> ## Documentation Index
> Fetch the complete documentation index at: https://gcore.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create role assignment

> Assign a role to an existing user in the specified scope.



## OpenAPI

````yaml /api-reference/services_documented/cloud_api.yaml post /cloud/v1/users/assignments
openapi: 3.1.0
info:
  title: Gcore OpenAPI – Cloud API
  description: >-
    This OpenAPI is an aggregated OpenAPI specification that unifies all Gcore
    products into a single file. It covers Cloud, CDN, DNS, WAAP, DDoS
    Protection, Object Storage, Streaming, and FastEdge services.
  version: '2026-05-14T07:00:22.640261+00:00'
servers:
  - url: https://api.gcore.com
security:
  - APIKey: []
tags:
  - name: Bare Metal
    x-displayName: Bare Metal
  - name: Container as a Service
    x-displayName: Container as a Service
  - name: Cost Reports
    x-displayName: Cost Reports
  - name: DDoS Protection
    x-displayName: DDoS Protection
  - name: Everywhere Inference
    x-displayName: Everywhere Inference
  - name: Everywhere Inference Apps
    x-displayName: Everywhere Inference Apps
  - name: File Shares
    x-displayName: File Shares
  - name: Floating IPs
    x-displayName: Floating IPs
  - name: Function as a Service
    x-displayName: Function as a Service
  - name: GPU Bare Metal
    x-displayName: GPU Bare Metal
  - name: GPU Virtual
    x-displayName: GPU Virtual
  - name: IP Ranges
    x-displayName: IP Ranges
  - name: Images
    x-displayName: Images
  - name: Instances
    x-displayName: Instances
  - name: Load Balancers
    x-displayName: Load Balancers
  - name: Logging
    x-displayName: Logging
  - name: Managed Kubernetes
    x-displayName: Managed Kubernetes
  - name: Managed PostgreSQL
    x-displayName: Managed PostgreSQL
  - name: Networks
    x-displayName: Networks
  - name: Placement Groups
    x-displayName: Placement Groups
  - name: Projects
    x-displayName: Projects
  - name: Quotas
    x-displayName: Quotas
  - name: Regions
    x-displayName: Regions
  - name: Registry
    x-displayName: Registry
  - name: Reservations
    x-displayName: Reservations
  - name: Reserved IPs
    x-displayName: Reserved IPs
  - name: Routers
    x-displayName: Routers
  - name: SSH Keys
    x-displayName: SSH Keys
  - name: Secrets
    x-displayName: Secrets
  - name: Security Groups
    x-displayName: Security Groups
  - name: Snapshot Schedules
    x-displayName: Snapshot Schedules
  - name: Snapshots
    x-displayName: Snapshots
  - name: Tasks
    x-displayName: Tasks
  - name: User Actions
    x-displayName: User Actions
  - name: User Role Assignments
    x-displayName: User Role Assignments
  - name: Volumes
    x-displayName: Volumes
paths:
  /cloud/v1/users/assignments:
    post:
      tags:
        - User Role Assignments
      summary: Create role assignment
      description: Assign a role to an existing user in the specified scope.
      operationId: AssignmentHandler.post
      parameters: []
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RequestAssignmentSerializer'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RoleAssignmentSerializer'
      x-codeSamples:
        - lang: Python
          source: |-
            import os
            from gcore import Gcore

            client = Gcore(
                api_key=os.environ.get("GCORE_API_KEY"),  # This is the default and can be omitted
            )
            role_assignment = client.cloud.users.role_assignments.create(
                role="ClientAdministrator",
                user_id=777,
            )
            print(role_assignment.id)
        - lang: Go
          source: "package main\n\nimport (\n\t\"context\"\n\t\"fmt\"\n\n\t\"github.com/G-Core/gcore-go\"\n\t\"github.com/G-Core/gcore-go/cloud\"\n\t\"github.com/G-Core/gcore-go/option\"\n)\n\nfunc main() {\n\tclient := gcore.NewClient(\n\t\toption.WithAPIKey(\"My API Key\"),\n\t)\n\troleAssignment, err := client.Cloud.Users.RoleAssignments.New(context.TODO(), cloud.UserRoleAssignmentNewParams{\n\t\tRole:   cloud.UserRoleAssignmentNewParamsRoleClientAdministrator,\n\t\tUserID: 777,\n\t})\n\tif err != nil {\n\t\tpanic(err.Error())\n\t}\n\tfmt.Printf(\"%+v\\n\", roleAssignment.ID)\n}\n"
components:
  schemas:
    RequestAssignmentSerializer:
      properties:
        client_id:
          anyOf:
            - type: integer
            - type: 'null'
          default: null
          description: Client ID. Required if `project_id` is specified
          examples:
            - 8
          title: Client Id
        project_id:
          anyOf:
            - type: integer
            - type: 'null'
          default: null
          description: Project ID
          examples:
            - null
          title: Project Id
        role:
          $ref: '#/components/schemas/CustomerAssignableRole'
          description: User role
          examples:
            - ClientAdministrator
        user_id:
          description: User ID
          example: 777
          examples:
            - 777
          title: User Id
          type: integer
      required:
        - user_id
        - role
      title: AssignRoleRequestSchema schema
      type: object
    RoleAssignmentSerializer:
      properties:
        assigned_by:
          anyOf:
            - type: integer
            - type: 'null'
          title: Assigned By
        client_id:
          description: Client ID
          example: 123
          examples:
            - 123
          title: Client Id
          type: integer
        created_at:
          description: Created timestamp
          example: '2019-06-25T08:42:42Z'
          examples:
            - '2019-06-25T08:42:42Z'
          format: date-time
          title: Created At
          type: string
        id:
          description: Assignment ID
          example: 12
          examples:
            - 12
          title: Id
          type: integer
        project_id:
          anyOf:
            - type: integer
            - type: 'null'
          description: Project ID
          examples:
            - 123
          title: Project Id
        role:
          $ref: '#/components/schemas/CustomerAssignableRole'
          description: User role
          examples:
            - ClientAdministrator
        updated_at:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
          description: Updated timestamp
          examples:
            - '2019-06-25T08:42:42Z'
          title: Updated At
        user_id:
          description: User ID
          example: 123
          examples:
            - 123
          title: User Id
          type: integer
      required:
        - id
        - user_id
        - role
        - client_id
        - project_id
        - assigned_by
        - created_at
        - updated_at
      title: Role assignments schema
      type: object
    CustomerAssignableRole:
      enum:
        - ClientAdministrator
        - InternalNetworkOnlyUser
        - Observer
        - ProjectAdministrator
        - User
      title: CustomerAssignableRole
      type: string
  securitySchemes:
    APIKey:
      description: >-
        API key for authentication. Make sure to include the word `apikey`,
        followed by a single space and then your token.

        Example: `apikey 1234$abcdef`
      type: apiKey
      in: header
      name: Authorization

````