> ## Documentation Index
> Fetch the complete documentation index at: https://docs-staging.auth0-mintlify.app/llms.txt
> Use this file to discover all available pages before exploring further.

> Learn how to create a role using the Auth0 Dashboard or the Management API.

# Create Roles

export const AuthCodeGroup = ({children, dropdown}) => {
  const [processedChildren, setProcessedChildren] = useState(children);
  useEffect(() => {
    let unsubscribe = null;
    function init() {
      unsubscribe = window.autorun(() => {
        const processChildren = node => {
          if (typeof node === "string") {
            let processedNode = node;
            for (const [key, value] of window.rootStore.variableStore.values.entries()) {
              const escapedKey = key.replaceAll(/[.*+?^${}()|[\]\\]/g, (String.raw)`\$&`);
              processedNode = processedNode.replaceAll(new RegExp(escapedKey, "g"), value);
            }
            return processedNode;
          } else if (Array.isArray(node)) {
            return node.map(processChildren);
          } else if (node && node.props && node.props.children) {
            return {
              ...node,
              props: {
                ...node.props,
                children: processChildren(node.props.children)
              }
            };
          }
          return node;
        };
        setProcessedChildren(processChildren(children));
      });
    }
    if (window.rootStore) {
      init();
    } else {
      window.addEventListener("adu:storeReady", init);
    }
    return () => {
      window.removeEventListener("adu:storeReady", init);
      unsubscribe?.();
    };
  }, [children]);
  return <CodeGroup dropdown={dropdown}>{processedChildren}</CodeGroup>;
};

export const AuthCodeBlock = ({filename, icon, language, highlight, children}) => {
  const [displayText, setDisplayText] = useState(children);
  const [copyText, setCopyText] = useState(children);
  const wrapperRef = React.useRef(null);
  useEffect(() => {
    let unsubscribe = null;
    function init() {
      if (!window.autorun || !window.rootStore) {
        return;
      }
      unsubscribe = window.autorun(() => {
        let processedChildrenForDisplay = children;
        let processedChildrenForCopy = children;
        for (const [key, value] of window.rootStore.variableStore.values.entries()) {
          const escapedKey = key.replaceAll(/[.*+?^${}()|[\]\\]/g, (String.raw)`\$&`);
          let displayValue = value;
          if (key === "{yourClientSecret}" && value !== "{yourClientSecret}") {
            displayValue = value.substring(0, 3) + "*****MASKED*****";
          }
          processedChildrenForDisplay = processedChildrenForDisplay.replaceAll(new RegExp(escapedKey, "g"), displayValue);
          processedChildrenForCopy = processedChildrenForCopy.replaceAll(new RegExp(escapedKey, "g"), value);
        }
        setDisplayText(processedChildrenForDisplay);
        setCopyText(processedChildrenForCopy);
      });
    }
    if (window.rootStore) {
      init();
    } else {
      window.addEventListener("adu:storeReady", init);
    }
    return () => {
      window.removeEventListener("adu:storeReady", init);
      unsubscribe?.();
    };
  }, [children]);
  useEffect(() => {
    if (!wrapperRef.current) return;
    const originalWriteText = navigator.clipboard.writeText.bind(navigator.clipboard);
    let isOverriding = false;
    const handleClick = e => {
      const button = e.target.closest('[data-testid="copy-code-button"]');
      if (!button || !wrapperRef.current.contains(button)) return;
      isOverriding = true;
      navigator.clipboard.writeText = text => {
        if (isOverriding) {
          isOverriding = false;
          navigator.clipboard.writeText = originalWriteText;
          return originalWriteText(copyText);
        }
        return originalWriteText(text);
      };
      setTimeout(() => {
        if (isOverriding) {
          isOverriding = false;
          navigator.clipboard.writeText = originalWriteText;
        }
      }, 100);
    };
    const wrapper = wrapperRef.current;
    wrapper.addEventListener('click', handleClick, true);
    return () => {
      wrapper.removeEventListener('click', handleClick, true);
      if (navigator.clipboard.writeText !== originalWriteText) {
        navigator.clipboard.writeText = originalWriteText;
      }
    };
  }, [copyText]);
  return <div ref={wrapperRef}>
      <CodeBlock filename={filename} icon={icon} language={language} lines highlight={highlight}>
        {displayText}
      </CodeBlock>
    </div>;
};

You can create [roles](/docs/manage-users/access-control/rbac) using Auth0's Dashboard or the <Tooltip tip="Management API: A product to allow customers to perform administrative tasks." cta="View Glossary" href="/docs/glossary?term=Management+API">Management API</Tooltip>. Roles work with the API Authorization Core feature set.

You can create two types of roles in Auth0:

* Tenant roles: Apply across your entire tenant and can be assigned to any user.
* Organization roles: Scoped to a specific organization. Users can hold different organization roles in each organization they belong to. To learn more, read [Organization Roles](/docs/manage-users/organizations/organization-roles).

<ReleaseStageNotice feature="Organization Roles" stage="ea" terms="true" contact="Auth0 Support" />

## Prerequisites

* For role-based access control (RBAC) to work properly, you must enable it for your API using either the Dashboard or the Management API. The Authorization Core functionality is different from the Authorization Extension. For a comparison, read [Authorization Core vs. Authorization Extension](/docs/manage-users/access-control/authorization-core-vs-authorization-extension).
* [Set up an API](/docs/get-started/auth0-overview/set-up-apis) in the <Tooltip tip="Auth0 Dashboard: Auth0's main product to configure your services." cta="View Glossary" href="/docs/glossary?term=Auth0+Dashboard">Auth0 Dashboard</Tooltip>.
* Permissions come from predefined values. If your list of permissions is blank, you need to [add permissions](/docs/get-started/apis/add-api-permissions) to your API.

## Create a tenant role

Tenant roles apply across an entire tenant and you can assign them to any user regardless of Organization membership.

<Tabs>
  <Tab title="Auth0 Dashboard">
    1. Go to [Dashboard > User Management > Roles](https://manage.auth0.com/#/roles) and select **Create Role**.
    2. Name the role and add a description, then select **Create**.
  </Tab>

  <Tab title="Management API">
    Make a `POST` call to the [Create Role endpoint](/docs/api/management/v2#!/Roles/post_roles). Be sure to replace `MGMT_API_ACCESS_TOKEN`, `ROLE_NAME`, and `ROLE_DESC` placeholder values with your Management API <Tooltip tip="Access Token: Authorization credential, in the form of an opaque string or JWT, used to access an API." cta="View Glossary" href="/docs/glossary?term=access+token">access token</Tooltip>, role name, and role description, respectively.

    <AuthCodeGroup>
      ```bash cURL theme={null}
      curl --request POST \
        --url 'https://{yourDomain}/api/v2/roles' \
        --header 'authorization: Bearer MGMT_API_ACCESS_TOKEN' \
        --header 'cache-control: no-cache' \
        --header 'content-type: application/json' \
        --data '{ "name": "ROLE_NAME", "description": "ROLE_DESC" }'
      ```

      ```csharp C# theme={null}
      var client = new RestClient("https://{yourDomain}/api/v2/roles");
      var request = new RestRequest(Method.POST);
      request.AddHeader("content-type", "application/json");
      request.AddHeader("authorization", "Bearer MGMT_API_ACCESS_TOKEN");
      request.AddHeader("cache-control", "no-cache");
      request.AddParameter("application/json", "{ "name": "ROLE_NAME", "description": "ROLE_DESC" }", ParameterType.RequestBody);
      IRestResponse response = client.Execute(request);
      ```

      ```go Go theme={null}
      package main

      import (
      	"fmt"
      	"strings"
      	"net/http"
      	"io/ioutil"
      )

      func main() {

      	url := "https://{yourDomain}/api/v2/roles"

      	payload := strings.NewReader("{ "name": "ROLE_NAME", "description": "ROLE_DESC" }")

      	req, _ := http.NewRequest("POST", url, payload)

      	req.Header.Add("content-type", "application/json")
      	req.Header.Add("authorization", "Bearer MGMT_API_ACCESS_TOKEN")
      	req.Header.Add("cache-control", "no-cache")

      	res, _ := http.DefaultClient.Do(req)

      	defer res.Body.Close()
      	body, _ := ioutil.ReadAll(res.Body)

      	fmt.Println(res)
      	fmt.Println(string(body))

      }
      ```

      ```java Java theme={null}
      HttpResponse<String> response = Unirest.post("https://{yourDomain}/api/v2/roles")
        .header("content-type", "application/json")
        .header("authorization", "Bearer MGMT_API_ACCESS_TOKEN")
        .header("cache-control", "no-cache")
        .body("{ "name": "ROLE_NAME", "description": "ROLE_DESC" }")
        .asString();
      ```

      ```javascript Node.JS theme={null}
      var axios = require("axios").default;

      var options = {
        method: 'POST',
        url: 'https://{yourDomain}/api/v2/roles',
        headers: {
          'content-type': 'application/json',
          authorization: 'Bearer MGMT_API_ACCESS_TOKEN',
          'cache-control': 'no-cache'
        },
        data: {name: 'ROLE_NAME', description: 'ROLE_DESC'}
      };

      axios.request(options).then(function (response) {
        console.log(response.data);
      }).catch(function (error) {
        console.error(error);
      });
      ```

      ```php PHP theme={null}
      $curl = curl_init();

      curl_setopt_array($curl, [
        CURLOPT_URL => "https://{yourDomain}/api/v2/roles",
        CURLOPT_RETURNTRANSFER => true,
        CURLOPT_ENCODING => "",
        CURLOPT_MAXREDIRS => 10,
        CURLOPT_TIMEOUT => 30,
        CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
        CURLOPT_CUSTOMREQUEST => "POST",
        CURLOPT_POSTFIELDS => "{ "name": "ROLE_NAME", "description": "ROLE_DESC" }",
        CURLOPT_HTTPHEADER => [
          "authorization: Bearer MGMT_API_ACCESS_TOKEN",
          "cache-control: no-cache",
          "content-type: application/json"
        ],
      ]);

      $response = curl_exec($curl);
      $err = curl_error($curl);

      curl_close($curl);

      if ($err) {
        echo "cURL Error #:" . $err;
      } else {
        echo $response;
      }
      ```

      ```python Python theme={null}
      import http.client

      conn = http.client.HTTPSConnection("")

      payload = "{ "name": "ROLE_NAME", "description": "ROLE_DESC" }"

      headers = {
          'content-type': "application/json",
          'authorization': "Bearer MGMT_API_ACCESS_TOKEN",
          'cache-control': "no-cache"
          }

      conn.request("POST", "/{yourDomain}/api/v2/roles", payload, headers)

      res = conn.getresponse()
      data = res.read()

      print(data.decode("utf-8"))
      ```

      ```ruby Ruby theme={null}
      require 'uri'
      require 'net/http'
      require 'openssl'

      url = URI("https://{yourDomain}/api/v2/roles")

      http = Net::HTTP.new(url.host, url.port)
      http.use_ssl = true
      http.verify_mode = OpenSSL::SSL::VERIFY_NONE

      request = Net::HTTP::Post.new(url)
      request["content-type"] = 'application/json'
      request["authorization"] = 'Bearer MGMT_API_ACCESS_TOKEN'
      request["cache-control"] = 'no-cache'
      request.body = "{ "name": "ROLE_NAME", "description": "ROLE_DESC" }"

      response = http.request(request)
      puts response.read_body
      ```
    </AuthCodeGroup>

    | **Value**               | **Description**                                                                                                       |
    | ----------------------- | --------------------------------------------------------------------------------------------------------------------- |
    | `MGMT_API_ACCESS_TOKEN` | [Access Token for the Management API](https://auth0.com/docs/api/management/v2/tokens) with the scope `create:roles`. |
    | `ROLE_NAME`             | Name of the role you want to create.                                                                                  |
    | `ROLE_DESC`             | User-friendly description of the role.                                                                                |
  </Tab>
</Tabs>

## Create an Organization role

You create Organization roles from within the Organization management view. Tenant admins can create up to 350 Organization roles per Organization.

<Tabs>
  <Tab title="Auth0 Dashboard">
    1. Go to [Dashboard > Organizations](https://manage.auth0.com/#/organizations) and select the Organization.
    2. Select the **Roles** tab, then select **Create Role**.
    3. Enter a name and description for the role, then select **Create**.
  </Tab>

  <Tab title="Management API">
    Make a `POST` call to the [Create Role endpoint](/docs/api/management/v2#!/Roles/post_roles). Set `type` to `"organization"` and set `owner_id` to the Organization ID. Be sure to replace `MGMT_API_ACCESS_TOKEN`, `ROLE_NAME`, `ROLE_DESC`, and `ORG_ID` placeholder values with your Management API <Tooltip tip="Access Token: Authorization credential, in the form of an opaque string or JWT, used to access an API." cta="View Glossary" href="/docs/glossary?term=access+token">access token</Tooltip>, role name, role description, and Organization ID, respectively.

    ```bash cURL theme={null}
    curl --request POST \
      --url 'https://{yourDomain}/api/v2/roles' \
      --header 'authorization: Bearer MGMT_API_ACCESS_TOKEN' \
      --header 'cache-control: no-cache' \
      --header 'content-type: application/json' \
      --data '{ "name": "ROLE_NAME", "description": "ROLE_DESC", "type": "organization", "owner_id": "ORG_ID" }'
    ```

    | **Value**               | **Description**                                                                                      |
    | ----------------------- | ---------------------------------------------------------------------------------------------------- |
    | `MGMT_API_ACCESS_TOKEN` | [Access Token for the Management API](/docs/api/management/v2/tokens) with the scope `create:roles`. |
    | `ROLE_NAME`             | Name of the Organization role you want to create. Must be unique within the Organization.            |
    | `ROLE_DESC`             | User-friendly description of the role.                                                               |
    | `ORG_ID`                | ID of the Organization in which to create the role.                                                  |

    The response includes `type: "organization"` and `owner_id` confirming the role is organization-scoped.
  </Tab>
</Tabs>

## Learn more

* [Add Permissions to Roles](/docs/manage-users/access-control/configure-core-rbac/roles/add-permissions-to-roles)
* [Remove Permissions from Roles](/docs/manage-users/access-control/configure-core-rbac/roles/remove-permissions-from-roles)
* [Assign Roles to Users](/docs/manage-users/access-control/configure-core-rbac/rbac-users/assign-roles-to-users)
* [Delete Roles](/docs/manage-users/access-control/configure-core-rbac/roles/delete-roles)
