---
title: "Add a user role assignment."
method: POST
path: "/access-control/users/{userId}/roles"
tags: ["access_control", "enterprise"]
---

# Add a user role assignment.

`POST /access-control/users/{userId}/roles`

Assign a role to a specific user. For bulk updates consider Set user role assignments.

You need to have a permission with action `users.roles:add` and scope `permissions:type:delegate`. `permissions:type:delegate` scope ensures that users can only assign roles which have same, or a subset of permissions which the user has. For example, if a user does not have required permissions for creating users, they won’t be able to assign a role which will allow to do that. This is done to prevent escalation of privileges.

## Path parameters

- `userId` integer, required

## Request body

- AddUserRoleCommand
  - `global` boolean
  - `roleUid` string

## Response `200`

An OKResponse is returned if the request was successful.

- SuccessResponseBody
  - `message` string

## Other responses

- `403` — ForbiddenError is returned if the user/token has insufficient permissions to access the requested resource.
- `404` — NotFoundError is returned when the requested resource was not found.
- `500` — InternalServerError is a general error indicating something went wrong internally.

---

[API](https://skmtc.net/grafana/apis/http-api.md) · [All operations](https://skmtc.net/grafana/apis/http-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/grafana/http-api/versions/df55ba1718ba/schema)
