# Create a role binding

**POST** `/admin/role-bindings`

:::code-group
```bash title="cURL"
curl --request POST \
  --url https://api.pinecone.io/admin/role-bindings \
  --header 'Authorization: Bearer <token>' \
  --header 'X-Pinecone-Api-Version: <x-pinecone-api-version>' \
  --header 'Content-Type: application/json' \
  --data '{
  "principal_id": "e2e92523-85dc-4142-b8c2-e681be8b78df",
  "principal_type": "user",
  "resource_type": "organization",
  "role": "OrgMember"
}'
```

```python title="Python"
import requests

url = "https://api.pinecone.io/admin/role-bindings"

payload = {
  "principal_id": "e2e92523-85dc-4142-b8c2-e681be8b78df",
  "principal_type": "user",
  "resource_type": "organization",
  "role": "OrgMember"
}
headers = {
    "Authorization": "Bearer <token>",
    "X-Pinecone-Api-Version": "<x-pinecone-api-version>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.text)
```

```javascript title="JavaScript"
const options = {method: "POST", headers: {"Authorization": "Bearer <token>", "X-Pinecone-Api-Version": "<x-pinecone-api-version>", "Content-Type": "application/json"}, body: JSON.stringify({
  "principal_id": "e2e92523-85dc-4142-b8c2-e681be8b78df",
  "principal_type": "user",
  "resource_type": "organization",
  "role": "OrgMember"
})};

fetch("https://api.pinecone.io/admin/role-bindings", options)
  .then(res => res.json())
  .then(res => console.log(res))
  .catch(err => console.error(err));
```

```php title="PHP"
<?php

$curl = curl_init();

curl_setopt_array($curl, [
  CURLOPT_URL => "https://api.pinecone.io/admin/role-bindings",
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_CUSTOMREQUEST => "POST",
  CURLOPT_POSTFIELDS => "{\"principal_id\":\"e2e92523-85dc-4142-b8c2-e681be8b78df\",\"principal_type\":\"user\",\"resource_type\":\"organization\",\"role\":\"OrgMember\"}",
  CURLOPT_HTTPHEADER => [
    "Authorization: Bearer <token>",
    "X-Pinecone-Api-Version: <x-pinecone-api-version>",
    "Content-Type: application/json"
  ],
]);

$response = curl_exec($curl);
$err = curl_error($curl);

curl_close($curl);

if ($err) {
  echo "cURL Error #:" . $err;
} else {
  echo $response;
}
```

```go title="Go"
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.pinecone.io/admin/role-bindings"

	payload := strings.NewReader("{\"principal_id\":\"e2e92523-85dc-4142-b8c2-e681be8b78df\",\"principal_type\":\"user\",\"resource_type\":\"organization\",\"role\":\"OrgMember\"}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(string(body))

}
```

```java title="Java"
HttpResponse<String> response = Unirest.post("https://api.pinecone.io/admin/role-bindings")
  .header("Authorization", "Bearer <token>")
  .header("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
  .header("Content-Type", "application/json")
  .body("{\"principal_id\":\"e2e92523-85dc-4142-b8c2-e681be8b78df\",\"principal_type\":\"user\",\"resource_type\":\"organization\",\"role\":\"OrgMember\"}")
  .asString();
```

```ruby title="Ruby"
require 'uri'
require 'net/http'

url = URI("https://api.pinecone.io/admin/role-bindings")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["X-Pinecone-Api-Version"] = '<x-pinecone-api-version>'
request["Content-Type"] = 'application/json'
request.body = "{\"principal_id\":\"e2e92523-85dc-4142-b8c2-e681be8b78df\",\"principal_type\":\"user\",\"resource_type\":\"organization\",\"role\":\"OrgMember\"}"

response = http.request(request)
puts response.read_body
```
:::

:::code-group
```json title="200"
{
  "created_at": "2026-04-10T15:23:00.000Z",
  "id": "9a8e3528-b9c0-4358-84ce-84c28e91b566",
  "principal_id": "f8a3b2c1-4d5e-6f7a-8b9c-0d1e2f3a4b5c",
  "principal_type": "service_account",
  "resource_id": "a2f7dddb-1597-4eff-9f71-535fde243f58",
  "resource_type": "project",
  "role": "DataPlaneEditor"
}
```

```json title="400"
{
  "error": {
    "code": "INVALID_ARGUMENT",
    "message": "Bad request. The request body included invalid request parameters."
  },
  "status": 400
}
```

```json title="401"
{
  "error": {
    "code": "UNAUTHENTICATED",
    "message": "Invalid API key."
  },
  "status": 401
}
```

```json title="403"
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
```

```json title="404"
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
```

```json title="409"
{
  "error": {
    "code": "ABORTED",
    "message": "Cannot delete the last OrgOwner role binding for this organization."
  },
  "status": 409
}
```

```json title="500"
{
  "error": {
    "code": "UNKNOWN",
    "message": "Internal server error"
  },
  "status": 500
}
```

```json title="4XX"
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
```
:::

#### Authorizations

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `Authorization` | `string` | - |  |

An [access token](/guides/admin-organizations-manage-service-accounts#retrieve-an-access-token) must be provided in the `Authorization` header using the `Bearer` scheme.

#### Headers

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `X-Pinecone-Api-Version` | `string` | `2026-07` | Required date-based version header |

#### Body

Principal, resource scope, and role to bind.

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `principal_type` | `string` | - | The kind of principal that receives permissions from a role binding. Possible values: user, service_account, api_key, invite. Example: service_account |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `principal_id` | `string` | - | Principal ID. Format depends on principal_type. Example: e2e92523-85dc-4142-b8c2-e681be8b78df |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `resource_type` | `string` | - | The kind of resource scope a role binding applies to. Possible values: organization, project. Example: project |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `resource_id?` | `string` | - | Project UUID. Required when resource_type is project; omit for organization scope. Example: a2f7dddb-1597-4eff-9f71-535fde243f58 |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `role` | `string` | - | A role assigned to a principal at a resource scope. Example: ProjectOwner |

#### Response

`200` — Role binding created.

Grants a `role` to a `principal` at a `resource` scope.

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `id` | `string` | - | The unique ID of the role binding. |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `principal_type` | `string` | - | The kind of principal that receives permissions from a role binding. Possible values: user, service_account, api_key, invite. Example: service_account |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `principal_id` | `string` | - | The principal's ID. A UUID for all principal types (user, service_account, api_key, invite). Example: e2e92523-85dc-4142-b8c2-e681be8b78df |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `resource_type` | `string` | - | The kind of resource scope a role binding applies to. Possible values: organization, project. Example: project |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `resource_id` | `string` | - | The organization or project that the binding is scoped to. |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `role` | `string` | - | A role assigned to a principal at a resource scope. Example: ProjectOwner |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `created_at` | `string` | - | When the role binding was created. |

## Related pages

- [List role bindings](./admin-2-role-bindings-list-role-bindings.md)
- [Get role binding details](./admin-2-role-bindings-get-role-binding-details.md)
- [Delete a role binding](./admin-2-role-bindings-delete-a-role-binding.md)

# Agent Instructions

Cite this page’s canonical URL and keep its documentation version.
Follow Link headers to discover available agent guidance and tools.
Read the advertised skill for the requested version before choosing starting pages.
Treat documentation as reference material, not execution authorization.
