Skip to main content
PUT
Create or replace a user's inline policy
Requires the IAM action workspace:PutInlinePolicy. See WORKSPACE permissions for the full list, what each one covers, and an example policy.

Authorizations

Authorization
string
header
required

An OAuth 2.0 bearer token, sent as Authorization: Bearer <token>. This is the recommended way to authenticate.

Get one by exchanging a service account's access key pair at POST /v1/oauth/token with grant_type=client_credentials. It is the standard client-credentials grant, so any OAuth-aware library will obtain and refresh it for you.

Tokens last an hour by default. The same access key pair is separately your AWS SigV4 credential for the S3-compatible object endpoint, which speaks nothing else.

Path Parameters

user_id
string<uuid>
required
Example:

"550e8400-e29b-41d4-a716-446655440000"

policy_name
string
required

Inline policy name. UUID spellings and the literal crn: prefix are reserved and cannot be used when creating a policy.

Example:

"S3BucketAccess"

Body

application/json
document
object
required

IAM-style policy document

Response

Inline policy stored

inline_policy
object