Skip to main content
Identity & access management — bindings and roles at project and tenant scope. Reach it as client.iam on a QumoClient.

listBindings

Lists the role bindings on a project. Types: IAMBinding

createBinding

Grants a role on a project to a user or identity. Types: IAMBinding

removeBinding

Deletes a binding. tenantId scopes the request for session (cookie) callers — the route names only the binding, so without a scope the permission check resolves nothing and the call 403s. The server also verifies the binding belongs to that tenant — for a project-scoped binding, via the binding’s parent tenant (API-key callers may omit it; their own tenant applies).

listTenantBindings

Lists the role bindings on a workspace. Types: IAMBinding

createTenantBinding

Grants a role on a workspace to a user or identity. Types: IAMBinding

listRoles

Lists the assignable IAM roles. tenantId scopes the request: session (cookie) callers carry no tenant of their own, and an unscoped admin request resolves to no permissions server-side, so omitting it yields 403. Types: IAMRole