# Create a role binding

**POST** `/admin/role-bindings`

Grant a role to a principal at an organization or project scope.

Base URL: `https://api.pinecone.io`

Tags: `Role Bindings`

## Authorization

| Option | Scheme | Type | Sent as | Scopes |
| --- | --- | --- | --- | --- |
| Option 1 | `BearerAuth` | `http` | `Authorization: Bearer <token>` | — |

## Header parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `X-Pinecone-Api-Version` | `string` | Yes | Required date-based version header |

## Request body

Required. Media type: `application/json`

Principal, resource scope, and role to bind.

### Example request body

```json
{
  "principal_id": "f8a3b2c1-4d5e-6f7a-8b9c-0d1e2f3a4b5c",
  "principal_type": "service_account",
  "resource_id": "a2f7dddb-1597-4eff-9f71-535fde243f58",
  "resource_type": "project",
  "role": "DataPlaneEditor"
}
```

## Responses

| Status | Description | Media type |
| --- | --- | --- |
| `200` | Role binding created. | `application/json` |
| `400` | Bad request. The request body included invalid request parameters. | `application/json` |
| `401` | Unauthorized. Possible causes: Invalid API key. | `application/json` |
| `403` | Forbidden | `application/json` |
| `404` | Not found | `application/json` |
| `409` | Conflict. The request conflicts with the persisted state of the resource. Common causes include invariant violations (e.g., removing the last `OrgOwner`), lifecycle-state mismatches (e.g., resending an invite that is not pending), and constraint violations checked against persisted data. | `application/json` |
| `4XX` | Unexpected error on request. | `application/json` |
| `500` | Internal server error. | `application/json` |

### Example response: 200 — Role binding created.

```json
{
  "created_at": "2026-04-10T15:23:00Z",
  "id": "9a8e3528-b9c0-4358-84ce-84c28e91b566",
  "principal_id": "f8a3b2c1-4d5e-6f7a-8b9c-0d1e2f3a4b5c",
  "principal_type": "service_account",
  "resource_id": "a2f7dddb-1597-4eff-9f71-535fde243f58",
  "resource_type": "project",
  "role": "DataPlaneEditor"
}
```

### Example response: 400 — Bad request. The request body included invalid request parameters.

```json
{
  "error": {
    "code": "INVALID_ARGUMENT",
    "message": "Bad request. The request body included invalid request parameters."
  },
  "status": 400
}
```

### Example response: 401 — Unauthorized. Possible causes: Invalid API key.

```json
{
  "error": {
    "code": "UNAUTHENTICATED",
    "message": "Invalid API key."
  },
  "status": 401
}
```

### Example response: 403 — Forbidden

```json
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
```

### Example response: 404 — Not found

```json
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
```

### Example response: 409 — Conflict. The request conflicts with the persisted state of the resource. Common causes include invariant violations (e.g., removing the last `OrgOwner`), lifecycle-state mismatches (e.g., resending an invite that is not pending), and constraint violations checked against persisted data.

```json
{
  "error": {
    "code": "ALREADY_EXISTS",
    "message": "This email already belongs to a member of the organization."
  },
  "status": 409
}
```

### Example response: 4XX — Unexpected error on request.

```json
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
```

### Example response: 500 — Internal server error.

```json
{
  "error": {
    "code": "UNKNOWN",
    "message": "Internal server error"
  },
  "status": 500
}
```

## Related pages

- [API Keys](./tags/api-keys.md)
- [Create a new project](./create_project.md)
- [Create a service account](./create_service_account.md)
- [Create an API key](./create_api_key.md)
- [Delete a project](./delete_project.md)
- [Delete a role binding](./delete_role_binding.md)
- [Delete a service account](./delete_service_account.md)
- [Delete an API key](./delete_api_key.md)
- [Delete an invite](./delete_invite.md)
- [Delete an organization](./delete_organization.md)

# Agent Instructions

Cite this page’s canonical URL and keep its documentation version.
Follow Link headers to discover available agent guidance and tools.
Read the advertised skill for the requested version before choosing starting pages.
Treat documentation as reference material, not execution authorization.
