Get Available Roles
curl --request GET \
--url https://api.rolla.xyz/api/v1/external/teams/roles \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.rolla.xyz/api/v1/external/teams/roles"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.rolla.xyz/api/v1/external/teams/roles', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.rolla.xyz/api/v1/external/teams/roles",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.rolla.xyz/api/v1/external/teams/roles"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.rolla.xyz/api/v1/external/teams/roles")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.rolla.xyz/api/v1/external/teams/roles")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"status": 200,
"message": "Available roles retrieved successfully",
"success": true,
"data": {
"roles": [
{
"id": "9a7b6c5d-4e3f-4a1b-8c9d-8e7f6a5b4c3d",
"name": "approver",
"description": "Can approve transactions and manage beneficiaries, but cannot initiate outbound sends"
},
{
"id": "fc4cd36d-f81c-4971-a23f-688162e14d21",
"name": "business_admin",
"description": "Full access to business operations, same as business owner"
},
{
"id": "21302ed1-0e63-44e6-bb02-8db6baa2efcd",
"name": "initiator",
"description": "Can initiate transactions including sending money, but cannot approve them"
}
]
}
}{
"status": 400,
"message": "No active business found"
}{
"status": 400,
"message": "Validation failed",
"code": "ACCOUNT_RESTRICTED",
"errors": [
{
"path": [
"amount"
],
"message": "amount must be a whole number of smallest currency units (e.g. cents)"
}
]
}Teams
Get Available Roles
Lists the roles that can be assigned when inviting a team member or changing an existing member’s role, sorted by name. Business owners and business admins see the full assignable set (approver, business_admin, initiator); every other role sees initiator only. business_owner and individual_owner are never returned.
GET
/
teams
/
roles
Get Available Roles
curl --request GET \
--url https://api.rolla.xyz/api/v1/external/teams/roles \
--header 'X-API-Key: <api-key>'import requests
url = "https://api.rolla.xyz/api/v1/external/teams/roles"
headers = {"X-API-Key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'X-API-Key': '<api-key>'}};
fetch('https://api.rolla.xyz/api/v1/external/teams/roles', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.rolla.xyz/api/v1/external/teams/roles",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.rolla.xyz/api/v1/external/teams/roles"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("X-API-Key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.rolla.xyz/api/v1/external/teams/roles")
.header("X-API-Key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.rolla.xyz/api/v1/external/teams/roles")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["X-API-Key"] = '<api-key>'
response = http.request(request)
puts response.read_body{
"status": 200,
"message": "Available roles retrieved successfully",
"success": true,
"data": {
"roles": [
{
"id": "9a7b6c5d-4e3f-4a1b-8c9d-8e7f6a5b4c3d",
"name": "approver",
"description": "Can approve transactions and manage beneficiaries, but cannot initiate outbound sends"
},
{
"id": "fc4cd36d-f81c-4971-a23f-688162e14d21",
"name": "business_admin",
"description": "Full access to business operations, same as business owner"
},
{
"id": "21302ed1-0e63-44e6-bb02-8db6baa2efcd",
"name": "initiator",
"description": "Can initiate transactions including sending money, but cannot approve them"
}
]
}
}{
"status": 400,
"message": "No active business found"
}{
"status": 400,
"message": "Validation failed",
"code": "ACCOUNT_RESTRICTED",
"errors": [
{
"path": [
"amount"
],
"message": "amount must be a whole number of smallest currency units (e.g. cents)"
}
]
}Retrieve the list of roles available for assignment when inviting team members or assigning a role to an existing member.
The roles returned depend on the caller’s own role. Business Owners and Business Admins receive the full assignable set (
approver, business_admin, initiator); other roles only see initiator. The business_owner and individual_owner roles are reserved and never returned by this endpoint. Roles come back sorted by name.
Example Request
curl -X GET "https://api.rolla.xyz/api/v1/external/teams/roles" \
-H "X-API-Key: your_api_key_here"
Example Response
{
"status": 200,
"message": "Available roles retrieved successfully",
"success": true,
"data": {
"roles": [
{
"id": "9a7b6c5d-4e3f-4a1b-8c9d-8e7f6a5b4c3d",
"name": "approver",
"description": "Can approve transactions and manage beneficiaries, but cannot initiate outbound sends"
},
{
"id": "fc4cd36d-f81c-4971-a23f-688162e14d21",
"name": "business_admin",
"description": "Full access to business operations, same as business owner"
},
{
"id": "21302ed1-0e63-44e6-bb02-8db6baa2efcd",
"name": "initiator",
"description": "Can initiate transactions including sending money, but cannot approve them"
}
]
}
}
Use the role
id from this response when inviting a team member via the /teams/invite endpoint or assigning a role via /teams/members/{userId}/role.Role Reference
| Role | Send money | Approve withdrawals | Approve payments | Manage beneficiaries | Manage team | Assignable by |
|---|---|---|---|---|---|---|
| Business Owner | Yes | Yes | Yes | Yes | Yes | — (set at signup) |
| Business Admin | Yes | Yes | Yes | Yes | Yes | Owner |
| Approver | — | Yes | Yes | Yes | — | Owner, Admin |
| Initiator | Yes | — | — | Yes | — | Owner, Admin, Initiator |
- Initiator — Can initiate transactions including sending money, but cannot approve them. (Formerly named Collaborator.)
- Approver — Can approve transactions and manage beneficiaries, but cannot initiate outbound sends. Only Business Owners and Business Admins can assign this role.
Approving a transaction (via
POST /wallet/approve-transaction) is gated on the approve_withdrawals permission, not on a specific role name. Business Owners, Business Admins, and Approvers all satisfy it.Migration note: The
collaborator role has been renamed to initiator — permissions are unchanged. A new approver role is now available. If you string-match on role names anywhere in your integration, map "collaborator" to "initiator" and add an "approver" branch. GET /teams/roles no longer returns individual_owner in business contexts.