Skip to content
You are reading the unreleased documentation. No version is released yet, and these pages describe code that is not in a release.

Permissions

Every permission is <module>:<action>; 26 modules and 5 actions. A role is a set of these strings, edited on the roles screen of the admin. The routes listed under a permission are the ones that check it; a permission with no route is accepted on a role but enforced nowhere.

  • view
  • create
  • update
  • delete
  • manage
  • admin_users:view: GET /v1/admin/roles, GET /v1/admin/staff
  • admin_users:create: POST /v1/admin/staff
  • admin_users:update: PATCH /v1/admin/staff/:id
  • admin_users:delete: DELETE /v1/admin/staff/:id
  • admin_users:manage: PATCH /v1/admin/roles/:id, POST /v1/admin/roles
  • analytics:view: GET /v1/admin/analytics/customers, GET /v1/admin/analytics/dashboard, GET /v1/admin/analytics/funnel, GET /v1/admin/analytics/pixels, GET /v1/admin/analytics/products, GET /v1/admin/analytics/revenue, GET /v1/admin/analytics/search, GET /v1/admin/analytics/timeseries, GET /v1/admin/search/analytics, GET /v1/admin/search/zero-results
  • analytics:create (no route checks it)
  • analytics:update (no route checks it)
  • analytics:delete (no route checks it)
  • analytics:manage: PATCH /v1/admin/analytics/pixels
  • assets:view: GET /v1/admin/assets, GET /v1/admin/assets/:id, GET /v1/admin/assets/:id/original-url, GET /v1/admin/assets/:id/references
  • assets:create: POST /v1/admin/assets/upload
  • assets:update (no route checks it)
  • assets:delete: DELETE /v1/admin/assets/:id
  • assets:manage (no route checks it)
  • audit_log:view: GET /v1/admin/audit-log, GET /v1/admin/audit-log/:entityType/:entityId
  • audit_log:create (no route checks it)
  • audit_log:update (no route checks it)
  • audit_log:delete (no route checks it)
  • audit_log:manage (no route checks it)
  • campaigns:view: GET /v1/admin/campaigns, GET /v1/admin/campaigns/:id, GET /v1/admin/campaigns/:id/stats, GET /v1/admin/subscribers, POST /v1/admin/campaigns/:id/preview
  • campaigns:create: POST /v1/admin/campaigns
  • campaigns:update: PATCH /v1/admin/campaigns/:id
  • campaigns:delete: DELETE /v1/admin/campaigns/:id
  • campaigns:manage: PATCH /v1/admin/subscribers/:id, POST /v1/admin/campaigns/:id/send, POST /v1/admin/campaigns/:id/test
  • carriers:view: GET /v1/admin/carriers, GET /v1/admin/carriers/:id
  • carriers:create: POST /v1/admin/carriers
  • carriers:update: PATCH /v1/admin/carriers/:id
  • carriers:delete: DELETE /v1/admin/carriers/:id
  • carriers:manage (no route checks it)
  • categories:view: GET /v1/admin/categories
  • categories:create: POST /v1/admin/categories
  • categories:update: PATCH /v1/admin/categories/:id, PATCH /v1/admin/categories/reorder
  • categories:delete: DELETE /v1/admin/categories/:id
  • categories:manage (no route checks it)
  • checkout:view: GET /v1/admin/checkout/settings
  • checkout:create (no route checks it)
  • checkout:update (no route checks it)
  • checkout:delete (no route checks it)
  • checkout:manage: PATCH /v1/admin/checkout/settings
  • cms:view: GET /v1/admin/pages
  • cms:create: POST /v1/admin/pages
  • cms:update: PATCH /v1/admin/pages/:id
  • cms:delete: DELETE /v1/admin/pages/:id
  • cms:manage (no route checks it)
  • customers:view: GET /v1/admin/customers, GET /v1/admin/customers/:id, GET /v1/admin/customers/segments
  • customers:create (no route checks it)
  • customers:update: PATCH /v1/admin/customers/:id
  • customers:delete (no route checks it)
  • customers:manage (no route checks it)
  • geo:view: GET /v1/admin/geo/ai-readiness, GET /v1/admin/geo/products/:productId/faqs/suggestions
  • geo:create: POST /v1/admin/geo/products/:productId/faqs/accept
  • geo:update (no route checks it)
  • geo:delete (no route checks it)
  • geo:manage (no route checks it)
  • gift_cards:view: GET /v1/admin/gift-cards, GET /v1/admin/gift-cards/:id
  • gift_cards:create: POST /v1/admin/gift-cards
  • gift_cards:update: PATCH /v1/admin/gift-cards/:id, POST /v1/admin/gift-cards/:id/adjust, POST /v1/admin/gift-cards/:id/resend
  • gift_cards:delete (no route checks it)
  • gift_cards:manage (no route checks it)
  • inventory:view: GET /v1/admin/inventory, GET /v1/admin/inventory/alerts, GET /v1/admin/inventory/locations, GET /v1/admin/inventory/movements, GET /v1/admin/inventory/variant/:variantId, GET /v1/admin/products/:id/stock
  • inventory:create: POST /v1/admin/inventory/locations
  • inventory:update: PATCH /v1/admin/inventory/adjust, PATCH /v1/admin/inventory/locations/:id, POST /v1/admin/inventory/transfer
  • inventory:delete: DELETE /v1/admin/inventory/locations/:id
  • inventory:manage (no route checks it)
  • license:view: GET /v1/admin/license
  • license:create (no route checks it)
  • license:update (no route checks it)
  • license:delete (no route checks it)
  • license:manage: POST /v1/admin/license/install
  • notifications:view: GET /v1/admin/notifications, GET /v1/admin/notifications/log, GET /v1/admin/notifications/templates, GET /v1/admin/notifications/templates/:id, GET /v1/admin/notifications/unread-count, POST /v1/admin/notifications/templates/:id/preview
  • notifications:create (no route checks it)
  • notifications:update (no route checks it)
  • notifications:delete (no route checks it)
  • notifications:manage: DELETE /v1/admin/notifications/templates/:id, PATCH /v1/admin/notifications/:id/read, PATCH /v1/admin/notifications/read-all, PATCH /v1/admin/notifications/templates/:id, POST /v1/admin/notifications/log/:id/resend, POST /v1/admin/notifications/templates, POST /v1/admin/notifications/templates/:id/send-test
  • orders:view: GET /v1/admin/orders, GET /v1/admin/orders/:id, GET /v1/admin/orders/:id/invoice, GET /v1/admin/orders/:id/invoice/pdf, GET /v1/admin/orders/export, GET /v1/admin/orders/stats
  • orders:create: POST /v1/admin/orders
  • orders:update: PATCH /v1/admin/orders/:id, PATCH /v1/admin/orders/:id/shipments/:sid, PATCH /v1/admin/orders/:id/status, POST /v1/admin/orders/:id/notes, POST /v1/admin/orders/:id/shipments
  • orders:delete (no route checks it)
  • orders:manage (no route checks it)
  • payment_methods:view: GET /v1/admin/payment-methods, GET /v1/admin/payment-methods/:id
  • payment_methods:create: POST /v1/admin/payment-methods
  • payment_methods:update: PATCH /v1/admin/payment-methods/:id, POST /v1/admin/payment-methods/reorder
  • payment_methods:delete: DELETE /v1/admin/payment-methods/:id
  • payment_methods:manage (no route checks it)
  • products:view: GET /v1/admin/attributes, GET /v1/admin/product-specs/labels, GET /v1/admin/product-types, GET /v1/admin/products, GET /v1/admin/products/:id, GET /v1/admin/storefront/public-config
  • products:create: POST /v1/admin/attributes, POST /v1/admin/attributes/:id/values, POST /v1/admin/product-types, POST /v1/admin/products, POST /v1/admin/products/:id/faqs, POST /v1/admin/products/:id/variants
  • products:update: DELETE /v1/admin/search/merchandising/:id, DELETE /v1/admin/search/synonyms/:id, GET /v1/admin/search/merchandising, GET /v1/admin/search/synonyms, PATCH /v1/admin/attributes/:id, PATCH /v1/admin/attributes/:id/values/:valueId, PATCH /v1/admin/product-types/:id, PATCH /v1/admin/products/:id, PATCH /v1/admin/products/:id/assets, PATCH /v1/admin/products/:id/faqs/:faqId, PATCH /v1/admin/products/:id/restore, PATCH /v1/admin/products/:id/variants/:variantId, PATCH /v1/admin/products/bulk/prices, PATCH /v1/admin/products/bulk/status, POST /v1/admin/search/merchandising, POST /v1/admin/search/synonyms, PUT /v1/admin/products/:id/specs
  • products:delete: DELETE /v1/admin/attributes/:id, DELETE /v1/admin/attributes/:id/values/:valueId, DELETE /v1/admin/product-types/:id, DELETE /v1/admin/products/:id, DELETE /v1/admin/products/:id/faqs/:faqId, DELETE /v1/admin/products/:id/variants/:variantId
  • products:manage: POST /v1/admin/search/reindex
  • promotions:view: GET /v1/admin/promotions, GET /v1/admin/promotions/:id
  • promotions:create: POST /v1/admin/promotions
  • promotions:update: PATCH /v1/admin/promotions/:id
  • promotions:delete: DELETE /v1/admin/promotions/:id
  • promotions:manage (no route checks it)
  • returns:view: GET /v1/admin/returns, GET /v1/admin/returns/:id, GET /v1/admin/returns/analytics
  • returns:create (no route checks it)
  • returns:update: PATCH /v1/admin/returns/:id/approve, PATCH /v1/admin/returns/:id/close, PATCH /v1/admin/returns/:id/receive, PATCH /v1/admin/returns/:id/refund, PATCH /v1/admin/returns/:id/reject
  • returns:delete (no route checks it)
  • returns:manage (no route checks it)
  • reviews:view: GET /v1/admin/questions, GET /v1/admin/reviews
  • reviews:create (no route checks it)
  • reviews:update: PATCH /v1/admin/questions/:id/approve, PATCH /v1/admin/questions/:id/reject, PATCH /v1/admin/reviews/:id, PATCH /v1/admin/reviews/:id/approve, PATCH /v1/admin/reviews/:id/reject, POST /v1/admin/questions/:id/answer
  • reviews:delete: DELETE /v1/admin/reviews/:id
  • reviews:manage (no route checks it)
  • search:view: GET /v1/admin/search
  • search:create (no route checks it)
  • search:update (no route checks it)
  • search:delete (no route checks it)
  • search:manage (no route checks it)
  • seo:view: GET /v1/admin/seo/analytics, GET /v1/admin/seo/coverage, GET /v1/admin/seo/health, GET /v1/admin/seo/quota, GET /v1/admin/seo/redirects, GET /v1/admin/seo/submissions, GET /v1/admin/seo/url-inspection
  • seo:create: POST /v1/admin/seo/redirects
  • seo:update (no route checks it)
  • seo:delete: DELETE /v1/admin/seo/redirects/:id
  • seo:manage: POST /v1/admin/seo/health/recheck, POST /v1/admin/seo/submit
  • settings:view: GET /v1/admin/countries, GET /v1/admin/currencies, GET /v1/admin/settings, GET /v1/admin/settings/locales, GET /v1/admin/tax/classes, GET /v1/admin/tax/zones, GET /v1/admin/tax/zones/:id, GET /v1/admin/webhooks, GET /v1/admin/webhooks/:id, GET /v1/admin/webhooks/:id/deliveries
  • settings:create (no route checks it)
  • settings:update (no route checks it)
  • settings:delete (no route checks it)
  • settings:manage: DELETE /v1/admin/webhooks/:id, PATCH /v1/admin/countries, PATCH /v1/admin/currencies, PATCH /v1/admin/settings, PATCH /v1/admin/settings/locales, PATCH /v1/admin/tax/zones/:id, PATCH /v1/admin/webhooks/:id, POST /v1/admin/tax/classes, POST /v1/admin/tax/zones, POST /v1/admin/webhooks, POST /v1/admin/webhooks/:id/test
  • shipping:view: GET /v1/admin/shipping/methods, GET /v1/admin/shipping/zones
  • shipping:create: POST /v1/admin/shipping/methods, POST /v1/admin/shipping/zones
  • shipping:update: PATCH /v1/admin/shipping/methods/:id, PATCH /v1/admin/shipping/zones/:id
  • shipping:delete: DELETE /v1/admin/shipping/methods/:id
  • shipping:manage (no route checks it)
  • storefront_config:view: GET /v1/admin/storefront/pages, GET /v1/admin/storefront/pages/:pageSlug(*)/sections
  • storefront_config:create (no route checks it)
  • storefront_config:update (no route checks it)
  • storefront_config:delete (no route checks it)
  • storefront_config:manage: DELETE /v1/admin/storefront/sections/:id, PATCH /v1/admin/storefront/pages/:pageSlug(*)/sections/reorder, PATCH /v1/admin/storefront/sections/:id, PATCH /v1/admin/storefront/sections/:id/visibility, POST /v1/admin/storefront/pages/:pageSlug(*)/sections