Create a role
create_workspace_role
Creates a custom role in a workspace with a chosen set of permissions.
Roles are how a workspace gives people less than full access. Every custom role grants workspace.access whether you list it or not, and api.access is what lets a member use an access token at all, from an MCP client or the HTTP API. Every permission explains what each one allows.
Deleting the workspace and managing billing belong to the owner alone, so workspace.delete and billing.manage are not among the values the tool accepts. A role with no permissions is refused. The answer is the new role, with the _id that assign_member_role and the roles of invite_workspace_member take.
It needs the Manage roles permission (roles.manage) and the workspace on Pro or Enterprise, otherwise it is refused with You must upgrade to the Pro plan to manage roles! A workspace holds up to 10 custom roles, and past that the call is refused with You can create up to 10 roles per workspace! See Members and roles.
Inputs
| Input | Type | Required | Description |
|---|---|---|---|
workspaceId |
string | Yes | The workspace id. |
name |
string | Yes | What to call the role, 2 to 32 characters. |
permissions |
array of strings | Yes | The permissions it grants, at least one of workspace.access, workspace.update, members.manage, roles.manage, projects.delete, projects.transfer, projects.move, projects.domains, folders.edit, folders.delete, folders.move and api.access. |