For AI agents: markdown of this page — /docs-content-en/chats/management/permissions-guest-invites.md documentation index — /llms.txt
Set the permission to invite guests
PUT /v1/chats/:dialogId/permissions/guest-invites
Sets who in a chat can invite guests: all members, managers and the owner, the owner only, or nobody.
Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
dialogId (path) |
string | yes | Dialog ID: chatXXX for a group chat, a numeric user ID for private messages, me — the current user's personal dialog. A CRM entity chat is found via Find a CRM entity chat |
The operation takes no query parameters: any parameter in the query string is refused with 400 INVALID_PARAMS.
Request fields (body)
| Field | Type | Required | Description |
|---|---|---|---|
rightsLevel |
string | yes | Who holds the permission: MEMBER — all members, MANAGER — managers and the owner, OWNER — the owner only, NONE — nobody. Case does not matter: manager and MANAGER are equivalent |
Other body fields are refused with 400 INVALID_PARAMS, and the message names the extra field.
Right after a group chat is created, the permission value is MANAGER.
Examples
The examples let only the owner invite guests.
curl — personal key
curl -X PUT https://vibecode.bitrix24.com/v1/chats/chat2741/permissions/guest-invites \
-H "X-Api-Key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"rightsLevel": "OWNER"}'
curl — OAuth application
curl -X PUT https://vibecode.bitrix24.com/v1/chats/chat2741/permissions/guest-invites \
-H "X-Api-Key: YOUR_APP_KEY" \
-H "Authorization: Bearer USER_SESSION_TOKEN" \
-H "Content-Type: application/json" \
-d '{"rightsLevel": "OWNER"}'
JavaScript — personal key
const res = await fetch('https://vibecode.bitrix24.com/v1/chats/chat2741/permissions/guest-invites', {
method: 'PUT',
headers: {
'X-Api-Key': 'YOUR_API_KEY',
'Content-Type': 'application/json',
},
body: JSON.stringify({ rightsLevel: 'OWNER' }),
})
const { success } = await res.json()
JavaScript — OAuth application
const res = await fetch('https://vibecode.bitrix24.com/v1/chats/chat2741/permissions/guest-invites', {
method: 'PUT',
headers: {
'X-Api-Key': 'YOUR_APP_KEY',
'Authorization': 'Bearer USER_SESSION_TOKEN',
'Content-Type': 'application/json',
},
body: JSON.stringify({ rightsLevel: 'OWNER' }),
})
const { success } = await res.json()
Response fields
| Field | Type | Description |
|---|---|---|
success |
boolean | Always true on success |
data |
boolean | true — the permission is saved |
Response example
{
"success": true,
"data": true
}
Error response example
400 — the request sets rightsLevel to "ALL", a value outside the operation's set:
{
"success": false,
"error": {
"code": "INVALID_PARAMS",
"message": "Body field `rightsLevel` must be one of MANAGER, NONE, MEMBER, OWNER (any case)."
}
}
Errors
| HTTP | Code | Description |
|---|---|---|
| 400 | INVALID_PARAMS |
The body has no rightsLevel, or the value is not in the operation's set: MEMBER, MANAGER, OWNER, NONE. The message lists the allowed values |
| 400 | INVALID_PARAMS |
The body has a field other than rightsLevel |
| 400 | INVALID_PARAMS |
The request body is not a JSON object |
| 400 | INVALID_PARAMS |
The query string has a parameter |
| 403 | BITRIX_ACCESS_DENIED |
Bitrix24 refused: the user is not a chat member, or the settings permission does not let them change permissions |
| 422 | BITRIX_ERROR |
Bitrix24 returned an error, and the Bitrix24 code is in error.b24Code. A missing chat gives CHAT_NOT_FOUND |
| 403 | SCOPE_DENIED |
The API key lacks the im scope |
| 403 | WRITE_BLOCKED_READONLY_KEY |
The key is read-only — changing permissions counts as a write |
| 401 | TOKEN_MISSING |
The API key has no configured Bitrix24 tokens |
| 502 | ME_ALIAS_RESOLUTION_FAILED |
dialogId=me — the current user's ID could not be resolved |
| 502 | BITRIX_UNAVAILABLE |
Bitrix24 is unavailable or returned a server error |
All 400 refusals happen before the Bitrix24 call.
Full list of common API errors — Errors.
Known specifics
Current value. The permissions.manageGuestInvites field of the Dialog details response returns the permission in lower case, for example owner.