PUT
/api/public/v1/employees/{employeeId}/permissions

Set an employee’s permissions

Reconciles their grants to **exactly** the set you send: everything missing is granted, everything extra is revoked. Sending a shorter list is how you take access away, so a partial list is a revocation rather than a no-op — read the current set first if you mean to add one thing. `PUT` rather than `PATCH` for that reason. The company owner cannot be reconciled: they implicitly hold every scope, so setting theirs would read as taking it all away. Internal-only scopes are rejected outside the internal Pixelbase company.

Required scope

The access token must carry this scope. A token missing it gets 403 Forbidden. Grant them to an API client under Settings → Company → API, and to a teammate under Employee → Permissions.

employee:permissions:write

Path Parameters

NameTypeRequiredDescription
employeeIdstringRequiredEmployee ID.

Request Body

PropertyTypeDescription
scopesarrayThe complete set, as `{ scope, locationId }`. Omit `locationId` (or send null) for a company-level grant. An empty array revokes everything.
PUTExample request
curl
curl -X PUT "https://www.pxb.app/api/public/v1/employees/{employeeId}/permissions" \
  -H "Authorization: Bearer your_access_token" \
  -H "Content-Type: application/json" \
  -d '{
    "scopes": [
      {
        "scope": "customers:read"
      },
      {
        "scope": "schedule:write",
        "locationId": "loc_abc123"
      }
    ]
  }'
200Example response
json
{
  "message": "Scopes updated.",
  "content": {
    "granted": 2,
    "revoked": 1
  }
}
403Example response
json
{
  "message": "The company owner already has every scope."
}

In the console

The same thing done by hand, for anyone comparing the API against the screen they already use.

Employees → Directory → Permissions
/employee/directory
  1. Open an employee.
  2. Permissions.
  3. Tick the scopes they should hold.