# API Patch Role - Entitlements

**URL:** <https://developer.sailpoint.com/discuss/t/api-patch-role-entitlements/72960>\
**Category:** SHF Discussion and Questions\
**Tags:** apis, identity-security-cloud, roles, entitlements\
**Created:** [July 16, 2024, 6:06pm UTC](https://developer.sailpoint.com/discuss/t/api-patch-role-entitlements/72960 "2024-07-16T18:06:15Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![RNewton](https://avatars.discourse-cdn.com/v4/letter/r/58f4c7/32.png) [@RNewton](https://developer.sailpoint.com/discuss/u/RNewton)\
**Post date:** [July 16, 2024, 6:06pm UTC](https://developer.sailpoint.com/discuss/t/api-patch-role-entitlements/72960/1 "2024-07-16T18:06:15Z")

</div>

Is it possible to patch entitlements to a role? [patch-role | SailPoint Developer Community](https://developer.sailpoint.com/docs/api/v3/patch-role) doesn’t list entitlements as a patchable field, but it and the beta version both note that entitlements can be seen in the response, suggesting it might just be a documentation issue.

If it is supported, here’s what I"m passing:

Header  
Key Value

* * *

Content-Type application/json-patch+json  
Accept application/json  
Authorization Bearer xyz

Body

```auto
{
    "path": "/entitlements",
    "op": "add",
    "value": [
                  {
                      "id": "2c91808677bb34ce0177bef124090a93",
                      "type": "ENTITLEMENT"
                  },
                  {
                      "id": "2c918087771b663c01773a99aa5f2199",
                      "type": "ENTITLEMENT"
                  },
                  {
                      "id": "2c918087771b663c01773a9956ca1f9a",
                      "type": "ENTITLEMENT"
                  }
              ]
}

```

and my error

```auto
Invoke-RestMethod : {"messages":[{"localeOrigin":"REQUEST","locale":"en-US","text":"The request could not be parsed."},{"localeOrigin":"DEFAULT","locale":"en-US","text":"The request could not 
be parsed."}],"trackingId":"dd5a6794e4414b1bbc541293399b7107","detailCode":"400.0 Bad request syntax"}

```

---

<div class="post-metadata">

**Author:** ![bcariaga](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/bcariaga/32/1890_2.png) [@bcariaga](https://developer.sailpoint.com/discuss/u/bcariaga)\
**Post date:** [July 16, 2024, 6:18pm UTC](https://developer.sailpoint.com/discuss/t/api-patch-role-entitlements/72960/2 "2024-07-16T18:18:51Z")

</div>

I’m not sure if this field is supported as you mentioned from the documentation. In the body of your request, you must have the body begin as an array:

```auto
[
    {
        "path": "/entitlements",
        "op": "add",
        "value": [
            {
                "id": "2c91808677bb34ce0177bef124090a93",
                "type": "ENTITLEMENT"
            },
            {
                "id": "2c918087771b663c01773a99aa5f2199",
                "type": "ENTITLEMENT"
            },
            {
                "id": "2c918087771b663c01773a9956ca1f9a",
                "type": "ENTITLEMENT"
            }
        ]
    }
]

```

---

<div class="post-metadata">

**Author:** ![RNewton](https://avatars.discourse-cdn.com/v4/letter/r/58f4c7/32.png) [@RNewton](https://developer.sailpoint.com/discuss/u/RNewton)\
**Post date:** [July 16, 2024, 6:47pm UTC](https://developer.sailpoint.com/discuss/t/api-patch-role-entitlements/72960/3 "2024-07-16T18:47:39Z")

</div>

Trying to rule out false positives by patching access profiles and still having issues with this body.

{  
“path”: “/accessProfiles”,  
“op”: “add”,  
“value”: [  
{  
“id”: “8815f51aa6b948d78be739ac428a73d7”,  
“type”: “ACCESS\_PROFILE”  
}  
]  
}

URL: [https://tenant.api.identitynow.com/beta/roles/14fa44ed9fa5498f85541c58774251ef](https://tenant.api.identitynow.com/beta/roles/14fa44ed9fa5498f85541c58774251ef)

Invoke-RestMethod : {“messages”:[{“localeOrigin”:“DEFAULT”,“locale”:“en-US”,“text”:“The request could not be parsed.”},{“localeOrigin”:“REQUEST”,“locale”:“en-US”,“text”:“The request could not  
be parsed.”}],“trackingId”:“dee22dcd3c6649268da3d2a196ff00fb”,“detailCode”:“400.0 Bad request syntax”}  
At line:1 char:15

- … $response = Invoke-RestMethod $url -Method ‘PATCH’ -Headers $headers

Any thoughts on what could be happening? Wrapped the value in an array like you pointed out but same issue pretty much.

---

<div class="post-metadata">

**Author:** ![awyss](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/awyss/32/37310_2.png) [@awyss](https://developer.sailpoint.com/discuss/u/awyss)\
**Post date:** [July 16, 2024, 7:29pm UTC](https://developer.sailpoint.com/discuss/t/api-patch-role-entitlements/72960/4 "2024-07-16T19:29:36Z")

</div>

Hi Russell, you might try adding the name of the access profile to your patch call as the object is incomplete.

```auto
{
	"id": "adace7fcee444aa282f5f17db9a53994",
	"type": "ACCESS_PROFILE",
	"name": "Telecom System Access"
}

```

---

<div class="post-metadata">

**Author:** ![bcariaga](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/bcariaga/32/1890_2.png) [@bcariaga](https://developer.sailpoint.com/discuss/u/bcariaga)\
**Post date:** [July 16, 2024, 9:05pm UTC](https://developer.sailpoint.com/discuss/t/api-patch-role-entitlements/72960/5 "2024-07-16T21:05:14Z")

</div>

Thanks, @awyss - That seemed to allow the requests to go through on my end. Some APIs don’t require name, but good to know that this one does.

I was able to get this to work for entitlements with this body:

```auto
[
    {
        "op": "add",
        "path": "/entitlements",
        "value": [
            {
                "id": "3831fe1f9e74476085bdd2be65c6af60",
                "type": "ENTITLEMENT",
                "name": "AccountingGeneral"
            }
        ]
    }
]

```

The operation seems to work as a replace instead of an add though.

---

<div class="post-metadata">

**Author:** ![neeraj99](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/neeraj99/32/14001_2.png) [@neeraj99](https://developer.sailpoint.com/discuss/u/neeraj99)\
**Post date:** [July 17, 2024, 11:11am UTC](https://developer.sailpoint.com/discuss/t/api-patch-role-entitlements/72960/6 "2024-07-17T11:11:20Z")

</div>

Hey @RNewton, So the main reason for request failing is missing “**[]**”  
So the body should be sent as mentioned below, the main reason you are getting that error is due to missing opening and closing square brackets “**[]**”:  
See the below attached image and highlighted part in order to successfully add the Access profile/entitlement

```auto
[
    {
        "path": "/accessProfiles",
        "op": "add",
        "value": [
            {
                "id": "ca7a66e5dd524836b25eef82ebbdb196",
                "type": "ACCESS_PROFILE"
            }
        ]
    }
]

```

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/2/201e7b6da6b846c6d31d80066ab2339e6210ddf0.png)

Hope this helps…

---

<div class="post-metadata">

**Author:** ![RNewton](https://avatars.discourse-cdn.com/v4/letter/r/58f4c7/32.png) [@RNewton](https://developer.sailpoint.com/discuss/u/RNewton)\
**Post date:** [July 17, 2024, 5:08pm UTC](https://developer.sailpoint.com/discuss/t/api-patch-role-entitlements/72960/7 "2024-07-17T17:08:18Z")

</div>

Thank you all so much. Wrapping the value into brackets was the answer I needed, and indeed you can patch through entitlements.

Sailpoint admins - if you’re looking, may want to update the documentation to explicitly note that.

---

<div class="post-metadata">

**Author:** ![TJ21](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/tj21/32/8407_2.png) [@TJ21](https://developer.sailpoint.com/discuss/u/TJ21)\
**Post date:** [July 17, 2024, 7:37pm UTC](https://developer.sailpoint.com/discuss/t/api-patch-role-entitlements/72960/8 "2024-07-17T19:37:28Z")

</div>

Worked for me .

 ![Screenshot 2024-07-17 153541](https://global.discourse-cdn.com/sailpoint/original/2X/5/51218dce6d1c15537cd9383cad8785e1aba54955.png)  
Thank You

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [September 15, 2024, 7:37pm UTC](https://developer.sailpoint.com/discuss/t/api-patch-role-entitlements/72960/9 "2024-09-15T19:37:59Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
