## Site permissions

`PUT /v1/sites/:id/permissions`

WARNING: fully replaces site rights. Non-empty rights is required; access codes may be any non-empty string (U42, G42, DR42, AU). read is added automatically; denied overrides all other operations. An empty operations array for one code is accepted: Bitrix24 adds read. Assignments cannot be read back: my-permissions shows only the current user. To explicitly clear all rights, use DELETE /v1/sites/:id/permissions without a body. Clearing restores default access. Requires administrator privileges and a tariff with extended permissions: IS_NOT_ADMIN / FEATURE_NOT_AVAIL return 403. id=0 is forbidden.

## Parameters

| Parameter | Type | Required | Description |
|---|---|---|---|
| id | integer | yes | Positive safe integer site ID |
| scope | string | no | KNOWLEDGE / GROUP / MAINPAGE; omit for ordinary sites |
| rights | object | PUT only | Non-empty access-code dictionary of operation arrays |

Requires landing key scope. A knowledge-base or group site can be invisible without scope.

## curl

```bash
curl -X PUT "https://vibecode.bitrix24.com/v1/sites/42/permissions" -H "X-Api-Key: YOUR_API_KEY" -H 'Content-Type: application/json' -d '{"rights":{"U42":["edit"]}}'
```

## JavaScript

```javascript
const response = await fetch("https://vibecode.bitrix24.com/v1/sites/42/permissions", {
  method: "PUT",
  headers: { "X-Api-Key": "YOUR_API_KEY", "Content-Type": "application/json" },
  body: JSON.stringify({ rights: { U42: ["edit"] } }),
});
const data = await response.json();
```

## Response

```json
{
  "success": true,
  "data": {
    "updated": true
  }
}
```

## Errors

400 INVALID_PARAMS / INVALID_SCOPE; 401 TOKEN_MISSING; 403 SCOPE_DENIED / BITRIX_ACCESS_DENIED; 404 ENTITY_NOT_FOUND; 409 LANDING_MODULE_NOT_ENABLED; 422 BITRIX_ERROR; 429 rate limits; 502 / 503 upstream or transport refusal. Write operations with a READONLY key return 403 WRITE_BLOCKED_READONLY_KEY.

Bitrix24: `landing.site.setRights`.

[Sites](/docs/entities/sites)
