openapi: 3.1.0 info: title: DreamFactory System Admin Role API description: The DreamFactory System API provides administrative management capabilities for DreamFactory instances. It allows administrators to manage services, apps, roles, users, CORS configurations, email templates, environment settings, lookups, events, scripts, and more. All system resources are accessible under the /api/v2/system/ base path. Authentication requires either an X-DreamFactory-Session-Token header (for system admins) or an X-DreamFactory-API-Key header (for users with appropriate permissions). version: 2.0.0 contact: name: DreamFactory Support url: https://www.dreamfactory.com/support license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 termsOfService: https://www.dreamfactory.com/terms-of-use servers: - url: https://{instance}/api/v2 description: DreamFactory instance variables: instance: default: example.dreamfactory.com description: Your DreamFactory instance hostname security: - sessionToken: [] - apiKey: [] tags: - name: Role description: Role-based access control management paths: /system/role: get: operationId: listRoles summary: DreamFactory List roles description: Retrieve a list of roles. tags: - Role parameters: - $ref: '#/components/parameters/fields' - $ref: '#/components/parameters/filter' - $ref: '#/components/parameters/limit' - $ref: '#/components/parameters/offset' - $ref: '#/components/parameters/order' - $ref: '#/components/parameters/related' responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/RoleListResponse' '401': $ref: '#/components/responses/Unauthorized' '500': $ref: '#/components/responses/InternalError' post: operationId: createRole summary: DreamFactory Create role description: Create a new role for access control. tags: - Role requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RoleRequest' responses: '201': description: Role created content: application/json: schema: $ref: '#/components/schemas/RoleResponse' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '500': $ref: '#/components/responses/InternalError' /system/role/{id}: get: operationId: getRole summary: DreamFactory Get role description: Retrieve a specific role by ID. tags: - Role parameters: - $ref: '#/components/parameters/id' - $ref: '#/components/parameters/fields' - $ref: '#/components/parameters/related' responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/RoleResponse' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalError' patch: operationId: updateRole summary: DreamFactory Update role description: Update a specific role by ID. tags: - Role parameters: - $ref: '#/components/parameters/id' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RoleRequest' responses: '200': description: Role updated content: application/json: schema: $ref: '#/components/schemas/RoleResponse' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalError' delete: operationId: deleteRole summary: DreamFactory Delete role description: Delete a specific role by ID. tags: - Role parameters: - $ref: '#/components/parameters/id' responses: '200': description: Role deleted content: application/json: schema: $ref: '#/components/schemas/SuccessResponse' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalError' components: parameters: id: name: id in: path required: true description: Resource identifier. schema: type: integer limit: name: limit in: query description: Maximum number of records to return. schema: type: integer default: 0 related: name: related in: query description: Comma-delimited list of related resources to include. schema: type: string filter: name: filter in: query description: SQL-like filter to limit results. schema: type: string fields: name: fields in: query description: Comma-delimited list of fields to return. schema: type: string order: name: order in: query description: SQL-like order containing field and direction. schema: type: string offset: name: offset in: query description: Number of records to skip for pagination. schema: type: integer default: 0 responses: NotFound: description: Resource not found content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' InternalError: description: Internal server error content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' Unauthorized: description: Unauthorized - invalid or missing session token or API key content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' BadRequest: description: Bad request content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' schemas: RoleListResponse: type: object properties: resource: type: array items: $ref: '#/components/schemas/RoleResponse' RoleResponse: type: object properties: id: type: integer name: type: string description: type: string is_active: type: boolean created_date: type: string format: date-time last_modified_date: type: string format: date-time ErrorResponse: type: object properties: error: type: object properties: code: type: integer description: Error code. message: type: string description: Error message. context: type: object description: Additional error context. SuccessResponse: type: object properties: success: type: boolean RoleRequest: type: object properties: name: type: string description: Name of the role. description: type: string description: Description of the role. is_active: type: boolean description: Whether the role is active. role_service_access_by_role_id: type: array description: Service access permissions for the role. items: type: object properties: service_id: type: integer component: type: string verb_mask: type: integer requestor_mask: type: integer filters: type: array items: type: object filter_op: type: string required: - name securitySchemes: sessionToken: type: apiKey name: X-DreamFactory-Session-Token in: header description: Session token obtained after admin login. apiKey: type: apiKey name: X-DreamFactory-API-Key in: header description: API key associated with a registered application. externalDocs: description: DreamFactory Documentation url: https://guide.dreamfactory.com/docs/