Address GroupsShare a folder (creator/admin)

Share a folder (creator/admin)

A grant on a FOLDER (address group): the subject gets permissions on all of the folder's addresses, including ones added later.

Permissions are set by a ROLE: role: viewer|contributor (as with an address grant). The legacy flags canView/canTransfer are still accepted; if both are sent, the role takes precedence.

IDEMPOTENT: repeating the call for the same (subject, folder) pair changes the permissions and reactivates a revoked grant; 409 GRANT_EXISTS is no longer returned. It used to be, and the client had to catch it, find the grant in the list, and send a PATCH: three requests instead of one.

canCreateAddress is a separate permission to "create NEW addresses in this folder"; it isn't part of the role and isn't granted by default: the role describes access to what's already in the folder.

curl -X POST "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-folders/example_string/grants" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN"
{
  "id": "cmr3f41z20001psp7phmyapw3",
  "vaultId": "example_string",
  "subjectType": "user",
  "subjectUserId": "example_string",
  "subjectGroupId": "example_string",
  "targetType": "address",
  "targetAddressId": "123 Main St",
  "targetGroupId": "example_string",
  "role": "viewer",
  "canView": true,
  "canTransfer": true,
  "canCreateAddress": true,
  "grantorId": "example_string",
  "status": "active",
  "createdAt": "2026-07-02T11:25:15.134000Z",
  "updatedAt": "2026-07-02T11:25:15.134000Z",
  "subject": {
    "id": "example_string",
    "name": "John Doe",
    "username": "John Doe",
    "image": "example_string",
    "color": "example_string",
    "emoji": "example_string"
  },
  "subjectGroup": {
    "id": "example_string",
    "name": "John Doe"
  }
}
POST
/api/v1/vaults/{code}/address-folders/{id}/grants
POST
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token
Bearer Tokenstring
Required

Session token. Mobile/services. The web uses a cookie.

Session token. Mobile/services. The web uses a cookie.
API Key (cookie: session_token)
session_tokenstring
Required

API key (sent in cookie)

Content-Typestring
Required

The media type of the request body

Options: application/json
No request body parameters defined
Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token. Session token. Mobile/services. The web uses a cookie.

path
parameterstring
Required

API Key for authentication. Provide your API key in the cookie.

Path Parameters

codestring
Required

Unique Vault code (slug)

Example:
demo_vault

Body

application/json
datastring
Required

Raw application/json data

Responses