Skip to main content
Pinecone Docs

Search documentation

Type to search this documentation.

Create a role binding

POST/admin/role-bindingsCreate a role binding

Grant a role to a principal at an organization or project scope.

Parameters

X-Pinecone-Api-Versionstringheaderrequired

Required date-based version header

default "2026-07"

Request body

required

Principal, resource scope, and role to bind.

application/json
objectCreateRoleBindingRequest
principal_idstringrequired

Principal ID. Format depends on `principal_type`.

principal_typestringrequired

The kind of principal that receives permissions from a role binding. Possible values: `user`, `service_account`, `api_key`, `invite`.

resource_idstring

Project UUID. Required when `resource_type` is `project`; omit for `organization` scope.

resource_typestringrequired

The kind of resource scope a role binding applies to. Possible values: `organization`, `project`.

rolestringrequired

A role assigned to a principal at a resource scope.

Example request
{
  "principal_id": "f8a3b2c1-4d5e-6f7a-8b9c-0d1e2f3a4b5c",
  "principal_type": "service_account",
  "resource_id": "a2f7dddb-1597-4eff-9f71-535fde243f58",
  "resource_type": "project",
  "role": "DataPlaneEditor"
}

Responses

200Role binding created.application/json
objectRoleBinding

Grants a `role` to a `principal` at a `resource` scope.

created_atstring · date-timerequired

When the role binding was created.

idstring · uuidrequired

The unique ID of the role binding.

principal_idstringrequired

The principal's ID. A UUID for all principal types (`user`, `service_account`, `api_key`, `invite`).

principal_typestringrequired

The kind of principal that receives permissions from a role binding. Possible values: `user`, `service_account`, `api_key`, `invite`.

resource_idstringrequired

The organization or project that the binding is scoped to.

resource_typestringrequired

The kind of resource scope a role binding applies to. Possible values: `organization`, `project`.

rolestringrequired

A role assigned to a principal at a resource scope.

Example response
{
  "created_at": "2026-04-10T15:23:00Z",
  "id": "9a8e3528-b9c0-4358-84ce-84c28e91b566",
  "principal_id": "f8a3b2c1-4d5e-6f7a-8b9c-0d1e2f3a4b5c",
  "principal_type": "service_account",
  "resource_id": "a2f7dddb-1597-4eff-9f71-535fde243f58",
  "resource_type": "project",
  "role": "DataPlaneEditor"
}
400Bad request. The request body included invalid request parameters.application/json
objectErrorResponse

The response shape used for all error responses.

errorobjectrequired

Detailed information about the error that occurred.

Show child attributes
codestringrequired

The error code. Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`, `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`, `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`, `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`, `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`, `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.

detailsobject

Additional information about the error. This field is not guaranteed to be present.

messagestringrequired
statusintegerrequired

The HTTP status code of the error.

Example response
{
  "error": {
    "code": "INVALID_ARGUMENT",
    "message": "Bad request. The request body included invalid request parameters."
  },
  "status": 400
}
401Unauthorized. Possible causes: Invalid API key.application/json
objectErrorResponse

The response shape used for all error responses.

errorobjectrequired

Detailed information about the error that occurred.

Show child attributes
codestringrequired

The error code. Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`, `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`, `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`, `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`, `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`, `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.

detailsobject

Additional information about the error. This field is not guaranteed to be present.

messagestringrequired
statusintegerrequired

The HTTP status code of the error.

Example response
{
  "error": {
    "code": "UNAUTHENTICATED",
    "message": "Invalid API key."
  },
  "status": 401
}
403Forbiddenapplication/json
objectErrorResponse

The response shape used for all error responses.

errorobjectrequired

Detailed information about the error that occurred.

Show child attributes
codestringrequired

The error code. Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`, `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`, `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`, `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`, `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`, `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.

detailsobject

Additional information about the error. This field is not guaranteed to be present.

messagestringrequired
statusintegerrequired

The HTTP status code of the error.

Example response
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
404Not foundapplication/json
objectErrorResponse

The response shape used for all error responses.

errorobjectrequired

Detailed information about the error that occurred.

Show child attributes
codestringrequired

The error code. Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`, `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`, `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`, `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`, `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`, `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.

detailsobject

Additional information about the error. This field is not guaranteed to be present.

messagestringrequired
statusintegerrequired

The HTTP status code of the error.

Example response
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
409Conflict. The request conflicts with the persisted state of the resource. Common causes include invariant violations (e.g., removing the last `OrgOwner`), lifecycle-state mismatches (e.g., resending an invite that is not pending), and constraint violations checked against persisted data.application/json
objectErrorResponse

The response shape used for all error responses.

errorobjectrequired

Detailed information about the error that occurred.

Show child attributes
codestringrequired

The error code. Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`, `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`, `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`, `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`, `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`, `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.

detailsobject

Additional information about the error. This field is not guaranteed to be present.

messagestringrequired
statusintegerrequired

The HTTP status code of the error.

Example response
{
  "error": {
    "code": "ALREADY_EXISTS",
    "message": "This email already belongs to a member of the organization."
  },
  "status": 409
}
4XXUnexpected error on request.application/json
objectErrorResponse

The response shape used for all error responses.

errorobjectrequired

Detailed information about the error that occurred.

Show child attributes
codestringrequired

The error code. Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`, `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`, `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`, `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`, `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`, `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.

detailsobject

Additional information about the error. This field is not guaranteed to be present.

messagestringrequired
statusintegerrequired

The HTTP status code of the error.

Example response
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
500Internal server error.application/json
objectErrorResponse

The response shape used for all error responses.

errorobjectrequired

Detailed information about the error that occurred.

Show child attributes
codestringrequired

The error code. Possible values: `OK`, `UNKNOWN`, `INVALID_ARGUMENT`, `DEADLINE_EXCEEDED`, `QUOTA_EXCEEDED`, `NOT_FOUND`, `ALREADY_EXISTS`, `PERMISSION_DENIED`, `UNAUTHENTICATED`, `RESOURCE_EXHAUSTED`, `FAILED_PRECONDITION`, `ABORTED`, `OUT_OF_RANGE`, `UNIMPLEMENTED`, `INTERNAL`, `UNAVAILABLE`, `DATA_LOSS`, `FORBIDDEN`, or `UNPROCESSABLE_ENTITY`.

detailsobject

Additional information about the error. This field is not guaranteed to be present.

messagestringrequired
statusintegerrequired

The HTTP status code of the error.

Example response
{
  "error": {
    "code": "UNKNOWN",
    "message": "Internal server error"
  },
  "status": 500
}
Documentation menu