## Set the permission to add members

`PUT /v1/chats/:dialogId/permissions/users-add`

Sets who in a chat can add members: all members, managers and the owner, or the owner only.

## Parameters

| Parameter | Type | Required | Description |
|----------|-----|:-----:|---------|
| `dialogId` (path) | string | yes | Dialog ID: `chatXXX` for a group chat, a numeric user ID for private messages, `me` — the current user's personal dialog. A CRM entity chat is found via [Find a CRM entity chat](/docs/chats/discovery/find) |

The operation takes no query parameters: any parameter in the query string is refused with `400 INVALID_PARAMS`.

## Request fields (body)

| Field | Type | Required | Description |
|------|-----|:-----:|---------|
| `rightsLevel` | string | yes | Who holds the permission: `MEMBER` — all members, `MANAGER` — managers and the owner, `OWNER` — the owner only. Case does not matter: `manager` and `MANAGER` are equivalent |

Other body fields are refused with `400 INVALID_PARAMS`, and the message names the extra field.

Right after a group chat is [created](/docs/chats/management/create), the permission value is `MEMBER`.

## Examples

The examples let managers and the owner add members.

### curl — personal key

```bash
curl -X PUT https://vibecode.bitrix24.com/v1/chats/chat2741/permissions/users-add \
  -H "X-Api-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"rightsLevel": "MANAGER"}'
```

### curl — OAuth application

```bash
curl -X PUT https://vibecode.bitrix24.com/v1/chats/chat2741/permissions/users-add \
  -H "X-Api-Key: YOUR_APP_KEY" \
  -H "Authorization: Bearer USER_SESSION_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"rightsLevel": "MANAGER"}'
```

### JavaScript — personal key

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/chats/chat2741/permissions/users-add', {
  method: 'PUT',
  headers: {
    'X-Api-Key': 'YOUR_API_KEY',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({ rightsLevel: 'MANAGER' }),
})

const { success } = await res.json()
```

### JavaScript — OAuth application

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/chats/chat2741/permissions/users-add', {
  method: 'PUT',
  headers: {
    'X-Api-Key': 'YOUR_APP_KEY',
    'Authorization': 'Bearer USER_SESSION_TOKEN',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({ rightsLevel: 'MANAGER' }),
})

const { success } = await res.json()
```

## Response fields

| Field | Type | Description |
|------|-----|---------|
| `success` | boolean | Always `true` on success |
| `data` | boolean | `true` — the permission is saved |

## Response example

```json
{
  "success": true,
  "data": true
}
```

## Error response example

400 — the request sets `rightsLevel` to `"NONE"`, a value outside the operation's set:

```json
{
  "success": false,
  "error": {
    "code": "INVALID_PARAMS",
    "message": "Body field `rightsLevel` must be one of MEMBER, OWNER, MANAGER (any case)."
  }
}
```

## Errors

| HTTP | Code | Description |
|------|-----|---------|
| 400 | `INVALID_PARAMS` | The body has no `rightsLevel`, or the value is not in the operation's set: `MEMBER`, `MANAGER`, `OWNER`. The message lists the allowed values |
| 400 | `INVALID_PARAMS` | The body has a field other than `rightsLevel` |
| 400 | `INVALID_PARAMS` | The request body is not a JSON object |
| 400 | `INVALID_PARAMS` | The query string has a parameter |
| 403 | `BITRIX_ACCESS_DENIED` | Bitrix24 refused: the user is not a chat member, or the `settings` permission does not let them change permissions |
| 422 | `BITRIX_ERROR` | Bitrix24 returned an error, and the Bitrix24 code is in `error.b24Code`. A missing chat gives `CHAT_NOT_FOUND` |
| 403 | `SCOPE_DENIED` | The API key lacks the `im` scope |
| 403 | `WRITE_BLOCKED_READONLY_KEY` | The key is read-only — changing permissions counts as a write |
| 401 | `TOKEN_MISSING` | The API key has no configured Bitrix24 tokens |
| 502 | `ME_ALIAS_RESOLUTION_FAILED` | `dialogId=me` — the current user's ID could not be resolved |
| 502 | `BITRIX_UNAVAILABLE` | Bitrix24 is unavailable or returned a server error |

All `400` refusals happen before the Bitrix24 call.

Full list of common API errors — [Errors](/docs/errors).

## Known specifics

**Current value.** The `permissions.manageUsersAdd` field of the [Dialog details](/docs/chats/discovery/get) response returns the permission in lower case, for example `manager`.

## See also

- [Set the permission to post messages](/docs/chats/management/permissions-messages)
- [Set the permission to invite guests](/docs/chats/management/permissions-guest-invites)
- [Set the permission to change chat settings](/docs/chats/management/permissions-settings)
- [Set the permission to change chat appearance](/docs/chats/management/permissions-ui)
- [Set the permission to remove members](/docs/chats/management/permissions-users-delete)
- [Members](/docs/chats/members)
- [Dialog details](/docs/chats/discovery/get)
