const collectionName = 'YourCollection';
// Add permissions to a user's existing set (additive, default behavior)
const userId = '540824222';
domo.put(
`/domo/datastores/v1/collections/${collectionName}/permission/USER/${userId}?permissions=read,create_content,read_content,update_content,delete_content`
).then(() => console.log('user permissions updated'));
// Replace the app instance's permission set entirely (overwrite=true)
// The instance UUID is the subdomain of the app's origin URL.
const instanceId = window.location.hostname.split('.')[0];
domo.put(
`/domo/datastores/v1/collections/${collectionName}/permission/RYUU_APP/${instanceId}?permissions=read,read_content&overwrite=true`
).then(() => console.log('app permissions replaced'));# This API is only available inside a Domo app.
# Use the JavaScript (domo.js) tab for the correct usage.# This API is only available inside a Domo app.
# Use the JavaScript (domo.js) tab for the correct usage.// This API is only available inside a Domo app.
// Use the JavaScript (domo.js) tab for the correct usage.// This API is only available inside a Domo app.
// Use the JavaScript (domo.js) tab for the correct usage.// This API is only available inside a Domo app.
// Use the JavaScript (domo.js) tab for the correct usage.# This API is only available inside a Domo app.
# Use the JavaScript (domo.js) tab for the correct usage.{
"status": 400,
"statusReason": "status 400 reading CollectionsResourceClient#setCollectionPermissions(UUID,String,String,Set,Boolean); content:\n{\"message\":\"Unable to verify user with id 1\",\"status\":400,\"statusReason\":\"Bad Request\",\"toe\":\"4TZK5F0MHP-VLK9M-YVHFY\"}",
"toe": "4TZK5F0MHP-VLK9M-YVHFY"
}{
"status": 403,
"statusReason": "status 403 reading CollectionsResourceClient#setCollectionPermissions(UUID,String,String,Set,Boolean); content:\n{\"message\":\"The item you're looking for can not be found\",\"status\":403,\"statusReason\":\"Forbidden\",\"toe\":\"6CPYAXAZXA-8DYRE-V4TQC\"}",
"toe": "6CPYAXAZXA-8DYRE-V4TQC"
}{
"status": 404,
"statusReason": "DA0088: Collection 'T' was not found in datastore fcd8baba-9524-4fb5-b94b-b3d3b588e740 - it may not exist on this instance or may not be accessible",
"toe": "DSKD0CWR0C-NTWA3-UNZVI"
}Modify Collection Permissions
Modify the permissions for a user, group, or app instance on a collection.
Permission Inheritance
Users and groups inherit permissions from the app, so often the most convenient thing is to give the app the permissions you want all people to have. Anyone who gets the app shared with them inherits its permissions on the collection and its documents. By default, apps are given the following permissions on their collections: read, create_content, read_content, update_content, and delete_content.
You can set the app permissions with this API or using the wiring screen of an app card.
Direct Permissions
However, in situations where not everyone should be able to create, update or delete documents, you’ll need a more nuanced permission model. You can give individual users and groups permissions using this API or AppDB Admin.
When you need control down to the document level, you can leverage Document-level Security.
overwrite=true. Then it will replace the entire permission set for that entity with the permissions you specify. To remove all permissions for an entity, use Delete Permissions.Available Permissions
| Permission | Grants |
|---|---|
admin | All permissions to the collection and its documents |
write | Update the collection’s properties |
read | Read the collection’s properties |
share | Add or remove permissions this entity already holds |
delete | Delete the collection |
create_content | Create documents in the collection |
update_content | Update documents in the collection |
read_content | Read documents in the collection |
delete_content | Delete documents from the collection |
Removing all entity permissions leaves only users with the Manage AppDB grant with access.
const collectionName = 'YourCollection';
// Add permissions to a user's existing set (additive, default behavior)
const userId = '540824222';
domo.put(
`/domo/datastores/v1/collections/${collectionName}/permission/USER/${userId}?permissions=read,create_content,read_content,update_content,delete_content`
).then(() => console.log('user permissions updated'));
// Replace the app instance's permission set entirely (overwrite=true)
// The instance UUID is the subdomain of the app's origin URL.
const instanceId = window.location.hostname.split('.')[0];
domo.put(
`/domo/datastores/v1/collections/${collectionName}/permission/RYUU_APP/${instanceId}?permissions=read,read_content&overwrite=true`
).then(() => console.log('app permissions replaced'));# This API is only available inside a Domo app.
# Use the JavaScript (domo.js) tab for the correct usage.# This API is only available inside a Domo app.
# Use the JavaScript (domo.js) tab for the correct usage.// This API is only available inside a Domo app.
// Use the JavaScript (domo.js) tab for the correct usage.// This API is only available inside a Domo app.
// Use the JavaScript (domo.js) tab for the correct usage.// This API is only available inside a Domo app.
// Use the JavaScript (domo.js) tab for the correct usage.# This API is only available inside a Domo app.
# Use the JavaScript (domo.js) tab for the correct usage.{
"status": 400,
"statusReason": "status 400 reading CollectionsResourceClient#setCollectionPermissions(UUID,String,String,Set,Boolean); content:\n{\"message\":\"Unable to verify user with id 1\",\"status\":400,\"statusReason\":\"Bad Request\",\"toe\":\"4TZK5F0MHP-VLK9M-YVHFY\"}",
"toe": "4TZK5F0MHP-VLK9M-YVHFY"
}{
"status": 403,
"statusReason": "status 403 reading CollectionsResourceClient#setCollectionPermissions(UUID,String,String,Set,Boolean); content:\n{\"message\":\"The item you're looking for can not be found\",\"status\":403,\"statusReason\":\"Forbidden\",\"toe\":\"6CPYAXAZXA-8DYRE-V4TQC\"}",
"toe": "6CPYAXAZXA-8DYRE-V4TQC"
}{
"status": 404,
"statusReason": "DA0088: Collection 'T' was not found in datastore fcd8baba-9524-4fb5-b94b-b3d3b588e740 - it may not exist on this instance or may not be accessible",
"toe": "DSKD0CWR0C-NTWA3-UNZVI"
}Path Parameters
The name given to the collection in the manifest. Case-sensitive.
The type of entity the permissions apply to.
USER, GROUP, RYUU_APP The ID of the entity the permissions apply to. For a USER or GROUP, this is the numeric ID (for example, 870010733). For a RYUU_APP, this is the app instance's UUID — the same value as the app's datastore UUID, which also appears as the subdomain of the app's origin (e.g., https://<instance-uuid>.domoapps.domo.com).
Query Parameters
One or more permissions to apply. Pass as a comma-separated list.
admin, write, read, share, delete, create_content, update_content, read_content, delete_content Controls how the specified permissions are applied to the entity's existing permission set.
false(default) — additive: merges the specified permissions with any permissions the entity already holds.true— replace: discards the entity's existing permissions and replaces them with exactly the permissions you specify.
Response
Permissions updated successfully. No response body is returned.