Set Role Permissions for the Site List landing.role.setRights

Choose a tool for developing with an AI agent:

  • use Alaio Vibecode to build an app for Bitrix24 from a task description without knowing any programming language. The agent writes the code and deploys the app to a server, with no manual hosting setup
  • use the MCP server to develop a REST API integration in your own project. The agent refers to the official REST documentation

Scope: landing

Who can execute the method: administrator or user with "full access" permission to the "Sites and Stores" section

The method landing.role.setRights sets role permissions for sites. You can specify separate permissions for each site, while others will have default permissions. The new set of permissions completely replaces the previous one.

Method Parameters

Required parameters are marked with *

Name
type

Description

scope
string

The section the role belongs to. This parameter is not related to the REST scope landing in the method name.

The values GROUP, KNOWLEDGE, and MAINPAGE correspond to the types of sites described in the article Working with Site Types and Scopes.

Possible values:
GROUP - roles for group sites
KNOWLEDGE - roles for knowledge bases
MAINPAGE - roles for the main page or vibe

If the parameter is not provided, the method works with roles for sites and online stores. For a role from another section, the method returns the error ROLE_SCOPE_MISMATCH

id*
integer

The identifier of the role for which permissions need to be updated.

You can obtain the identifier using the landing.role.getList method.

If you pass the identifier of a non-existent role, the method returns the error ROLE_SCOPE_MISMATCH.

rights*
object | array

An object in the following format:

{
            "0": ["read"],
            "<siteId>": ["read", "edit", "sett"]
        }
        

where:

  • 0 — default permission for sites without separate settings
  • <siteId> — site identifier

The list of available permission codes is described below, and the structure of the object is in the parameter table rights.

The method completely replaces previously saved role permissions for sites.

additional
string[]

Additional capabilities of the role.

Possible values:

  • menu24 — show the menu item of the section for the role
  • create — allow creating new sites, knowledge bases, or pages in the section

The codes depend on the section specified in the scope parameter. For knowledge bases, group sites, and the main page, the codes have a prefix — knowledge_, group_, and vibe_ respectively. For example, for a knowledge base you need to pass knowledge_create.

The method does not save codes that belong to another section.

If the parameter is not passed, the current additional capabilities of the role will remain unchanged.

Parameter rights

Name
type

Description

0
string[]

Default permissions for the role for all sites that do not have separate settings.

Available permission codes are described below.

<siteId>
string[]

Role permissions for the site with the specified identifier.

The key is the site identifier, and the value is an array of permission codes. If a site with that identifier is not found, the entry will be skipped without an error.

You can obtain the site identifier using the landing.site.getList method or from the result of the landing.site.add method.

For each site, pass an array of permission codes. If a different value is passed instead of an array, the entry for that site will be skipped without an error.

Permission Codes

Code

Description

denied

Access to the site is denied.

read

View the site.

edit

Modify site pages.

sett

Change site settings.

public

Publish.

delete

Move to trash and restore from trash.

Code Examples

How to Use Examples in Documentation

curl -X POST \
          -H "Content-Type: application/json" \
          -d '{
            "id": 11,
            "rights": {
              "0": ["read"],
              "66": ["read", "edit", "sett"],
              "71": ["denied"]
            },
            "additional": ["menu24", "create"]
          }' \
          "https://**put.your-domain-here**/rest/**user_id**/**webhook_code**/landing.role.setRights.json"
        
curl -X POST \
          -H "Content-Type: application/json" \
          -d '{
            "id": 11,
            "rights": {
              "0": ["read"],
              "66": ["read", "edit", "sett"],
              "71": ["denied"]
            },
            "additional": ["menu24", "create"],
            "auth": "**put_access_token_here**"
          }' \
          "https://**put.your-domain-here**/rest/landing.role.setRights.json"
        
// This snippet is an ES module: top-level await requires type="module" or a bundler.
        // $b24 is an already-initialized SDK instance (see the SDK "Get started" guide).
        import { Text } from '@bitrix24/b24jssdk'
        import type { B24Frame } from '@bitrix24/b24jssdk'
        
        declare const $b24: B24Frame
        
        try {
          const response = await $b24.actions.v2.call.make<boolean>({
            method: 'landing.role.setRights',
            params: {
              id: 11,
              rights: {
                0: ['read'],
                66: ['read', 'edit', 'sett'],
                71: ['denied'],
              },
              additional: ['menu24', 'create'],
            },
            requestId: Text.getUuidRfc4122()
          })
        
          // The payload is available only on a successful response
          if (!response.isSuccess) {
            console.error(response.getErrorMessages().join('; '))
          } else {
            const result = response.getData()!.result
            console.info('Rights set successfully:', result)
          }
        } catch (error) {
          // Thrown on transport or SDK failures (AjaxError, SdkError, etc.)
          console.error(error)
        }
        
<!-- Load the SDK (UMD build); it is exposed as the global B24Js -->
        <script src="https://unpkg.com/@bitrix24/b24jssdk@1/dist/umd/index.min.js"></script>
        <script>
          async function setRoleRights() {
            try {
              // Initialize the SDK inside a Bitrix24 frame
              const $b24 = await B24Js.initializeB24Frame()
        
              const response = await $b24.actions.v2.call.make({
                method: 'landing.role.setRights',
                params: {
                  id: 11,
                  rights: {
                    0: ['read'],
                    66: ['read', 'edit', 'sett'],
                    71: ['denied'],
                  },
                  additional: ['menu24', 'create'],
                },
                requestId: B24Js.Text.getUuidRfc4122()
              })
        
              // The payload is available only on a successful response
              if (!response.isSuccess) {
                console.error(response.getErrorMessages().join('; '))
                return
              }
        
              const result = response.getData().result
              console.info('Rights set successfully:', result)
            } catch (error) {
              // Thrown on transport or SDK failures (AjaxError, SdkError, etc.)
              console.error(error)
            }
          }
        
          document.addEventListener('DOMContentLoaded', setRoleRights)
        </script>
        
from b24pysdk.errors import BitrixAPIError, BitrixSDKException
        
        try:
            bitrix_response = client.landing.role.set_rights(
                bitrix_id=11,
                rights={
                    "0": [
                        "read",
                    ],
                    "66": [
                        "read",
                        "edit",
                        "sett",
                    ],
                    "71": [
                        "denied",
                    ],
                },
                additional=[
                    "menu24",
                    "create",
                ],
            ).response
            result = bitrix_response.result
            print(result)
        except BitrixAPIError as error:
            print(
                "Bitrix API error",
                f"error: {error.error}",
                f"error_description: {error.error_description}",
                sep="\n",
            )
        except BitrixSDKException as error:
            print(f"Bitrix SDK error: {error.message}")
        except Exception as error:
            print(f"Unexpected error: {error}")
        
try {
            $response = $b24Service
                ->core
                ->call(
                    'landing.role.setRights',
                    [
                        'id' => 11,
                        'rights' => [
                            0 => ['read'],
                            66 => ['read', 'edit', 'sett'],
                            71 => ['denied'],
                        ],
                        'additional' => ['menu24', 'create'],
                    ]
                );
        
            $result = $response
                ->getResponseData()
                ->getResult();
        
            echo 'Success: ' . var_export($result, true);
        } catch (Throwable $e) {
            error_log($e->getMessage());
            echo 'Error setting role rights: ' . $e->getMessage();
        }
        
BX24.callMethod(
            'landing.role.setRights',
            {
                id: 11,
                rights: {
                    0: ['read'],
                    66: ['read', 'edit', 'sett'],
                    71: ['denied']
                },
                additional: ['menu24', 'create']
            },
            function(result)
            {
                if (result.error())
                {
                    console.error(result.error());
                }
                else
                {
                    console.info(result.data());
                }
            }
        );
        
require_once('crest.php');
        
        $result = CRest::call(
            'landing.role.setRights',
            [
                'id' => 11,
                'rights' => [
                    0 => ['read'],
                    66 => ['read', 'edit', 'sett'],
                    71 => ['denied'],
                ],
                'additional' => ['menu24', 'create'],
            ]
        );
        
        if (isset($result['error']))
        {
            echo 'Error: ' . $result['error_description'];
        }
        else
        {
            echo '<pre>';
            print_r($result['result']);
            echo '</pre>';
        }
        
// client and ctx are already created — see the Go SDK section
        res, err := client.Core().Call(ctx, "landing.role.setRights", b24.Params{
        	"id": 11,
        	"rights": b24.Params{
        		"0":  []string{"read"},
        		"66": []string{"read", "edit", "sett"},
        		"71": []string{"denied"},
        	},
        	"additional": []string{"menu24", "create"},
        })
        if err != nil {
        	return fmt.Errorf("landing.role.setRights: %w", err)
        }
        
        var ok bool
        if err := json.Unmarshal(res.Result, &ok); err != nil {
        	return fmt.Errorf("parse response: %w", err)
        }
        fmt.Println("done:", ok)
        

Response Handling

HTTP Status: 200

{
            "result": true,
            "time": {
                "start": 1775071662,
                "finish": 1775071663.148474,
                "duration": 1.1484739780426025,
                "processing": 0,
                "date_start": "2026-04-01T22:27:42+02:00",
                "date_finish": "2026-04-01T22:27:43+02:00",
                "operating_reset_at": 1775072263,
                "operating": 0.1147608757019043
            }
        }
        

Returned Data

Name
type

Description

result
boolean

The result of the call.

The method returns true if the request was processed without access or system errors.

The value true does not guarantee that permissions were recorded for each provided site. If a site is not found or the format of one of the entries is incorrect, that entry will be skipped without an error.

After the call, check the saved set of permissions using the landing.role.getRights method.

time
time

Information about the execution time of the request.

Error Handling

HTTP Status: 400

{
            "error": "MISSING_PARAMS",
            "error_description": "Not enough parameters for the call, missing: rights"
        }
        

Name
type

Description

error
string

String error code. It consists of digits, Latin letters, and underscores. It may arrive empty — in that case only error_description shows the reason

error_description
string

Error message for the developer. Do not show it to the end user without processing

Possible Error Codes

Code

Description

ACCESS_DENIED

Not enough permissions to work with the "Sites and Stores" section.

IS_NOT_ADMIN

The method requires administrator rights or "full access" permission to the "Sites and Stores" section.

FEATURE_NOT_AVAIL

Permission management in the "Sites and Stores" section is not available on the current plan.

MISSING_PARAMS

The required parameter id or rights is missing.

ROLE_SCOPE_MISMATCH

The role does not belong to the section specified in the scope parameter. The method returns this error both for a role from another section and for a role that does not exist.

Statuses and System Error Codes

HTTP Status: 4xx, 5xx

The errors described below are returned by the REST API itself, not by the logic of a specific method. They can arrive in response to any method.

Status

Code
Error Message

Description

500

INTERNAL_SERVER_ERROR
Internal server error

An internal server error has occurred. Retry the call, and if the error persists, contact the server administrator or Bitrix24 technical support

500

ERROR_UNEXPECTED_ANSWER
Server returned an unexpected response

The server returned an unexpected response. Retry the call, and if the error persists, contact the server administrator or Bitrix24 technical support

503

QUERY_LIMIT_EXCEEDED
Too many requests

The request intensity limit has been exceeded

429

OPERATION_TIME_LIMIT
Method is blocked due to operation time limit

The method is blocked because the request resource intensity limit has been exceeded. The block is lifted automatically once the accumulated execution time of the method no longer exceeds the limit

401

NO_AUTH_FOUND
Wrong authorization data

The request contains no authorization data: neither an access token nor a webhook code was passed

401

INVALID_REQUEST
Https required

Methods are called over the HTTPS protocol only

401

OVERLOAD_LIMIT
REST API is blocked due to overload

The REST API is blocked due to overload. This is a manual individual block. To have it lifted, contact Bitrix24 technical support

401

ACCESS_DENIED
REST is available only on commercial plans

REST API access is not active for this account. In Bitrix24 Cloud, check the current plan or trial status: Vibe+ plans include REST API access, while Essentials plans do not. A webhook receives a different error message — REST is available only by subscription

401

INVALID_CREDENTIALS
Invalid request credentials

No active webhook with the specified user identifier and secret code was found

404

ERROR_METHOD_NOT_FOUND
Method not found!

No method with this name was found. The name is misspelled, the method does not exist in the REST API, or it is unavailable without the required scope

401

insufficient_scope
The request requires higher privileges than provided by the webhook token

The request requires broader permissions than the token has: for a webhook these are the permissions granted to it, for an application it is the scope. For an application, the error message ends with provided by the access token

401

expired_token
The access token provided has expired

The access token has expired

401

user_access_error
The user does not have access to the application

The application is installed, but the Bitrix24 administrator has granted access to it only to specific users

403

PORTAL_DELETED
Portal was deleted

The public part of the site is closed. To open it on an on-premise installation, disable the "Temporary closure of the public part of the site" option. Path to the setting: Desktop > Settings > Product Settings > Module Settings > Main Module > Temporary closure of the public part of the site

Continue Learning