---
metadata:
  - name: generator
    content: Diplodoc Platform v5.57.3
alternate:
  - https://sourcecraft.dev/portal/docs/en/sourcecraft/operations/bind.md
  - https://sourcecraft.dev/portal/docs/ru/sourcecraft/operations/bind.md
  - href: en/sourcecraft/operations/bind.md
    type: text/markdown
    title: Markdown version
  - href: ../../llms.txt
    type: text/markdown
    title: llms.txt
---
> **Documentation Index:** Fetch the complete configuration index at https://sourcecraft.dev/portal/docs/en/llms.txt

<!-- source: en/_includes/sourcecraft/security-bind.md -->
# Assigning a role to a user in SourceCraft

<!-- source: en/_includes/sourcecraft/security-intro.md -->
Access to SourceCraft is controlled by issuing permissions to users in [organizations](https://sourcecraft.dev/portal/docs/en/sourcecraft/concepts/index.md#org) and [repositories](https://sourcecraft.dev/portal/docs/en/sourcecraft/concepts/index.md#repos).
<!-- endsource: en/_includes/sourcecraft/security-intro.md -->

You can assign [roles](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/index.md#roles-list) to users at the [organization](#org), [project](#project), or individual [repository](#repo) level.

You can specify an organization-level role for a new user in the [invitation](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/invite.md).

## Assigning a role to a user in an organization {#org}

{% note warning %}

You need at least the [Organization admin](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/index.md#organization-manager-admin) role to assign a role to an organization user.

{% endnote %}

1. Open the SourceCraft [home page](https://sourcecraft.dev).
1. On the ![image](../../_assets/console-icons/house.svg) **Home** tab, navigate to ![image](../../_assets/console-icons/briefcase.svg) **Organizations**.
1. Select the organization you want to assign a role in.
1. On the organization page, under ![image](../../_assets/console-icons/person-nut-hex.svg) **People**, go to the ![image](../../_assets/console-icons/person.svg) **Members & roles** section.
1. Next to the user you want to assign the role to, click ![image](../../_assets/console-icons/sliders.svg) in the **Members & roles** column.
1. Mark the roles you want to assign to the user with ![image](../../_assets/console-icons/check.svg).
1. Click **Apply**.

{% note tip %}

You can assign roles in the organization directly to a user group. For more information, see {#T}.

{% endnote %}

## Assigning a project-level role to a user {#project}

<!-- source: en/_includes/sourcecraft/project-binding-role.md -->
{% note info %}

To assign or delete user roles in a [project](https://sourcecraft.dev/portal/docs/en/sourcecraft/concepts/index.md#projects), you need the [Project maintainer](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/index.md#src-projects-maintainer) role or higher at the project or organization level.

{% endnote %}
<!-- endsource: en/_includes/sourcecraft/project-binding-role.md -->

<!-- source: en/_includes/sourcecraft/project-role-note.md -->
[Roles](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/index.md#src-roles) assigned to a user in a project apply to all repositories in the project.
<!-- endsource: en/_includes/sourcecraft/project-role-note.md -->

<!-- source: en/_includes/sourcecraft/project-add-member.md -->
1. Open the SourceCraft [home page](https://sourcecraft.dev).
1. On the ![image](../../_assets/console-icons/house.svg) **Home** tab, navigate to ![image](../../_assets/console-icons/briefcase.svg) **Organizations** and select an organization.
1. In the ![image](../../_assets/console-icons/layout-tabs.svg) **Your craftspace** section, navigate to ![image](../../_assets/console-icons/folders.svg) **Projects**.
1. To the right of the project, click ![image](../../_assets/console-icons/sliders.svg) and go to ![image](../../_assets/console-icons/person.svg) **Members & roles**.
1. In the top-right corner, click ![image](../../_assets/console-icons/plus.svg) **Add member**.
1. Select a user and their role in the project.

    {% note warning %}

    You can add to the project only users who are members of the organization.

    {% endnote %}

1. Click **Add**.
<!-- endsource: en/_includes/sourcecraft/project-add-member.md -->

## Assigning a role to a user in a repository {#org}

{% note warning %}

You need at least the [Repository maintainer](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/index.md#src-repositories-maintainer) role to assign a role to a repository user.

When you assign a role in a repository to a user who is not a member of the organization owning the repository, the user will be invited to the organization. In which case you will need the [Organization admin](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/index.md#organization-manager-admin) role.

{% endnote %}

<iframe width="640" height="360" src="https://runtime.strm.yandex.ru/player/video/vplvf5ebzkkqjjzokanj?autoplay=0&mute=0" allow="autoplay; fullscreen; picture-in-picture; encrypted-media" frameborder="0" scrolling="no"></iframe>

1. Open the SourceCraft [home page](https://sourcecraft.dev).
1. On the ![image](../../_assets/console-icons/house.svg) **Home** tab, under ![image](../../_assets/console-icons/layout-tabs.svg) **Your craftspace**, navigate to ![image](../../_assets/console-icons/archive.svg) **Repositories**.
1. Select the repository you want to assign a role in.
1. Under ![image](../../_assets/console-icons/gear.svg) **Repository settings** on the repository page, go to ![image](../../_assets/console-icons/persons-lock.svg) **Members & roles**.
1. In the top-right corner, click **New role**.
1. In the window that opens, select the principle of issuing an invitation and a role to the user:

    {% list tabs group=invite-type %}

    - Login {#login}

      1. In the **Users or teams** field, start typing the user's public name, e.g., `John Smith`, or nickname, e.g., `jsmith-2000`, and select the user from among the suggested options.
      1. In the **Role** drop-down list, select the [role](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/index.md#roles-list) you want to assign.
      1. In the **Invite Expires In** drop-down list, select how long the invitation to the repository will remain valid.
      1. Click **Add**.

    - E-mail {#e-mail}

      1. In the **Emails** field, enter the email addresses of the users you want to assign the role to, one by one.
      1. In the **Role** drop-down list, select the [role](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/index.md#roles-list) you want to assign.
      1. In the **Invite Expires In** drop-down list, select how long the invitation to the repository will remain valid.
      1. Click **Add**.

    - Link {#link}

      <!-- source: en/_includes/sourcecraft/link-invite-intro.md -->
      You can generate unique _invitation links_ for ad-hoc users. Each link has its own expiration date and can only be used once. 

      This is useful if you do not know the logins or emails of your users or want to automate role assignment and repository access management.

      A user accepts the invitation by clicking the link and gets access to your organization and its repositories.
      <!-- endsource: en/_includes/sourcecraft/link-invite-intro.md -->
      
      The user will also get the [role](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/index.md#roles-list) you specify.
      
      To generate invitation links:
      1. In the **Invite Expires In** drop-down list, select how long the link will remain valid.
      1. In the **Quantity** field, specify the number of unique invitation links.
      1. Optionally, in the **Prefix** field, specify a prefix for the invitation links, e.g., `team-sourcecraft`.
      1. In the **Role** drop-down list, select the [role](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/index.md#roles-list) that will be assigned to the users who accept the invitation via the link.
      1. Click **Add**.
      1. In the window that opens, copy the links to the clipboard or download them as a file, then close the window.

          {% note warning %}

          After closing the window, the links you generated will no longer be available. However, you can create new ones.

          {% endnote %}

      1. Send the invitation links to the users you want to assign the role to.

    - Multi-invite link {#multi-link}

      You can generate a single _multi-invite link_ that allows one or more users to join the repository. You can create a multi-invite link either for specific users or for anyone with the link.

      Users joining through the multi-invite link will also get the [role](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/index.md#roles-list) you specify.

      <!-- source: en/_includes/sourcecraft/multi-link-sa.md -->
      Multi-invite links are managed via a Yandex Identity and Access Management [service account](https://yandex.cloud/en/docs/iam/concepts/users/service-accounts) with the `organization-manager.passportUserAdmin` [role](https://yandex.cloud/en/docs/iam/roles-reference#organization-manager-passportUserAdmin). You can select an existing service account or create a new one.
      <!-- endsource: en/_includes/sourcecraft/multi-link-sa.md -->

      To generate a multi-invite link:
      1. In the **Invite Expires In** drop-down list, select how long the multi-invite link will remain valid.
      1. Optionally, in the **Invitee limit** field, specify the maximum number of users who can accept your multi-invite link. For an unlimited number of users, leave this field empty.
      1. Optionally, in the **Unique invite link name** field, enter a unique name for the multi-invite link. Leave this field empty to generate a name automatically.
      1. In the **Role** drop-down list, select a [role](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/index.md#roles-list) for the users you invite.
      1. Under **Can accept**, select an invitation restriction:
          * **Everyone**: Any user can accept the invitation.
          * **Specific users**: Only specific users can accept the invitation:
            * **SourceCraft users**: Start typing a public name, e.g., `John Smith`, or nickname, e.g., `jsmith-2000`, and select one of the suggested options. This is an optional setting. You can add multiple users.
            * **Yandex logins**: Enter a user login and click **Add login**. This is an optional setting. You can add multiple users.
      1. Under **Service account**, select one of the following options:
          * **Auto**: Yandex Cloud will automatically create a new service account with the `organization-manager.passportUserAdmin` [role](https://yandex.cloud/en/docs/iam/roles-reference#organization-manager-passportUserAdmin).
          * **Choose existing**: Select a Yandex Identity and Access Management [service account](https://yandex.cloud/en/docs/iam/concepts/users/service-accounts) to use for creating invitations.
      1. Click **Add**.
      1. In the window that opens, copy the multi-invite link to the clipboard, then close the window.

          {% note warning %}

          After you close the window, the multi-invite link you generated will no longer be available. However, you can create a new one.

          {% endnote %}

      1. Send the multi-invite link to the users you want to assign the role to.

    {% endlist %}

{% note tip %}

You can assign roles in a repository to a whole group of users. For more information, see {#T}.

{% endnote %}

### Assigning a role in a repository to a user via the API {#api}

You can automate role assignment using the [SourceCraft REST API](https://sourcecraft.dev/portal/docs/en/sourcecraft/operations/api-start.md).

For example, you can integrate role assignment into your website or access management system.

For more information, see [Repository | Roles](https://api.sourcecraft.tech/docs/index.html#tag/Repository-or-Roles).

To assign a role to a user:
1. [Get](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/pat.md#create) a personal access token (PAT).
1. Run queries depending on whether the user is a member of the organization.

    {% list tabs group=user-type %}

    - Organization member {#org-user}

      1. Get user ID in SourceCraft.

          ```bash
          export PAT=<personal_access_token>
          curl \
            --request GET \
            --url "https://api.sourcecraft.tech/users/<user_slug>" \
            --header "Authorization: Bearer $PAT" | jq -r '.id'
          ```

          Result:

          ```json
          "01971bf5-676b-79a3-adbf-7644********"
          ```

          For more information, see [GetProfile](https://api.sourcecraft.tech/docs/index.html#tag/User/operation/GetProfile).

      1. Assign a role to the user:

          ```bash
          export PAT=<personal_access_token>
          curl \
            --request POST \
            --url "https://api.sourcecraft.tech/repos/<organization_slug>/<repository_slug>/roles" \
            --header "Authorization: Bearer $PAT" \
            --header "Content-Type: application/json" \
            --data '{
              "subject_roles": [
                {
                  "role": "<role>",
                  "subject": {
                    "type": "user",
                    "id": "<user_ID_in_SourceCraft>"
                  }
                }
              ]
            }' | jq
          ```

          For possible `role` values, see [Repository | Roles](https://api.sourcecraft.tech/docs/index.html#tag/Repository-or-Roles).

          Result:

          ```json
          {
            "subject_roles": [
              {
                "role": "admin",
                "subject": {
                  "type": "user",
                  "id": "01971bf5-673f-7c64-a88a-509b********"
                }
              },
              {
                "role": "viewer",
                "subject": {
                  "type": "user",
                  "id": "01971bf5-676b-79a3-adbf-7644********"
                }
              }
            ],
            "next_page_token": ""
          }
          ```

          For more information, see [Repository | Roles](https://api.sourcecraft.tech/docs/index.html#tag/Repository-or-Roles).

    - New user {#invitee}

      1. [Invite](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/invite.md#api-create-invite) the user to the organization.
      1. [Get](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/invite.md#api-get-invite) the invitation creation operation info. Use this info to find the organization user ID (the `response: invites: subject: id` field).
      1. Assign a role to the user:

          ```bash
          export PAT=<personal_access_token>
          curl \
            --request POST \
            --url "https://api.sourcecraft.tech/repos/<organization_slug>/<repository_slug>/roles" \
            --header "Authorization: Bearer $PAT" \
            --header "Content-Type: application/json" \
            --data '{
              "subject_roles": [
                {
                  "role": "<role>",
                  "subject": {
                    "type": "invitee",
                    "id": "<user_ID_in_organization>"
                  }
                }
              ]
            }' | jq
          ```

          For possible `role` values, see [Repository | Roles](https://api.sourcecraft.tech/docs/index.html#tag/Repository-or-Roles).

          Result:

          ```json
          {
            "subject_roles": [
              {
                "role": "admin",
                "subject": {
                  "type": "user",
                  "id": "01971bf5-673f-7c64-a88a-509b********"
                }
              },
              {
                "role": "viewer",
                "subject": {
                  "type": "invitee",
                  "id": "ajeth710l8gi********"
                }
              }
            ],
            "next_page_token": ""
          }
          ```

          For more information, see [Repository | Roles](https://api.sourcecraft.tech/docs/index.html#tag/Repository-or-Roles).

    {% endlist %}
<!-- endsource: en/_includes/sourcecraft/security-bind.md -->

#### Useful links {#see-also}

* [Access management in SourceCraft](https://sourcecraft.dev/portal/docs/en/sourcecraft/security/index.md)
* [Inviting a user to an organization](https://sourcecraft.dev/portal/docs/en/sourcecraft/operations/invite.md)
