/api/public/v1/employees/{employeeId}/permissionsSet an employee’s permissions
Reconciles their grants to **exactly** the set you send: everything missing is granted, everything extra is revoked. Sending a shorter list is how you take access away, so a partial list is a revocation rather than a no-op — read the current set first if you mean to add one thing. `PUT` rather than `PATCH` for that reason. The company owner cannot be reconciled: they implicitly hold every scope, so setting theirs would read as taking it all away. Internal-only scopes are rejected outside the internal Pixelbase company.
Required scope
The access token must carry this scope. A token missing it gets 403 Forbidden. Grant them to an API client under Settings → Company → API, and to a teammate under Employee → Permissions.
Path Parameters
| Name | Type | Required | Description |
|---|---|---|---|
employeeId | string | Required | Employee ID. |
Request Body
| Property | Type | Description |
|---|---|---|
scopes | array | The complete set, as `{ scope, locationId }`. Omit `locationId` (or send null) for a company-level grant. An empty array revokes everything. |
curl -X PUT "https://www.pxb.app/api/public/v1/employees/{employeeId}/permissions" \
-H "Authorization: Bearer your_access_token" \
-H "Content-Type: application/json" \
-d '{
"scopes": [
{
"scope": "customers:read"
},
{
"scope": "schedule:write",
"locationId": "loc_abc123"
}
]
}'{
"message": "Scopes updated.",
"content": {
"granted": 2,
"revoked": 1
}
}{
"message": "The company owner already has every scope."
}In the console
The same thing done by hand, for anyone comparing the API against the screen they already use.
- Open an employee.
- Permissions.
- Tick the scopes they should hold.