> ## Documentation Index
> Fetch the complete documentation index at: https://docs.linkutm.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

> Which workspace role may call which endpoint, and what each permission unlocks.

Every write endpoint is guarded by a named permission. Permissions are not assigned individually —
they come from the caller's role on their workspace membership. An API key inherits the permissions
of the member who created it.

## Roles

| Permission | Owner | Admin | Member | Viewer |
| - | :-: | :-: | :-: | :-: |
| `links.create` | ✅ | ✅ | ✅ | — |
| `links.edit` | ✅ | ✅ | ✅ | — |
| `links.delete` | ✅ | ✅ | — | — |
| `links.import` | ✅ | ✅ | — | — |
| `domains.create` | ✅ | ✅ | — | — |
| `domains.update` | ✅ | ✅ | — | — |
| `domains.delete` | ✅ | ✅ | — | — |
| `analytics.view` | ✅ | ✅ | ✅ | ✅ |
| `data.export` | ✅ | ✅ | ✅ | — |
| `utm_templates.create` / `.edit` / `.delete` | ✅ | ✅ | ✅ | — |
| `utm_parameters.create` / `.edit` / `.delete` | ✅ | ✅ | ✅ | — |
| `utm_rules.manage` | ✅ | ✅ | — | — |
| `team.invite` / `team.remove` | ✅ | ✅ | — | — |
| `workspace.settings_edit` | ✅ | ✅ | — | — |
| `api_keys.manage` | ✅ | ✅ | — | — |
| `billing.manage` | ✅ | — | — | — |

## Which permission each endpoint needs

| Permission | Endpoints |
| - | - |
| `links.create` | `POST /links`, `POST /folders`, `POST /tags` |
| `links.edit` | `PATCH /links/{id}`, `POST /links/bulk-archive`, `PATCH /folders/{id}`, `DELETE /folders/{id}`, `POST /folders/set-default`, `PATCH /tags/{id}`, `DELETE /tags/{id}` |
| `links.delete` | `DELETE /links/{id}`, `POST /links/bulk-delete` |
| `links.import` | `POST /links/bulk-create` |
| `domains.create` | `POST /domains` |
| `domains.update` | `POST /domains/{id}/verify`, `POST /domains/{id}/set-default` |
| `domains.delete` | `DELETE /domains/{id}` |
| `analytics.view` | `GET /analytics`, `GET /links/{linkId}/analytics` |

<Note>
  Read endpoints — `GET /links`, `GET /links/{id}`, `GET /domains`, `GET /folders` and `GET /tags` —
  carry no permission guard. Any member of the workspace can call them, and a workspace whose plan no
  longer includes Tags & Folders can still read the folders and tags it already has.
</Note>

## Plan gates are separate

Holding the permission is not enough on its own. A call can still fail with `403` because the
workspace's plan does not include the feature or has exhausted a quota:

* **Feature-gated** — folders and tags need `tagsAndFolders`; device targeting, geo targeting, link
  cloaking, scheduling and QR customisation each need their own feature on the plan.
* **Quota-limited** — links, clicks, domains, team members, QR codes and password-protected links
  each count against a numeric plan maximum.

The error message names which of the two applies.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.