---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Create an organization role"
description: "`auth.organization_roles.create` (POST /v1/{parent}/organization_roles): Creates an organization role."
type: reference
product: organizations
summary: "Creates an organization role."
updated: 2026-09-28
nav: false
---

Creates an organization role.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/organization_roles`
- **Scope** `auth:write`
- **Effect** `write` — a successful call changes state.
- **Collection** [organization_roles](/docs/api/organization_roles)
- **Query** `organization_role_id`, `validate_only`

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `parent` | `string` | The parent to create in. Required. |
| `organization_role_id` | `string` | The organization role id, the final name segment; the server assigns one when empty. |
| `organization_role` | `OrganizationRole` | The organization role to create; only caller-writable fields are read. Required. |
| `validate_only` | `bool` | Validate and return the result without writing anything. |

### OrganizationRole

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/organization_roles/{organization_role}`; the final segment is the role key memberships name, for example `hr_manager`. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `permissions` | `string[]` | The app's permission strings `<resource>:<action>`, for example `invoices:read` or `org:payroll:approve`. |
| `auto_assign` | `bool` | Whether new members and invitations without roles get this role. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/organization_roles/{organization_role}`; the final segment is the role key memberships name, for example `hr_manager`. |
| `uid` | `string` | `orl_<cell><ulid>`; never reused. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `permissions` | `string[]` | The app's permission strings `<resource>:<action>`, for example `invoices:read` or `org:payroll:approve`. |
| `auto_assign` | `bool` | Whether new members and invitations without roles get this role. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`UNKNOWN_FIELD`](/docs/api/errors/UNKNOWN_FIELD) — The request has a field the schema does not know.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`RESOURCE_ALREADY_EXISTS`](/docs/api/errors/RESOURCE_ALREADY_EXISTS) — A Resource with this name exists.
- [`IDEMPOTENCY_KEY_REUSED`](/docs/api/errors/IDEMPOTENCY_KEY_REUSED) — An Idempotency-Key was reused with another body.
- [`IDEMPOTENCY_IN_PROGRESS`](/docs/api/errors/IDEMPOTENCY_IN_PROGRESS) — The first call with this Idempotency-Key is still running.
- [`PLAN_LIMIT_REACHED`](/docs/api/errors/PLAN_LIMIT_REACHED) — The plan's limit is reached.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/organization_roles" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{}'
```

**TypeScript**

```ts
const response = await sylphx.auth.organizationRoles.create({ organizationRole: {}, parent: 'orgs/acme/projects/shop/envs/production' })
```

**Rust**

```rust
let mut req = sylphx::auth::CreateOrganizationRoleRequest::default();
req.organization_role = Some(Default::default());
req.parent = "orgs/acme/projects/shop/envs/production".to_string();
let response = sx.auth().organization_roles().create(req).await?;
```

**CLI**

```bash
sylphx auth organization-roles create --parent orgs/acme/projects/shop/envs/production
```

**MCP**

```json
{ "method_id": "auth.organization_roles.create", "args": {"organization_role":{},"parent":"orgs/acme/projects/shop/envs/production"} }
```
