---
title: "Updates permissions for a folder. This operation will remove existing permissions if they’re not included in the request."
method: POST
path: "/folders/{folder_uid}/permissions"
tags: ["folder_permissions"]
---

# Updates permissions for a folder. This operation will remove existing permissions if they’re not included in the request.

`POST /folders/{folder_uid}/permissions`

## Path parameters

- `folder_uid` string, required

## Request body

- UpdateDashboardACLCommand
  - `items` DashboardACLUpdateItem[]
    - `permission` integer
    - `role` 'Viewer' | 'Editor' | 'Admin'
    - `teamId` integer
    - `userId` integer

## Response `200`

An OKResponse is returned if the request was successful.

- SuccessResponseBody
  - `message` string

## Other responses

- `401` — UnauthorizedError is returned when the request is not authenticated.
- `403` — ForbiddenError is returned if the user/token has insufficient permissions to access the requested resource.
- `404` — NotFoundError is returned when the requested resource was not found.
- `500` — InternalServerError is a general error indicating something went wrong internally.

---

[API](https://skmtc.net/nforgeio/apis/grafana-http-api.md) · [All operations](https://skmtc.net/nforgeio/apis/grafana-http-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/nforgeio/grafana-http-api/versions/3cb6c3f42dc7/schema)
