Member VisibilityGrant member visibility (admin)

Grant member visibility (admin)

To whom (subjectType user|group) and whom they see (scope self|group|vault). scope="self" for a group subject means the members of that same group; for a user subject, the members of all their groups. scope="group" requires targetGroupId. Granting the same pair again reactivates a revoked grant.

curl -X POST "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/visibility-grants" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN" \
  -d '{
  "subjectType": "user",
  "subjectUserId": "example_string",
  "subjectGroupId": "example_string",
  "scope": "self",
  "targetGroupId": "example_string"
}'
{
  "id": "cmr3f41z20001psp7phmyapw3",
  "vaultId": "example_string",
  "subjectType": "example_string",
  "subjectUserId": "example_string",
  "subjectGroupId": "example_string",
  "subject": {
    "id": "example_string",
    "name": "John Doe",
    "username": "John Doe",
    "image": "example_string",
    "color": "example_string",
    "emoji": "example_string"
  },
  "subjectGroup": {
    "id": "example_string",
    "name": "John Doe",
    "color": "example_string",
    "emoji": "example_string"
  },
  "scope": "example_string",
  "targetGroupId": "example_string",
  "targetGroup": {
    "id": "example_string",
    "name": "John Doe",
    "color": "example_string",
    "emoji": "example_string"
  },
  "status": "example_string",
  "grantorId": "example_string",
  "createdAt": "2026-07-02T11:25:15.134000Z"
}
POST
/api/v1/vaults/{code}/visibility-grants
POST
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token
Bearer Tokenstring
Required

Session token. Mobile/services. The web uses a cookie.

Session token. Mobile/services. The web uses a cookie.
API Key (cookie: session_token)
session_tokenstring
Required

API key (sent in cookie)

path
codestring
Required

Unique Vault code (slug)

Content-Typestring
Required

The media type of the request body

Options: application/json
subjectTypestring
Required
Options: user, group
subjectUserIdstring

When subjectType="user"

subjectGroupIdstring

When subjectType="group"

scopestring
Required

Whom the subject sees: "self" means members of their own group; "group" means the specified group (targetGroupId); "vault" means all members of the Vault

Options: self, group, vault
targetGroupIdstring

Required when scope="group"

Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token. Session token. Mobile/services. The web uses a cookie.

path
parameterstring
Required

API Key for authentication. Provide your API key in the cookie.

Path Parameters

codestring
Required

Unique Vault code (slug)

Example:
demo_vault

Body

application/json
subjectTypestring
Required
Allowed values:usergroup
subjectUserIdstring

When subjectType="user"

subjectGroupIdstring

When subjectType="group"

scopestring
Required

Whom the subject sees: "self" means members of their own group; "group" means the specified group (targetGroupId); "vault" means all members of the Vault

Allowed values:selfgroupvault
targetGroupIdstring

Required when scope="group"

Responses