---
id: user-grants-bulk-create
title: "Bulk create grants for a user"
description: "Create multiple grants for a user in a single request. This operation is **additive**: it adds new grants without affecting existing ones."
sidebar_label: "Bulk create grants for a user"
hide_title: true
hide_table_of_contents: true
api: eJztWW1v2zgS/isEP7WBYjtNcukK2APcJN3NXbcNEge3h8RIJuLY4lYiVZKy4zX83w9DSpb8kibdbreHw+WDI8vizPCZmWeGozkXaBMjCye14jE/NggOWV5mThYZsrEB5SwbacOAlRYNk4oBs1KNM2QGP5VoXYcNUmmZLtAAyWHSsp0dEEI6OcGdnZhJx0AIyxROa5FT6VJdOgajESZOqjHDB2n9hVZoOzfqRg1SXJfqDCgLCd2AzIseMVCzIJWNQGaWTSCTwq+JmNK1QjDIEr894YX/W5csAcV2dkqLDKVL0bA7ozO8leKO6fqLzcrx3c6OxwAhSStVUjGXNhDcKB5xB2PL42t+oTNkoER4lA8jvtzFmeAxJyDjYFZ8X2Yfd4NdPOIWk9JIN+Px9ZzfIxg0/dKlPL4eLoYRL8BAjg6N9Q8oyJHHXAoecUnuK8ClPFrzKaFYKvmpRCYFKidHEo3fDm3AO9VggnJC2NOtYFmHR5x2Jw0KHjtTYsRtkmIOPJ5zNyu8auVwjIYvIo4PkBcZ8vjo9Q9ka4XMGy1mtCDRyqFydAlFkcnEw9H9zZKN803JYAzMNvbSp7tMj2qnOl35dGU/HXbaOCovrWO2wESOZgwUe3/x3vum8jg86vPg01yqM4e55fFexHN4qL/0ehGX4XrOtcIPI+8SJx1hwK8oRRgJYySMgiPsS9//holbwfaaK0OqlqopYgpDMeMkegX0QIONdUaq8VZH0+70qApNq0uTIJumaDDcInukZWCtHCsU5OOl37g2Y1Dyd++YH/diSBJdKvfjK/JuY9uzzKAnl3aQUqcrpT73/s7ea4cxu0Rk15QtdviiK3Riu1C6VJvKiC4ttS+9b3NtkEk10sEtjdUCJ5gRVnyxWERbPXB28nz8pfhvRV+KLYm3zYqzk78G+qNeb3/v6Ojwb4vFYriIlsgTpf1EuXcRKKDFDh7OxjPLiJpAVmLgNML6cTBWIrHt++iJpftrS3Vhube6ZU1A+EttoVUNFM+2Iyx7fdj74ejwtbfkF/mAorbEc9T3wmjdNvqjjLGFVjY48VVvj/6t0XOWLes7NvWW2TJJ0NpRmWUzivo/uRhUarplIby6poAtGfpz2e/rZ6AAqh63/nuNQ8StA1faTVZ4dj4+Xny9oSs0sPdq/+BwEX1/yqmR+FLK8f3ENNVVT4HikY1Sl/CVxLZ1U61M/OqitR21dkLVwbFFPqoyp+iiZnVCvV2BStBPw626vZxa+yZctZjFdp4Nicm3/eizpHnCZ/JBr7eZvIOmnfWNNIpWJ91hxzrPtWIJlBZtfKN2Wb/qsCAzCGIWGnhbBbe0VShIl/o9Wchx2XwRvCRiUEMtNFqmtAtCVn5KwVLfFpyRo3IU6M7IJJwKVKLzApy8z7BR5lWTR5aSwsaI6sMxJmirax6FaV0mg7W+YZRYmxoOI3d+9x2pBD7csZHETDCpBPEXWjZN5frxwBNXhWaonl9KfVsZK0TLsRboJfp/aIymtMnRWhjjJl+1Fj2dbj8PBud1UJKClWA86PUWld4nE+sXSFKpcJdCBMhH3s5Nmfzi9PLD1cXx6e1PF/33g8vOm6t3/7w9vjjtD05v3/bP3p2e+D7C7/JJrT+XOah1nbRkVecbEKzVpNTQPSn+BJ0/acI9HWHJ0V7DqvC3IYeaI0pVGaVilJyk0IfTNmc/pa4Kz6SKNpdCnbNkw6rfn+enQVtq46NlqaoYYQszrTvu5Or83dkxuc3foH0Kv4EvxXWazgKRNIf7dS4e1GS5RkKk1GfpMyvL72j07j1Y9PmMDytE3IZ37dwfEny1ggeK3eDhUx+5Ff/++usm/x5nksgtYL/stZgofQsvlSdjJlVROjqp5tL6zrWZCfyRzuppevm2vMIMFgYtdUbV9GEZhEkbjxfYGXcidtDr0ccefezTx8HLP8xMfZY/zk3B58TrY18fbLANzYTaN5BZada45B7ErWkdeJ5HVH12bySOIpauMlbrqToWGxKr0bhpE9gNpxtXqilpN/zln0N3fT/Ko4kbE89hvnYnMQXLcshG2uQomEdXOZDKp1II6XYEL6qzxuG2DLkM8K9nSFWBKYCAxoS2RKZDmvbPz5iVodT8D6WGbQNRBcMhpcZh7xV97K86/vD7ZQVt1ijIbsNDtwGyvyw/zir1rAodT8IhU+iOTJBdKZiAzEjqRsJsXf5NU6evWKnwocCEDrJhSzpJSmNQdNh5hmCROTNjMAapWAYOTZ013i6XahoxF9pS6PqBcMy71PN251IsumEkTZNm2lGYI5cm4zFPnSts3O1CITuqzLIiA0dp20l0zmmiWw+nLylTQoC3R9RLKEgQr4bFnhn9QzyqLt5qk4PjMf/Hvwb+PEMZeNFMi09rML7hpOOR4c2QuoaR9tMWNDa4cK/T6/R4U9H77TkZBQNhnYMnkWoi/6bMPq51fc0rlPUYac3G///+5evev4T4c/jgukUG0nvHB/e8yoRrXnkg9qOd5fuZlNIlvubzOTWBVyZbLOj2pxINvYsZRnwCRhJH+LAU0tK14PEIMoufceiLi6p4vGRf8R5m68bq2ZiiyVg1HOQ84h9xFl4K+aFiiiDQeKvDD8fBtt0BLW8WbpREyqGwop8kWLjPPjtsUc/5h8sBJXv14if3ZYcbmFLOwTQYqT1WnkP8vTnPQI1Lz6k8yCRqgFVmWWOS8MZlGwzzeXhioD+iWiyWqDj6zv1E8z8oiguv
sidebar_class_name: "post api-method"
info_path: docs/api/authorization
custom_edit_url: null
---

import MethodEndpoint from "@theme/ApiExplorer/MethodEndpoint";
import ParamsDetails from "@theme/ParamsDetails";
import RequestSchema from "@theme/RequestSchema";
import StatusCodes from "@theme/StatusCodes";
import OperationTabs from "@theme/OperationTabs";
import TabItem from "@theme/TabItem";
import Heading from "@theme/Heading";

<Heading
  as={"h1"}
  className={"openapi__heading"}
  children={"Bulk create grants for a user"}
>
</Heading>

<MethodEndpoint
  method={"post"}
  path={"/user/{id}/grant"}
  context={"endpoint"}
>
  
</MethodEndpoint>



Create multiple grants for a user in a single request. This operation is **additive**: it adds new grants without affecting existing ones.

The operation is **transactional**: if any grant fails validation, no grants are created.

You can **use either `role_id` or `role_slug`** for each grant in the request.


<Heading
  id={"request"}
  as={"h2"}
  className={"openapi-tabs__heading"}
  children={"Request"}
>
</Heading>

<ParamsDetails
  parameters={[{"name":"id","in":"path","description":"The unique identifier for the user receiving the grants.","required":true,"schema":{"type":"integer"},"example":789}]}
>
  
</ParamsDetails>

<RequestSchema
  title={"Body"}
  body={{"content":{"application/json":{"schema":{"type":"array","description":"Array of grants to create for the user. Each grant must specify an NRN and either a `role_id` or `role_slug`.\n","minItems":1,"maxItems":100,"items":{"oneOf":[{"title":"Using role slug","type":"object","required":["nrn","role_slug"],"properties":{"nrn":{"type":"string","description":"The NRN of the resource where the role is assigned.","example":"organization=1:account=2"},"role_slug":{"type":"string","description":"The slug of the role to assign.\n\n> Note: See [Roles](/docs/authorization/roles) for more info.\n","example":"developer"}}},{"title":"Using role ID","type":"object","required":["nrn","role_id"],"properties":{"nrn":{"type":"string","description":"The NRN of the resource where the role is assigned.","example":"organization=1:account=2"},"role_id":{"type":"integer","description":"The ID of the role to assign.\n\n> Note: See [Roles](/docs/authorization/roles) for more info.\n","example":700317756}}}]},"title":"bulkGrantRequest"},"examples":{"Using role_slug":{"value":[{"nrn":"organization=1:account=2","role_slug":"developer"},{"nrn":"organization=1:account=3","role_slug":"ops"}]},"Using role_id":{"value":[{"nrn":"organization=1:account=2","role_id":700317756},{"nrn":"organization=1:account=3","role_id":708509758}]},"Mixed role_id and role_slug":{"value":[{"nrn":"organization=1:account=2","role_slug":"developer"},{"nrn":"organization=1:account=3","role_id":708509758}]}}}}}}
>
  
</RequestSchema>

<StatusCodes
  id={undefined}
  label={undefined}
  responses={{"201":{"description":"All grants were created successfully.","content":{"application/json":{"schema":{"type":"array","description":"Array of created/updated grants.","items":{"type":"object","required":["id","nrn","user_id","role_id","status"],"properties":{"id":{"type":"integer","description":"The unique identifier for the grant.","example":12345},"nrn":{"type":"string","description":"The NRN of the resource where the role is assigned.","example":"organization=1:account=2"},"user_id":{"type":"integer","description":"The ID of the user who received the grant.","example":789},"role_id":{"type":"integer","description":"The ID of the role assigned.","example":700317756},"role_slug":{"type":"string","description":"The slug of the role assigned.","example":"developer"},"status":{"type":"string","enum":["active","pending"],"description":"The status of the grant.","example":"active"}},"title":"bulkGrantResponse"},"title":"bulkGrantArrayResponse"}}}},"400":{"description":"The request failed validation. Common causes:\n- A grant already exists for this user with the same NRN and role\n- The role does not exist\n- The role has an assignment restriction incompatible with the user type\n- The requesting user is not authorized to assign the specified role\n\nThe `cause.index` field indicates which grant in the array failed.\n","content":{"application/json":{"schema":{"type":"object","required":["statusCode","code","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code.","example":400},"code":{"type":"string","description":"Machine-readable error code.","example":"RESOURCE_GRANTS.BULK_CREATE_FAILED"},"error":{"type":"string","description":"Human-readable error type.","example":"Bad Request"},"message":{"type":"string","description":"Details about the error.","example":"Failed to create grants in bulk"},"cause":{"type":"object","description":"Details about the specific grant that failed.","properties":{"code":{"type":"string","description":"The specific error code for the failed grant.","example":"RESOURCE_GRANTS.DUPLICATE_GRANT"},"detail":{"type":"string","description":"Details about why this grant failed.","example":"The grant already exists"},"index":{"type":"integer","description":"The zero-based index of the grant that failed in the request array.","example":1}}}},"title":"bulkGrantError"}}}},"4XX":{"description":"Client error responses due to invalid input or missing parameters.","content":{"application/json":{"schema":{"type":"object","required":["statusCode","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code representing the specific client error (e.g., 400, 401, 403, 404).","example":400},"code":{"type":"string","description":"A machine-readable error code that categorizes the server failure.","example":"bad_request"},"error":{"type":"string","description":"A brief, human-readable description of the error type (e.g., \"Bad Request\", \"Unauthorized\").","example":"Bad Request"},"message":{"type":"string","description":"Additional details about the error.","example":"The request was malformed or contained invalid parameters."}}}}}},"5XX":{"description":"Server error responses indicating an issue on the API side.","content":{"application/json":{"schema":{"type":"object","required":["statusCode","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code representing the specific server error (e.g., 500, 502, 503).","example":500},"code":{"type":"string","description":"A machine-readable error code that categorizes the server failure.","example":"internal_server_error"},"error":{"type":"string","description":"A brief, human-readable description of the error type (e.g., \"Internal Server Error\", \"Service Unavailable\").","example":"Internal Server Error"},"message":{"type":"string","description":"Additional details about the error.","example":"An unexpected error occurred. Please try again later."}}}}}}}}
>
  
</StatusCodes>


      