

Successful response

On success, the inheritance has been removed and the API returns the new role graph version. Replaying the same request ID with the same content does not remove it again.

{"code":"OK","msg":"OK","data":{"child_role_id":"role-001","parent_role_id":"role-parent","role_graph_version":"graph-v2","idempotent_replay":false}}

Field

Type

Description

code

string

OK on success.

msg

string

OK on success.

data.child_role_id

string

Child role ID.

data.parent_role_id

string

Parent role ID that was removed.

data.role_graph_version

string

Updated role graph version.

data.idempotent_replay

boolean

Whether this is an idempotent replay of the same request.

Error response

{"code":"ErrParamInvalid","msg":"请求参数无效","data":null}

Field

Type

Description

code

string

Error code.

msg

string

Error message.

data

null

Last updated on