Skip to content
POST /unified/file-storage/permissions

Query Parameters

Refer Specifying query parameters in Truto APIs

Show Truto-specific parameters
integrated_account_idstring · uuid
required·

The ID of the integrated account to use for the request.

Example: 62f44730-dd91-461e-bd6a-aedd9e0ad79d
truto_response_formatstring

The format of the response.

  • unified returns the response with unified mappings applied.
  • raw returns the unprocessed, raw response from the remote API.
  • normalized applies the unified mappings and returns the data in a normalized format.
  • stream returns the response as a stream, which is ideal for transmitting large datasets, files, or binary data. Using streaming mode helps to efficiently handle large payloads or real-time data flows without requiring the entire data to be buffered in memory.
  • debug returns the final unified result alongside raw remote fetch information. The response is an envelope containing result (identical to unified mode output) and debug (with requestUrl, requestOptions, data, responseHeaders, and for list operations: nextCursor, isLooping, isEmptyResult, resultCount). debug is null for static responses or when truto_skip_api_call=true.

Defaults to unified.

Example: unified
Possible values:
unifiedrawnormalizedstreamdebug
truto_ignore_remote_databoolean

Excludes the remote_data attribute from the response.

truto_enforce_write_schemaboolean

Validates the request body against this method's request_body_schema before the request is sent to the underlying integration. When a field marked required is missing, Truto responds 400 with the missing field names under truto_error_insight.missing_required_body_fields instead of forwarding the call. Only the fields documented in request_body_schema are checked. A body carrying a non-empty remote_data object is forwarded unchecked, because remote_data is merged into the provider request and may already carry the required values. A field the mapping always supplies through its default body is treated as present, and a field that is only conditionally required is reported under truto_error_insight.conditionally_required_body_fields rather than rejected. Some integrations declare fields required on update that the provider only requires on create; check meta/{method} for the resource before enabling this on update calls. If you sent an Idempotency-Key and the request was rejected, use a fresh key when you retry with a corrected body: the idempotency cache is keyed on the integrated account, path and key only — it ignores the query string and the body — so reusing the key replays the rejection. Defaults to false, which forwards the request as-is.

truto_exclude_fieldsstring[]

Array of fields to exclude from the response.

Example: truto_exclude_fields[]=id&truto_exclude_fields[]=name
remote_queryRecord<string, any>

Query parameters to pass to the underlying API without any transformations. Refer this guide to see how to structure the query parameters.

Example: remote_query[foo]=bar

Request Body

Refer Writing data using Unified APIs

drive_itemobject

The drive item for which the permission is created.

1 supported1 required
Box
required
idstring
required·

Unique identifier for the drive item.

typestring
required·

The type of drive item.

Possible values:
filefolder
permissionsstring[]

The list of permissions

4 supported4 required
Box
required
Google Drive
required
Google Sheets
required
SharePoint
required
Possible values:
ownerorganizerfileOrganizerwritercommenterreaderownerorganizerfileOrganizerwritercommenterreader
remote_dataRecord<string, any>

Any additional data that should be passed as part of the request body. This data is not transformed by Truto and is passed as is to the remote API.

resourcesobject[]

The resources for which the permission is applicable.

4 supported3 required
Google Drive
required
Google Sheets
required
SharePoint
required
Box
supported
idstring
required·

Unique identifier for the resource

typestring
required·

Type of the resource

Possible values:
drive_itemdrivedrive_itemdrive_itemdrivedrive_item
send_notificationboolean

Send Google's sharing notification email. Defaults to false.

2 supported
Google Drive
supported
Google Sheets
supported
userobject

The user for whom the permission is applicable.

4 supported4 required
Box
required
Google Drive
required
Google Sheets
required
SharePoint
required
emailstring

Email address of the user or principal

emailsobject[]

Email addresses of the user or principal

3 properties
emailstring

The email address

is_primaryboolean

Whether the email address is primary

typestring

The type of email address

idstring

Unique identifier for the user or principal

typestring

Defaults to user.

Possible values:
usergroupusergroupdomainanyoneusergroupdomainanyone

Response Body

idstring

Unique identifier for the permission

4 supported
Box
supported
Google Drive
supported
Google Sheets
supported
SharePoint
supported
permissionsstring[]

The list of permissions

4 supported
Box
supported
Google Drive
supported
Google Sheets
supported
SharePoint
supported
remote_dataRecord<string, any>

Raw data returned from the remote API call.

resourcesobject[]

The resources for which the permission is applicable for

4 supported
Box
supported
Google Drive
supported
Google Sheets
supported
SharePoint
supported
idstring

Unique identifier for the resource

typestring

Type of the resource

Possible values:
drive_itemdrive
userobject

The user for whom the permission is applicable for

4 supported
Box
supported
Google Drive
supported
Google Sheets
supported
SharePoint
supported
idstring

Unique identifier for the user

truto unified file-storage permissions \
  -m create \
  -a '<integrated_account_id>' \
  -b '{
  "drive_item": {},
  "user": {},
  "permissions": [],
  "resources": [],
  "send_notification": true,
  "remote_data": {}
}' \
  -o json
import Truto from '@truto/truto-ts-sdk';

const truto = new Truto({
  token: '<your_api_token>',
});

const result = await truto.unifiedApi.create(
  'file-storage',
  'permissions',
  {
  "drive_item": {},
  "user": {},
  "permissions": [],
  "resources": [],
  "send_notification": true,
  "remote_data": {}
},
  { integrated_account_id: '<integrated_account_id>' }
);

console.log(result);
import asyncio
from truto_python_sdk import TrutoApi

truto_api = TrutoApi(token="<your_api_token>")

async def main():
    result = await truto_api.unified_api.create(
        "file-storage",
        "permissions",
        {
        "drive_item": {},
        "user": {},
        "permissions": [],
        "resources": [],
        "send_notification": True,
        "remote_data": {}
},
        {"integrated_account_id": "<integrated_account_id>"}
    )
    print(result)

asyncio.run(main())
curl -X POST 'https://api.truto.one/unified/file-storage/permissions?integrated_account_id=<integrated_account_id>' \
  -H 'Authorization: Bearer <your_api_token>' \
  -H 'Content-Type: application/json' \
  -d '{
  "drive_item": {},
  "user": {},
  "permissions": [],
  "resources": [],
  "send_notification": true,
  "remote_data": {}
}'
const integratedAccountId = '<integrated_account_id>';

const body = {
  "drive_item": {},
  "user": {},
  "permissions": [],
  "resources": [],
  "send_notification": true,
  "remote_data": {}
};

const response = await fetch(`https://api.truto.one/unified/file-storage/permissions?integrated_account_id=${integratedAccountId}`, {
  method: 'POST',
  headers: {
    'Authorization': 'Bearer <your_api_token>',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify(body),
});

const data = await response.json();
console.log(data);
import requests

url = "https://api.truto.one/unified/file-storage/permissions"
headers = {
    "Authorization": "Bearer <your_api_token>",
    "Content-Type": "application/json",
}
params = {
    "integrated_account_id": "<integrated_account_id>"
}
payload = {
    "drive_item": {},
    "user": {},
    "permissions": [],
    "resources": [],
    "send_notification": True,
    "remote_data": {}
}

response = requests.post(url, headers=headers, params=params, json=payload)
print(response.json())