---
metadata:
  - name: generator
    content: Diplodoc Platform v5.63.2
  - property: og:type
    content: article
  - property: article:section
    content: API reference
  - property: og:title
    content: Change extended entity access settings
  - property: article:tag
    content: Technical reference
alternate:
  - https://www.yandex.ru/support/tracker/en/api/entities/patch-access.md
  - https://www.yandex.ru/support/tracker/ru/api/entities/patch-access.md
  - href: https://www.yandex.ru/support/tracker/en/api/entities/patch-access.md
    type: text/markdown
    title: Markdown version
  - href: https://www.yandex.ru/support/tracker/en/llms.txt?revision=r21584721
    rel: describedby
---
> **Documentation Index:** Fetch the complete configuration index at https://www.yandex.ru/support/tracker/en/llms.txt?revision=r21584721


# Change extended entity access settings

Use this request to change extended access settings for an entity, including inherited permissions: [goal](https://www.yandex.ru/support/tracker/en/goals/goals-start.md), [project](https://www.yandex.ru/support/tracker/en/manager/project-new.md), or [project portfolio](https://www.yandex.ru/support/tracker/en/manager/portfolio.md).

<div class="request_example yfm-code-floating-container method_patch">
    <p>PATCH</p>
    <pre><code>https://api.tracker.yandex.net/v3/entities/{entity_type}/{entity_ID}/extendedPermissions</code></pre>
    <button class="yfm-clipboard-button"><svg width="16" height="16" viewBox="0 0 24 24" class="yfm-clipboard-icon" data-animation="15">
    <path fill="currentColor" d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path>
    <path stroke="currentColor" fill="transparent" strokewidth="1.5" d="M9.5 13l3 3l5 -5" visibility="hidden">
        <animate id="visibileAnimation-15" attributeName="visibility" from="hidden" to="visible" dur="0.2s" fill="freeze" begin=""></animate>
        <animate id="hideAnimation-15" attributeName="visibility" from="visible" to="hidden" dur="1s" begin="visibileAnimation-15.end+1" fill="freeze"></animate>
    </path>
</svg>
</button>
</div>

<!-- source: en/api/_assets/style/methods.md -->

<!-- endsource: en/api/_assets/style/methods.md -->

{% note info "" %}

To update direct permissions without changing inheritance, use the [Change entity permissions](https://www.yandex.ru/support/tracker/en/api/entities/patch-permissions.md) request.

{% endnote %}

## Query format {#query}

Before making a request, [get permission to access the API](https://www.yandex.ru/support/tracker/en/api/access.md).

To update an entity's extended access settings, use an HTTP `PATCH` request. In the request body, specify the parameters in JSON format.

```json translate=no
PATCH /v3/entities/{entity_type}/{entity_ID}/extendedPermissions
Host: api.tracker.yandex.net
Authorization: OAuth API_TOKEN
Content-Type: application/json
X-Org-ID or X-Cloud-Org-ID: ORGANIZATION_ID

{
    "permissionSources": [],
    "acl": {
        "grant": {
            "READ": {
                "users": ["username1", "username2"],
                "groups": [],
                "roles": []
            },
            "WRITE": {
                "users": [],
                "groups": [1, 2],
                "roles": []
            },
            "GRANT": {
                "users": [],
                "groups": [],
                "roles": []
            }
        },
        "revoke": {
            "READ": {
                "users": {"uid": 123********},
                "groups": 3,
                "roles": []
            },
            "WRITE": {
                "users": [],
                "groups": [],
                "roles": "FOLLOWER"
            },
            "GRANT": {
                "users": [],
                "groups": [],
                "roles": []
            }
        }
    }
}
```

<!-- source: en/api/_includes/headings.md -->
{% cut "Headers" %}

* `Host`: address of the node that provides the API.

* <!-- source: en/api/_includes/authorization.md -->
  `Authorization`: Authorization token about these formats:

    - `OAuth OAUTH_TOKEN`: For authorization using the OAuth 2.0 protocol. [Learn more](https://www.yandex.ru/support/tracker/en/api/access.md#about_OAuth)

    - `Bearer IAM_TOKEN`: For authorization using an IAM token, if a Yandex Identity Hub organization is linked to Tracker. [Learn more](https://www.yandex.ru/support/tracker/en/api/access.md#iam-token)
  <!-- endsource: en/api/_includes/authorization.md -->


* <!-- source: en/api/_includes/org-id.md -->
  # ID types {#types}


  `X-Org-ID` or `X-Cloud-Org-ID`: Organization ID.

  - Use the `X-Org-ID` header if a Tracker organization is linked to Yandex 360 for Business.

  - Use the `X-Cloud-Org-ID` header if a Tracker organization is linked to Yandex Identity Hub.


  # Finding the ID {#find-id}


  To get the organization ID, go to **Administration** → [**Organizations**](https://tracker.yandex.com/admin/orgs) and copy the value from the **ID** field.
  <!-- endsource: en/api/_includes/org-id.md -->


{% endcut %}
<!-- endsource: en/api/_includes/headings.md -->

<!-- source: en/api/_includes/resource-entity.md -->
{% cut "Resource" %}

| Parameter | Description | Data type |
-------- | -------- | ----------
| `entity_type` | Entity type:<ul><li>project</li><li>portfolio</li><li>goal</li></ul> | String |
| `entity_ID` | Entity ID. To get the ID, see the [entity list](search-entities.md). You can use the `id` or `shortId` parameter as the ID. | String |

{% endcut %}
<!-- endsource: en/api/_includes/resource-entity.md -->

{% cut "Request body parameters" %}

**Additional parameters**

#|
|| Parameter | Description | Data type ||
|| [permissionSources](#entity-id) | The ID of the parent entity from which the current entity inherits access settings.
* To enable access inheritance, specify the ID of the main portfolio (for portfolios or projects) or the parent goal (for goals).
  You'll find the ID of the parent entity in the response to the [Get extended entity access settings](https://www.yandex.ru/support/tracker/en/api/entities/get-access.md) request.
  To change the parent entity, use the [Updating an entity](https://www.yandex.ru/support/tracker/en/api/entities/update-entity.md) request.
* To disable access inheritance, pass `"permissionSources": []` |
String or array of strings ||
|| [acl](#acl-req) | Object that specifies the permissions that you want to grant or revoke | Object ||
|#

{% note warning "" %}

If `permissionSources` is set to a non-empty value:
* You can’t update permissions using the `acl` parameter.
* The `teamAccess` entity parameter is ignored (see [Additional entity parameters](https://www.yandex.ru/support/tracker/en/api/entities/about-entities.md#query-params)).

To update permissions, first disable access inheritance from the parent entity.

{% endnote %}

`acl` **object fields** {#acl-req}

| Parameter | Description | Data type |
| -------- | -------- | ---------- |
| [grant](#grant-revoke) | Object that specifies the permissions you want to grant to users, groups, or roles | Object |
| [revoke](#grant-revoke) | Object that specifies the permissions you want to revoke from users, groups, or roles | Object |

`grant` and `revoke` **object fields** {#grant-revoke}

| Parameter | Description | Data type |
| -------- | -------- | ---------- |
| [READ](#read-write-req) | Object with details about users, groups, or roles for whom you want to grant or revoke view access to the entity | Object |
| [GRANT](#read-write-req) | Object with details about users, groups, or roles for whom you want to grant or revoke access management permissions | Object |
| [WRITE](#read-write-req) | Object with details about users, groups, or roles for whom you want to grant or revoke edit access to the entity | Object |

`READ`, `GRANT`, and `WRITE` **object fields** {#read-write-req}

#|
|| Parameter | Description | Data type ||
|| users | User IDs or usernames for whom you want to grant or revoke this type of access | String or array of strings ||
|| groups | Group IDs for whom you want to grant or revoke this type of access | Number or array of numbers ||
|| roles | List of entity roles for which you want to grant or revoke this type of access:
* `AUTHOR`: Author.
* `OWNER`: Lead.
* `CLIENT`: Customer.
* `FOLLOWER`: Follower.
* `MEMBER`: Participants
| String or array of strings ||
|#

{% endcut %}

> Example 1: Enable access inheritance for a project from the main portfolio.
>
> ```json translate=no
> PATCH /v3/entities/project/655f8cc52*****/extendedPermissions
> Host: api.tracker.yandex.net
> Authorization: OAuth API_TOKEN
> Content-Type: application/json
> X-Org-ID or X-Cloud-Org-ID: ORGANIZATION_ID
>
> {
>    "permissionSources": "67ffd7e3********"
> }
> ```

> Example 2: Disable access inheritance for a project from the main portfolio and grant edit access to group with ID `2`.
>
> ```json translate=no
> PATCH /v3/entities/project/655f8cc52*****/extendedPermissions
> Host: api.tracker.yandex.net
> Authorization: OAuth API_TOKEN
> Content-Type: application/json
> X-Org-ID or X-Cloud-Org-ID: ORGANIZATION_ID
>
> {
>    "permissionSources": [],
>    "acl": {
>        "grant": {
>            "WRITE": {
>                "users": [],
>                "groups": 2,
>                "roles": []
>            }
>        }
>    }
> }
> ```


> Example 3: Grant read-only access to a project for the user with `username1`. You need to disable access inheritance from the main portfolio first.
>
> ```json translate=no
> PATCH /v3/entities/project/655f8cc52*****/extendedPermissions
> Host: api.tracker.yandex.net
> Authorization: OAuth API_TOKEN
> Content-Type: application/json
> X-Org-ID or X-Cloud-Org-ID: ORGANIZATION_ID
>
> {
>   "acl": {
>       "grant": {
>           "READ": {
>               "users": {"login": "username1"}
>           }
>       }
>   }
> }
> ```

## Response format {#answer}

{% list tabs %}

- Request executed successfully

   <!-- source: en/api/_includes/answer-200.md -->
   If the request is successful, the API returns a response with code `200 OK`.
   <!-- endsource: en/api/_includes/answer-200.md -->

   The response body contains information about the entity's access settings in JSON format.

   <!-- source: en/api/_includes/entity-access.md -->
   ```json translate=no
   {
       "acl": {
           "READ": {
               "users": [
                   {
                       "self": "https://api.tracker.yandex.net/v3/users/11********",
                       "id": "11********",
                       "display": "User Name",
                       "passportUid": 11********
                   }
               ],
               "groups": [
                   {
                       "self": "https://api.tracker.yandex.net/v3/groups/1",
                       "id": "1",
                       "display": "Group 1"
                   }
               ],
               "roles": []
           },
           "GRANT": {
               "users": [],
               "groups": [
                   {
                       "self": "https://api.tracker.yandex.net/v3/groups/2",
                       "id": "2",
                       "display": "Group 2"
                   }
               ],
               "roles": [
                   "AUTHOR",
                   "OWNER"
               ]
           },
           "WRITE": {
               "users": [],
               "groups": [
                   {
                       "self": "https://api.tracker.yandex.net/v3/groups/3",
                       "id": "3",
                       "display": "Group 3"
                   }
               ],
               "roles": [
                   "CLIENT",
                   "AUTHOR",
                   "FOLLOWER",
                   "OWNER",
                   "MEMBER"
               ]
           }
       },
       "permissionSources": [
           {
               "self": "https://api.tracker.yandex.net/v3/entities/portfolio/67ffd7e3********",
               "id": "67ffd7e3********",
               "display": "My portfolio"
           }
       ],
       "parentEntities": {
           "primary": {
               "self": "https://api.tracker.yandex.net/v3/entities/portfolio/67ffd7e3********",
               "id": "67ffd7e3********",
               "display": "My portfolio"
           },
           "secondary": []
       }
   }
   ```
   <!-- endsource: en/api/_includes/entity-access.md -->

   {% cut "Response parameters" %}

   <!-- source: en/api/_includes/entity-access.md -->
   | Parameter | Description | Data type |
   -------- | -------- | ----------
   | [acl](#acl) | An object detailing the users, groups, and roles with various access types for the entity | Object |
   | [permissionSources](#entity-id) | The parent entity (the main portfolio or parent goal) from which the current entity inherits its access permissions | Object |
   | [parentEntities](#parent) | A list of parent entities from which the current entity inherits access permissions | Object |
   <!-- endsource: en/api/_includes/entity-access.md -->

   `parentEntities` **object fields**{#parent}

   <!-- source: en/api/_includes/entity-fields.md -->
   | Parameter | Description | Data type |
   -------- | -------- | ----------
   | [primary](#entity-id) | The main portfolio (for projects and portfolios) or parent goal (for goals) | Object |
   | [secondary](#entity-id) | For projects and portfolios: a list of additional portfolios<br>For goals, the parameter value is always empty | Array of objects |

   {% note info "" %}

   If the request address specifies the API `v2`, the `parentEntity` object contains information only about the main portfolio or parent goal.

   {% endnote %}
   <!-- endsource: en/api/_includes/entity-fields.md -->

   **Fields of the object that contains entity data** {#entity-id}

   The `permissionSources`, `primary`, and `secondary` parameters contain objects with the following fields:

   <!-- source: en/api/_includes/entity-fields.md -->
   | Parameter | Description | Data type |
   -------- | -------- | ----------
   | self | Address of the API resource with information about the entity | String |
   | id | Entity ID | String |
   | display | Entity name | String |
   <!-- endsource: en/api/_includes/entity-fields.md -->

   **acl** `object fields` {#acl}

   <!-- source: en/api/_includes/entity-access.md -->
   | Parameter | Description | Data type |
   -------- | -------- | ----------
   | [READ](#read-write) | An object detailing the users, groups, and roles with view access to the entity | Object |
   | [GRANT](#read-write) | An object detailing the users, groups, and roles that can manage access settings for the entity | Object |
   | [WRITE](#read-write) | An object detailing the users, groups, and roles with edit access to the entity | Object |
   <!-- endsource: en/api/_includes/entity-access.md -->

   `READ`, `GRANT`, and `WRITE` **object fields** {#read-write}

   <!-- source: en/api/_includes/entity-access.md -->
   #|
   || Parameter | Description | Data type ||
   || [users](#users) | A list of users with this access type | Object array ||
   || [groups](#groups) | A list of groups with this access type | Object array ||
   || roles | A list of entity roles with this access type:
   * `AUTHOR`: Author.
   * `OWNER`: Lead.
   * `CLIENT`: Customer.
   * `FOLLOWER`: Follower.
   * `MEMBER` — Participants.
   | String array ||
   |#
   <!-- endsource: en/api/_includes/entity-access.md -->

   **Fields of objects in the** `users` array {#users}

   <!-- source: en/api/_includes/user.md -->
   | Parameter | Description | Data type |
   ----- | ----- | -----
   | self | Address of the API resource with information about the user | String |
   | id | User ID. | String |
   | display | Displayed user name | String |
   | passportUid | Unique ID of the user account in the Yandex 360 for Business organization and Yandex ID. | Number |
   | cloudUid | Unique user ID in Yandex Identity Hub | String |
   <!-- endsource: en/api/_includes/user.md -->

   **Fields of objects in the** `groups` array {#groups}

   <!-- source: en/api/_includes/group-short.md -->
   | Parameter | Description | Data type |
   ----- | ----- | -----
   self | The address of the API resource that contains information about the user group | String
   id | Group ID | String
   display | Group display name | String
   <!-- endsource: en/api/_includes/group-short.md -->

   {% endcut %}

- Request failed

   If the request is processed incorrectly, the API returns a response with an error code:

   <!-- source: en/api/_includes/answer-error-400.md -->
   400
   :   One or more request parameters have an invalid value.
   <!-- endsource: en/api/_includes/answer-error-400.md -->

   <!-- source: en/api/_includes/answer-error-401.md -->
   401
   :   The user is not authorized. Make sure that actions described in the [API access](https://www.yandex.ru/support/tracker/en/api/access.md) section are performed.
   <!-- endsource: en/api/_includes/answer-error-401.md -->

   <!-- source: en/api/_includes/answer-error-403.md -->
   403
   :   You are not authorized to perform this action. You can check what rights you have in the Tracker interface. The same rights are required to perform an action via the API and interface.
   <!-- endsource: en/api/_includes/answer-error-403.md -->

   <!-- source: en/api/_includes/answer-error-404.md -->
   404
   :   The requested object was not found. You may have specified an invalid object ID or key.
   <!-- endsource: en/api/_includes/answer-error-404.md -->

   <!-- source: en/api/_includes/answer-error-412.md -->
   412
   :   A conflict occurred while editing the object. The error may be due to an invalid update version.
   <!-- endsource: en/api/_includes/answer-error-412.md -->

   <!-- source: en/api/_includes/answer-error-423.md -->
   423
   :   Object edits disabled. The `version` parameter value limit (the maximum number of object updates) might have been exceeded. The maximum version value is `10100` for robots and `11100` for users.
   <!-- endsource: en/api/_includes/answer-error-423.md -->

   <!-- source: en/api/_includes/answer-error-428.md -->
   428
   :   Access to the resource is denied. Make sure all required conditions for the request are specified.
   <!-- endsource: en/api/_includes/answer-error-428.md -->


{% endlist %}
