Skip to main content
PUT
Import an application's access

This is a full replace, not a merge

Import sends the complete access list for one application. Users, resources and permissions are matched by email and title, and any access not present in the body is removed — this is a replace, not an incremental update. An email matching no known user creates one, so send the full intended state every time, not just the rows you want to add or change. The write is all-or-nothing: if any row cannot be resolved, nothing is written and every rejected row is listed in the response. Importing into an application with an active access-syncing integration is allowed, but the next scheduled sync will overwrite whatever the import wrote.
Because this call replaces all of an application’s access, an omission is a deletion. Read back the current state with List access states and build the body from there rather than from a partial list.

Long-running request — combine with idempotency

Replacing every user, resource and permission for an application is a large operation. For a big application the request can be long-running, and the underlying TCP connection may be held open long enough that a proxy, load balancer or client timeout drops it before AccessOwl responds — even though the import is still being applied on the server. A plain retry after such a timeout would re-run the whole replace. To retry safely, send a unique Idempotency-Key header and reuse the same key on every retry of that import — a repeat then returns 409 Conflict instead of re-applying the replace.
See Idempotency for the full contract — key format, how 409/422 responses behave, and retention.

Authorizations

Authorization
string
header
required

Bearer token authentication. Pass your AccessOwl API token in the Authorization header as Bearer <token>.

Headers

Idempotency-Key
string

Optional key (1–255 chars) for safely retrying a request. Reusing the same key for the same request returns 409 Conflict and is not processed again — this confirms the request was already received. Keys are retained for 14 days.

Required string length: 1 - 255

Path Parameters

application_id
string<uuid>
required

Application ID

Body

application/json

Complete access list

The complete access list for one application. Any access not listed is removed.

access
object[]
required

One entry per user and resource

Response

Import result

Counts of the changes the import made

data
object
required
Last modified on September 29, 2026