> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blindsight.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Put User Permission Overrides

> Grant or withdraw permissions for one person, on top of their roles.

Gated on ``users.assign_roles`` rather than ``users.edit``: this hands out
capability exactly as assigning a role does, and gating it on the weaker
grant would make the role rule pointless. It is bounded further by
:func:`permissions_actor_cannot_grant`, nobody can give away more than
they hold, and the role-escalating permissions never travel this way.



## OpenAPI

````yaml /api-reference/openapi.json put /api/users/{user_id}/permissions
openapi: 3.1.0
info:
  title: Blindsight API
  version: 0.1.0
  description: >-
    The full Blindsight REST surface, generated from the running application.
    Replace the server host with your own deployment.


    For the Runtime Security integration surface (scan, proxy, tool calls) see
    the Runtime Security spec, which is hand written and carries worked
    examples.
servers:
  - url: https://api.your-blindsight.com
    description: Your Blindsight deployment
security: []
paths:
  /api/users/{user_id}/permissions:
    put:
      tags:
        - users
      summary: Put User Permission Overrides
      description: >-
        Grant or withdraw permissions for one person, on top of their roles.


        Gated on ``users.assign_roles`` rather than ``users.edit``: this hands
        out

        capability exactly as assigning a role does, and gating it on the weaker

        grant would make the role rule pointless. It is bounded further by

        :func:`permissions_actor_cannot_grant`, nobody can give away more than

        they hold, and the role-escalating permissions never travel this way.
      operationId: put_user_permission_overrides_api_users__user_id__permissions_put
      parameters:
        - name: user_id
          in: path
          required: true
          schema:
            type: integer
            title: User Id
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UserPermissionOverridesUpdate'
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UserPermissionsResponse'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    UserPermissionOverridesUpdate:
      properties:
        granted:
          items:
            type: string
          type: array
          title: Granted
          default: []
        revoked:
          items:
            type: string
          type: array
          title: Revoked
          default: []
      type: object
      title: UserPermissionOverridesUpdate
      description: >-
        Per-person adjustments on top of what this person's roles carry.


        Both lists are absolute, not deltas: what is sent is what the person
        ends up

        with, so removing a key from ``granted`` withdraws that grant.
    UserPermissionsResponse:
      properties:
        user_id:
          type: integer
          title: User Id
        roles:
          items:
            type: string
          type: array
          title: Roles
        from_roles:
          items:
            type: string
          type: array
          title: From Roles
        granted:
          items:
            type: string
          type: array
          title: Granted
        revoked:
          items:
            type: string
          type: array
          title: Revoked
        effective:
          items:
            type: string
          type: array
          title: Effective
      type: object
      required:
        - user_id
        - roles
        - from_roles
        - granted
        - revoked
        - effective
      title: UserPermissionsResponse
      description: One person's permissions, and where each one came from.
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError

````