Miridia
Portal
Administration

Roles

Manages the business roles and their permission matrices.

Base URL: https://api.miridia.io. Read Authentication and Conventions before you call these operations.

MethodPathOperation
GET/api/v1/rolesGet all roles
POST/api/v1/rolesCreate role
GET/api/v1/roles/{roleId}Get role
PATCH/api/v1/roles/{roleId}Patch role
DELETE/api/v1/roles/{roleId}Delete role
POST/api/v1/roles/{roleId}/restore-defaultsRestore role defaults

Get all roles

GET/api/v1/roles

Returns all roles for the current business.

Access. Send a bearer token or an API key. The caller needs the TeamAndRoles view permission.

Response

200. Returns a JSON array. Each item is RoleResponse.

Request
curl -X GET "https://api.miridia.io/api/v1/roles" \
  -H "Authorization: Bearer $MIRIDIA_TOKEN" \
  -H "X-Business-Id: $MIRIDIA_BUSINESS_ID"
Response
[
  {
    "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "title": "string",
    "description": "string",
    "roleType": "Default",
    "scope": "Branch",
    "isSystem": true,
    "permissions": {
      "Orders": "View",
      "Shipments": "View",
      "Customers": "View",
      "Products": "View",
      "Vehicles": "View",
      "Integrations": "View",
      "TeamAndRoles": "View",
      "Billing": "View",
      "Workflows": "View",
      "Settings": "View",
      "Insights": "View",
      "Suppliers": "View",
      "PurchaseOrders": "View",
      "WorkOrders": "View",
      "TransferOrders": "View",
      "Schedule": "View"
    },
    "peopleCount": 0
  }
]

Create role

POST/api/v1/roles

Creates a new custom role for the current business.

Access. Send a bearer token or an API key. The caller needs the TeamAndRoles modify permission.

Request body

Send JSON with the shape CreateRoleCommand.

FieldTypeRequiredDescription
titlestringNo
descriptionstringNo
roleTypeenum RoleTypeNoOne of: Default, Remote, Custom.
scopeenum RoleScopeNoOne of: Branch, Franchise.
permissionsobjectNo

Response

200. Returns a SingleResult envelope. The data field is RoleResponse.

Request
curl -X POST "https://api.miridia.io/api/v1/roles" \
  -H "Authorization: Bearer $MIRIDIA_TOKEN" \
  -H "X-Business-Id: $MIRIDIA_BUSINESS_ID" \
  -H "Content-Type: application/json" \
  -d '{
  "title": "string",
  "description": "string",
  "roleType": "Default",
  "scope": "Branch",
  "permissions": {
    "Orders": "View",
    "Shipments": "View",
    "Customers": "View",
    "Products": "View",
    "Vehicles": "View",
    "Integrations": "View",
    "TeamAndRoles": "View",
    "Billing": "View",
    "Workflows": "View",
    "Settings": "View",
    "Insights": "View",
    "Suppliers": "View",
    "PurchaseOrders": "View",
    "WorkOrders": "View",
    "TransferOrders": "View",
    "Schedule": "View"
  }
}'
Response
{
  "message": "string",
  "messages": [
    {
      "title": "string",
      "message": "string",
      "level": "Standard",
      "icon": "SyncAlert",
      "code": "string"
    }
  ],
  "data": {
    "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "title": "string",
    "description": "string",
    "roleType": "Default",
    "scope": "Branch",
    "isSystem": true,
    "permissions": {
      "Orders": "View",
      "Shipments": "View",
      "Customers": "View",
      "Products": "View",
      "Vehicles": "View",
      "Integrations": "View",
      "TeamAndRoles": "View",
      "Billing": "View",
      "Workflows": "View",
      "Settings": "View",
      "Insights": "View",
      "Suppliers": "View",
      "PurchaseOrders": "View",
      "WorkOrders": "View",
      "TransferOrders": "View",
      "Schedule": "View"
    },
    "peopleCount": 0
  },
  "statusCode": "OK",
  "canRead": true,
  "canEdit": true,
  "canDelete": true
}

Get role

GET/api/v1/roles/{roleId}

Returns a single role, including its full permission matrix.

Access. Send a bearer token or an API key. The caller needs the TeamAndRoles view permission.

Parameters

NameInTypeRequiredDescription
roleIdpathstring (uuid)Yes

Response

200. Returns a SingleResult envelope. The data field is RoleResponse.

Request
curl -X GET "https://api.miridia.io/api/v1/roles/{roleId}" \
  -H "Authorization: Bearer $MIRIDIA_TOKEN" \
  -H "X-Business-Id: $MIRIDIA_BUSINESS_ID"
Response
{
  "message": "string",
  "messages": [
    {
      "title": "string",
      "message": "string",
      "level": "Standard",
      "icon": "SyncAlert",
      "code": "string"
    }
  ],
  "data": {
    "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "title": "string",
    "description": "string",
    "roleType": "Default",
    "scope": "Branch",
    "isSystem": true,
    "permissions": {
      "Orders": "View",
      "Shipments": "View",
      "Customers": "View",
      "Products": "View",
      "Vehicles": "View",
      "Integrations": "View",
      "TeamAndRoles": "View",
      "Billing": "View",
      "Workflows": "View",
      "Settings": "View",
      "Insights": "View",
      "Suppliers": "View",
      "PurchaseOrders": "View",
      "WorkOrders": "View",
      "TransferOrders": "View",
      "Schedule": "View"
    },
    "peopleCount": 0
  },
  "statusCode": "OK",
  "canRead": true,
  "canEdit": true,
  "canDelete": true
}

Patch role

PATCH/api/v1/roles/{roleId}

Partially updates a role: metadata (title, description, type, scope) and/or a full permission-matrix replace. All fields are optional; only supplied fields are applied.

Access. Send a bearer token or an API key. The caller needs the TeamAndRoles modify permission.

Parameters

NameInTypeRequiredDescription
roleIdpathstring (uuid)Yes

Request body

Send JSON with the shape PatchRoleCommand. Partial update of a role: metadata (title/description/type/scope) and/or a full permission-matrix replace. Every field is nullable so a caller can PATCH just one concern without clobbering the other. When permissions is supplied it fully replaces the matrix (mirroring the old SetRolePermissions behaviour); metadata fields are applied individually when non-null.

FieldTypeRequiredDescription
titlestringNo
descriptionstringNo
roleTypeenum RoleTypeNoOne of: Default, Remote, Custom.
scopeenum RoleScopeNoOne of: Branch, Franchise.
permissionsobjectNoWhen provided, replaces the full permission matrix for the role.

Response

200. Returns a SingleResult envelope. The data field is RoleResponse.

Request
curl -X PATCH "https://api.miridia.io/api/v1/roles/{roleId}" \
  -H "Authorization: Bearer $MIRIDIA_TOKEN" \
  -H "X-Business-Id: $MIRIDIA_BUSINESS_ID" \
  -H "Content-Type: application/json" \
  -d '{
  "title": "string",
  "description": "string",
  "roleType": "Default",
  "scope": "Branch",
  "permissions": {
    "Orders": "View",
    "Shipments": "View",
    "Customers": "View",
    "Products": "View",
    "Vehicles": "View",
    "Integrations": "View",
    "TeamAndRoles": "View",
    "Billing": "View",
    "Workflows": "View",
    "Settings": "View",
    "Insights": "View",
    "Suppliers": "View",
    "PurchaseOrders": "View",
    "WorkOrders": "View",
    "TransferOrders": "View",
    "Schedule": "View"
  }
}'
Response
{
  "message": "string",
  "messages": [
    {
      "title": "string",
      "message": "string",
      "level": "Standard",
      "icon": "SyncAlert",
      "code": "string"
    }
  ],
  "data": {
    "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "title": "string",
    "description": "string",
    "roleType": "Default",
    "scope": "Branch",
    "isSystem": true,
    "permissions": {
      "Orders": "View",
      "Shipments": "View",
      "Customers": "View",
      "Products": "View",
      "Vehicles": "View",
      "Integrations": "View",
      "TeamAndRoles": "View",
      "Billing": "View",
      "Workflows": "View",
      "Settings": "View",
      "Insights": "View",
      "Suppliers": "View",
      "PurchaseOrders": "View",
      "WorkOrders": "View",
      "TransferOrders": "View",
      "Schedule": "View"
    },
    "peopleCount": 0
  },
  "statusCode": "OK",
  "canRead": true,
  "canEdit": true,
  "canDelete": true
}

Delete role

DELETE/api/v1/roles/{roleId}

Deletes a role. Returns 400 if the role is a system role.

Access. Send a bearer token or an API key. The caller needs the TeamAndRoles modify permission.

Parameters

NameInTypeRequiredDescription
roleIdpathstring (uuid)Yes

Response

200. Returns a SingleResult envelope. The data field is boolean.

Request
curl -X DELETE "https://api.miridia.io/api/v1/roles/{roleId}" \
  -H "Authorization: Bearer $MIRIDIA_TOKEN" \
  -H "X-Business-Id: $MIRIDIA_BUSINESS_ID"
Response
{
  "message": "string",
  "messages": [
    {
      "title": "string",
      "message": "string",
      "level": "Standard",
      "icon": "SyncAlert",
      "code": "string"
    }
  ],
  "data": true,
  "statusCode": "OK",
  "canRead": true,
  "canEdit": true,
  "canDelete": true
}

Restore role defaults

POST/api/v1/roles/{roleId}/restore-defaults

Access. Send a bearer token or an API key. The caller needs the TeamAndRoles modify permission.

Parameters

NameInTypeRequiredDescription
roleIdpathstring (uuid)Yes

Response

200. Returns a SingleResult envelope. The data field is RoleResponse.

Request
curl -X POST "https://api.miridia.io/api/v1/roles/{roleId}/restore-defaults" \
  -H "Authorization: Bearer $MIRIDIA_TOKEN" \
  -H "X-Business-Id: $MIRIDIA_BUSINESS_ID"
Response
{
  "message": "string",
  "messages": [
    {
      "title": "string",
      "message": "string",
      "level": "Standard",
      "icon": "SyncAlert",
      "code": "string"
    }
  ],
  "data": {
    "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "title": "string",
    "description": "string",
    "roleType": "Default",
    "scope": "Branch",
    "isSystem": true,
    "permissions": {
      "Orders": "View",
      "Shipments": "View",
      "Customers": "View",
      "Products": "View",
      "Vehicles": "View",
      "Integrations": "View",
      "TeamAndRoles": "View",
      "Billing": "View",
      "Workflows": "View",
      "Settings": "View",
      "Insights": "View",
      "Suppliers": "View",
      "PurchaseOrders": "View",
      "WorkOrders": "View",
      "TransferOrders": "View",
      "Schedule": "View"
    },
    "peopleCount": 0
  },
  "statusCode": "OK",
  "canRead": true,
  "canEdit": true,
  "canDelete": true
}

Models

The operations on this page use these object types. Select a type to see its fields.

RoleResponse
FieldTypeDescription
idstring (uuid)
titlestring
descriptionstring
roleTypeenum RoleTypeOne of: Default, Remote, Custom.
scopeenum RoleScopeOne of: Branch, Franchise.
isSystemboolean
permissionsobject
peopleCountinteger (int32)