Поделиться папкой (создатель/admin)
Грант на ПАПКУ (группу адресов): субъект получает права на все адреса папки, включая добавленные позже.
Права задаются РОЛЬЮ — role: viewer|contributor (как у гранта на адрес). Legacy-флаги canView/canTransfer ещё принимаются; если пришло и то и другое, роль приоритетнее.
ИДЕМПОТЕНТЕН: повтор для той же пары (субъект, папка) меняет права, отозванный грант реактивирует — 409 GRANT_EXISTS больше не возвращается. Раньше он возвращался, и клиенту приходилось ловить его, искать грант в списке и слать PATCH — три запроса вместо одного.
canCreateAddress — отдельное право «заводить НОВЫЕ адреса в эту папку», в роль не входит и по умолчанию не выдаётся: роль описывает доступ к тому, что в папке уже есть.
curl -X POST "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-folders/example_string/grants" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN"
import requests
import json
url = "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-folders/example_string/grants"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
response = requests.post(url, headers=headers)
print(response.json())
const response = await fetch("https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-folders/example_string/grants", {
method: "POST",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("POST", "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-folders/example_string/grants", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-folders/example_string/grants')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Post.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN'
response = http.request(request)
puts response.body
{
"id": "cmr3f41z20001psp7phmyapw3",
"vaultId": "example_string",
"subjectType": "user",
"subjectUserId": "example_string",
"subjectGroupId": "example_string",
"targetType": "address",
"targetAddressId": "123 Main St",
"targetGroupId": "example_string",
"role": "viewer",
"canView": true,
"canTransfer": true,
"canCreateAddress": true,
"grantorId": "example_string",
"status": "active",
"createdAt": "2026-07-02T11:25:15.134Z",
"updatedAt": "2026-07-02T11:25:15.134Z",
"subject": {
"id": "example_string",
"name": "John Doe",
"username": "John Doe",
"image": "example_string",
"color": "example_string",
"emoji": "example_string"
},
"subjectGroup": {
"id": "example_string",
"name": "John Doe"
}
}
{
"error": "Bad Request",
"message": "The request contains invalid parameters or malformed data",
"code": 400,
"details": [
{
"field": "email",
"message": "Invalid email format"
}
]
}
{
"error": "Unauthorized",
"message": "Authentication required. Please provide a valid API token",
"code": 401
}
{
"error": "Forbidden",
"message": "You don't have permission to access this resource",
"code": 403
}
{
"error": "Not Found",
"message": "The requested resource was not found",
"code": 404
}
{
"error": "Internal Server Error",
"message": "An unexpected error occurred on the server",
"code": 500,
"requestId": "req_1234567890"
}
/api/v1/vaults/{code}/address-folders/{id}/grantsTarget server for requests. Edit to use your own host.
better-auth session token. Мобилка/сервисы. Веб использует cookie.
API key (sent in cookie)
Уникальный код Vault'а (slug)
The media type of the request body
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token. better-auth session token. Мобилка/сервисы. Веб использует cookie.
API Key for authentication. Provide your API key in the cookie.
Path Parameters
Body
Raw application/json data