Share a folder (creator/admin)
A grant on a FOLDER (address group): the subject gets permissions on all of the folder's addresses, including ones added later.
Permissions are set by a ROLE: role: viewer|contributor (as with an address grant). The legacy flags canView/canTransfer are still accepted; if both are sent, the role takes precedence.
IDEMPOTENT: repeating the call for the same (subject, folder) pair changes the permissions and reactivates a revoked grant; 409 GRANT_EXISTS is no longer returned. It used to be, and the client had to catch it, find the grant in the list, and send a PATCH: three requests instead of one.
canCreateAddress is a separate permission to "create NEW addresses in this folder"; it isn't part of the role and isn't granted by default: the role describes access to what's already in the folder.
curl -X POST "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-groups/example_string/grants" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN"
import requests
import json
url = "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-groups/example_string/grants"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
response = requests.post(url, headers=headers)
print(response.json())
const response = await fetch("https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-groups/example_string/grants", {
method: "POST",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("POST", "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-groups/example_string/grants", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/address-groups/example_string/grants')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Post.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN'
response = http.request(request)
puts response.body
{
"id": "cmr3f41z20001psp7phmyapw3",
"vaultId": "example_string",
"subjectType": "user",
"subjectUserId": "example_string",
"subjectGroupId": "example_string",
"targetType": "address",
"targetAddressId": "123 Main St",
"targetGroupId": "example_string",
"role": "viewer",
"canView": true,
"canTransfer": true,
"canCreateAddress": true,
"grantorId": "example_string",
"status": "active",
"createdAt": "2026-07-02T11:25:15.134000Z",
"updatedAt": "2026-07-02T11:25:15.134000Z",
"subject": {
"id": "example_string",
"name": "John Doe",
"username": "John Doe",
"image": "example_string",
"color": "example_string",
"emoji": "example_string"
},
"subjectGroup": {
"id": "example_string",
"name": "John Doe"
}
}
{
"error": "Bad Request",
"message": "The request contains invalid parameters or malformed data",
"code": 400,
"details": [
{
"field": "email",
"message": "Invalid email format"
}
]
}
{
"error": "Unauthorized",
"message": "Authentication required. Please provide a valid API token",
"code": 401
}
{
"error": "Forbidden",
"message": "You don't have permission to access this resource",
"code": 403
}
{
"error": "Not Found",
"message": "The requested resource was not found",
"code": 404
}
{
"error": "Internal Server Error",
"message": "An unexpected error occurred on the server",
"code": 500,
"requestId": "req_1234567890"
}
/api/v1/vaults/{code}/address-groups/{id}/grantsTarget server for requests. Edit to use your own host.
Session token. Mobile/services. The web uses a cookie.
API key (sent in cookie)
Unique Vault code (slug)
The media type of the request body
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token. Session token. Mobile/services. The web uses a cookie.
API Key for authentication. Provide your API key in the cookie.
Path Parameters
Body
Raw application/json data