> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://contentful.com/developers/docs/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://contentful.com/_mcp/server. # Create a role POST https://api.contentful.com/spaces/{space_id}/roles Content-Type: application/vnd.contentful.management.v1+json Use this endpoint to create a custom role. The role name must be unique within the space. Reference: https://contentful.com/developers/docs/references/content-management-api/roles/create-a-role ## Authentication - `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer `, where token is your auth token. ## Request ### Path parameters - `space_id` (string, required) — ID of the Space in form of a string ### Body (application/vnd.contentful.management.v1+json) This endpoint expects a map from string to any. - `map from string to any` ## Response ### 201 Created - Resource created successfully - `map from string to any` ## Examples **Request** ```json { "description": "Test role", "name": "Some role", "permissions": { "ContentDelivery": "all", "ContentModel": [ "read" ], "EnvironmentAliases": "all", "Environments": "all", "Settings": "all" }, "policies": [ { "actions": [ "read", "create", "update", "delete", "publish", "unpublish", "archive", "unarchive" ], "constraint": { "and": [ [ "equals", { "doc": "sys.type" }, "Entry" ] ] }, "effect": "allow" } ] } ``` **Response** ```json { "description": "Test role", "name": "Some role", "permissions": { "ContentDelivery": "all", "ContentModel": [ "read" ], "EnvironmentAliases": "all", "Environments": "all", "Settings": "all" }, "policies": [ { "actions": [ "read", "create", "update", "delete", "publish", "unpublish", "archive", "unarchive" ], "constraint": { "and": [ [ "equals", { "doc": "sys.type" }, "Entry" ] ] }, "effect": "allow" } ], "sys": { "createdAt": "2025-10-31T05:59:20.000Z", "createdBy": { "sys": { "id": "7BslKh9TdKGOK41VmLDjFZ", "linkType": "User", "type": "Link" } }, "id": "0xvkNW6WdQ8JkWlWZ8BC4x", "type": "Role", "updatedAt": "2025-10-31T05:59:20.000Z", "updatedBy": { "sys": { "id": "4FLrUHftHW3v2BLi9fzfjU", "linkType": "User", "type": "Link" } }, "version": 0 } } ``` **SDK Code** ```android Android // Create the Contentful client. final CMAClient client = new CMAClient .Builder() .setAccessToken("") .setSpaceId("") .setEnvironmentId("") .build(); final CMARole role = new CMARole(); role .setName("This role is mine!") .setDescription("A test role"); // Create it on Contentful. client .roles() .async() .create( "", role, new CMACallback() { @Override protected void onSuccess(CMARole result) { // The fetched role will be the parameter of this method. new AlertDialog.Builder(context) .setTitle("Contentful") .setMessage("Role created." + "\n\nResult: " + result) .show(); } @Override protected void onFailure(RuntimeException exception) { // An error occurred! Inform the user. new AlertDialog.Builder(context) .setTitle("Contentful Error") .setMessage("Could not create a new role." + "\n\nReason: " + exception.toString()) .show(); super.onFailure(exception); } } ); ``` ```java Java // Create the Contentful client. final CMAClient client = new CMAClient .Builder() .setAccessToken("") .setSpaceId("") .setEnvironmentId("") .build(); // Create a locale role: final CMARole role = new CMARole(); role .setName("My own new role!") .setDescription("This role is mine!") .setPermissions( new CMAPermissions() .setContentModel("all") .setContentModel("all") .setSettings("all") ).setPolicies( singletonList( new CMAPolicy() .update() .setActions( singletonList("all") ).setConstraint( new CMAConstraint() .setEquals( new CMAConstraint.Equals() .setPath(new CMAConstraint.FieldKeyPath().setDoc("fields.%")) .setValue("%") ) ) ) ); // Upload it to contentful final CMARole newRole = client .roles() .create("", role); ``` ```kotlin Kotlin // Create the Contentful client. val client = CMAClient.Builder() .setAccessToken("") .setSpaceId("") .setEnvironmentId("") .build() // Create a locale role: val role = CMARole() role .setName("My own new role!") .setDescription("This role is mine!") .setPermissions( CMAPermissions() .setContentModel("all") .setContentModel("all") .setSettings("all") ).policies = listOf(CMAPolicy() .update() .setActions( listOf("all") ).setConstraint( CMAConstraint() .setEquals( CMAConstraint.Equals() .setPath(CMAConstraint.FieldKeyPath().setDoc("fields.%")) .setValue("%") ) )) // Upload it to contentful val newRole = client .roles() .create("", role) ``` ```swift Swift We currently don't provide a CMA SDK for this platform. ``` ```js-legacy JavaScript (legacy) import { createClient } from 'contentful-management' const client = createClient({ accessToken: '' }, { type: 'legacy' }) client.getSpace('') .then((space) => space.createRole({ name: 'My Role', description: 'foobar role', permissions: { ContentDelivery: 'all', ContentModel: ['read'], Settings: [] }, policies: [ { effect: 'allow', actions: 'all', constraint: { and: [ { equals: [ { doc: 'sys.type' }, 'Entry' ] }, { equals: [ { doc: 'sys.type' }, 'Asset' ] } ] } } ] })) .then((role) => console.log(role)) .catch(console.error) ``` ```javascript JavaScript import { createClient } from 'contentful-management' const client = createClient({ accessToken: '' }, { type: 'legacy' }) const role = await client.role.create( { spaceId: '', }, { name: 'My role', description: 'My role description', permissions: { ContentModel: ['read'], ContentDelivery: 'all', Environments: 'all', EnvironmentAliases: 'all', Settings: 'all', }, policies: [ { effect: 'allow', actions: [ 'read', 'create', 'update', 'delete', 'publish', 'unpublish', 'archive', 'unarchive', ], constraint: { and: [ [ 'equals', { doc: 'sys.type', }, 'Entry', ], ], }, }, ], } ); ``` ```php PHP $client = new \Contentful\Management\Client(''); $space = $client->getSpaceProxy(''); $role = new \Contentful\Management\Resource\Role('My Role', 'foobar role'); $role->getPermissions() ->setContentDelivery('all') ->setContentModel('read') ->setSettings('all'); $policy = new \Contentful\Management\Resource\Role\Policy( 'allow', // Effect 'all' // Actions ); use Contentful\Management\Resource\Role\Constraint\AndConstraint; use Contentful\Management\Resource\Role\Constraint\EqualityConstraint; $policy->setConstraint(new AndConstraint([ new EqualityConstraint('sys.type', 'Entry'), new EqualityConstraint('sys.type', 'Asset'), ])); $role->setPolicy($policy); $space->create($role); ``` ```ruby Ruby require 'contentful/management' client = Contentful::Management::Client.new('') role = client.roles('').create( { name: 'My Role', description: 'foobar role', permissions: { ContentDelivery: 'all', ContentModel: ['read'], Settings: [] }, policies: [ { effect: 'allow', actions: 'all', constraint: { and: [ { equals: [ { doc: 'sys.type' }, 'Entry' ] }, { equals: [ { doc: 'sys.type' }, 'Asset' ] } ] } } ] } ) ``` ```python Python from contentful_management import Client client = Client('') role = client.roles('').create({ 'name': 'My Role', 'description': 'foobar role', 'permissions': { 'ContentDelivery': 'all', 'ContentModel': ['read'], 'Settings': [] }, 'policies': [ { 'effect': 'allow', 'actions': 'all', 'constraint': { 'and': [ { 'equals': [ { 'doc': 'sys.type' }, 'Entry' ] }, { 'equals': [ { 'doc': 'sys.type' }, 'Asset' ] } ] } } ] }) ``` ```.net .NET // This client should only be created once per application. var httpClient = new HttpClient(); var client = new ContentfulManagementClient(httpClient, "", ""); var role = new Role(); role.Name = "Name of the role"; role.Description = "Describe the role"; role.Permissions = new ContentfulPermissions(); role.Permissions.ContentDelivery = new List() { "read" }; // What permissions should the role have to the ContentDelivery API. role.Permissions.ContentModel = new List() { "read" }; // What permissions should the role have to the content model, i.e. reading the content model. role.Permissions.Settings = new List() { "manage" }; // What permissions should the role have to other type of settings. role.Policies = new List(); // Add more granular policies to the role. role.Policies.Add(new Policy() // Every policy consists of a number of actions and constraints. { Effect = "allow", Actions = new List() { "read", "create", "update" }, Constraint = new AndConstraint() { new EqualsConstraint() { Property = "sys.type", ValueToEqual = "Entry" } } }); var createdRole = await client.CreateRole(role) ```