Iblai api agent access
Manage role-based access to an ibl.ai agent via the platform API — list role policies, search users/groups, and grant/revoke editor, chat, or analytics_viewer roles for users, groups, and emails. Use when controlling who can edit, chat with, or view analytics for an agent.From its SKILL.md
npx -y skills add iblai/api --skill iblai-api-agent-accessAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
3 things to look at
- reads credentialsReads from 3 credential sources: `IBLAI_API_KEY` and 2 more.
- 15 stars15 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
- fetches URLsInstructs the agent to fetch 4 URLs, including https://api.iblai.app/dm/api/core/rbac/mentor-access/ and 3 more.
SKILL.md
3.5 KB, 939 tokens by cl100k_base, as published. Nobody here has run it
iblai-api-agent-access
Manage role-based access control that decides who can edit, chat with, or
view analytics for an agent. Searches resolve users and groups; every grant
and revoke flows through the single mentor-access/ write endpoint. Use when
controlling who can edit, chat with, or view analytics for an agent.
Auth & conventions
- Base URL:
https://api.iblai.app - Header:
Authorization: Api-Token $IBLAI_API_KEYon every request. - Path vars:
{org}=$IBLAI_ORG,{username}=$IBLAI_USERNAME,{mentor}= the agent's unique id (e.g.d17dc729-60fd-4363-81a0-f67d9318b03e). - Access writes go through one endpoint —
POST
https://api.iblai.app/dm/api/core/rbac/mentor-access/— keyed by the numericmentor_id, adding/removing users, groups, and emails perrole. - Not connected yet? Run
/iblai-api-loginfirst to populateIBLAI_ORG,IBLAI_USERNAME, andIBLAI_API_KEY.
Reads
- GET
…/users/{username}/mentors/{mentor}/settings/— resolve the numericmentor_id. - GET
https://api.iblai.app/dm/api/core/rbac/mentor-access/?mentor_id={id}&platform_key={org}— list current role policies. - POST
https://api.iblai.app/dm/api/core/rbac/permissions/check/— can the user search users/groups?{ "platform_key": "string (required)", "resources": ["/users/", "/groups/"] } - GET
https://api.iblai.app/dm/api/core/platform/users/?platform_key={org}&platform_org={org}&query={q}&page=1&page_size=20&return_policies=false— user autocomplete. - GET
https://api.iblai.app/dm/api/core/rbac/groups/?platform_key={org}&name={q}&page=1&page_size=20&include_users=true— group autocomplete.
Writes
- POST
https://api.iblai.app/dm/api/core/rbac/mentor-access/— grant / revoke access (all access changes go through this one endpoint):{ "platform_key": "string (required)", "mentor_id": "number (required)", "role": "editor | chat | analytics_viewer (required)", "users_to_add": "number[]", "users_to_remove": "number[]", "groups_to_add": "number[]", "groups_to_remove": "number[]", "emails_to_add": "string[]", "usernames_to_add": "string[]" }
Example
Grant a user (id 4218) the chat role and revoke a group (id 91) on the agent:
curl -X POST \
"https://api.iblai.app/dm/api/core/rbac/mentor-access/" \
-H "Authorization: Api-Token $IBLAI_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"platform_key": "'"$IBLAI_ORG"'",
"mentor_id": 1057,
"role": "chat",
"users_to_add": [4218],
"groups_to_remove": [91]
}'
Notes
- The write endpoint takes the numeric
mentor_id, not the{mentor}UUID — resolve it from thesettings/read first. - One role per POST: send
roleaseditor,chat, oranalytics_viewerand the add/remove arrays apply to that role only. - Use
permissions/check/before searching — if the user lacks access to/users/or/groups/, skip the corresponding autocomplete. emails_to_addandusernames_to_addinvite by identifier without a prior id lookup; users and groups are added/removed by numeric id from the search reads.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.