> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apsio.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Let an OAuth client write for you here

> Creates your grant for one OAuth client (its client_id) to write in the organization on your behalf, with your own role: dashboards:write creates and edits dashboards (deleting still needs an owner or admin), issues:write changes issue states and assignees. One grant per capability. Console session only; at most 20 grants an hour per user in the organization.



## OpenAPI

````yaml /api-reference/openapi.json post /orgs/{orgId}/agent-grants
openapi: 3.1.0
info:
  title: Apsio API
  version: 0.1.0
  description: >-
    Read API v0: your projects, release health and comparisons, missing symbols,
    issues, sessions, vitals, cohort comparisons, performance (app start,
    screens, hangs, MetricKit) and network endpoints and traces for one project.
    Authenticate with a project token as a bearer token, with an OAuth access
    token from Apsio's authorization server (MCP clients), or, from the console,
    with the session cookie of a member of the project's organization.
servers:
  - url: https://api.apsio.io/v1
security: []
paths:
  /orgs/{orgId}/agent-grants:
    post:
      summary: Let an OAuth client write for you here
      description: >-
        Creates your grant for one OAuth client (its client_id) to write in the
        organization on your behalf, with your own role: dashboards:write
        creates and edits dashboards (deleting still needs an owner or admin),
        issues:write changes issue states and assignees. One grant per
        capability. Console session only; at most 20 grants an hour per user in
        the organization.
      parameters:
        - schema:
            type: string
            pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
            example: 0192f3a4-0000-7000-8000-00000000a001
          required: true
          name: orgId
          in: path
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                client_id:
                  type: string
                  minLength: 1
                  maxLength: 256
                client_name:
                  type: string
                  maxLength: 100
                capability:
                  type: string
                  enum:
                    - dashboards:write
                    - issues:write
                  description: >-
                    What the client may do: dashboards:write (create and edit
                    dashboards) or issues:write (change issue states and
                    assignees).
              required:
                - client_id
                - capability
      responses:
        '201':
          description: The grant
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AgentGrant'
      security:
        - session: []
components:
  schemas:
    AgentGrant:
      type: object
      properties:
        id:
          type: string
        org_id:
          type: string
        user_id:
          type: string
        user_name:
          type: string
        client_id:
          type: string
          description: >-
            The OAuth client's id, as the access token names it (a URL for
            clients registered by a Client ID Metadata Document). Untrusted
            text: show it as text, never as a link.
        client_name:
          type: string
          description: The name the user gave the client.
        capability:
          type: string
          enum:
            - dashboards:write
            - issues:write
          description: >-
            What the client may do: dashboards:write (create and edit
            dashboards) or issues:write (change issue states and assignees).
        created_at:
          type: string
        last_used_at:
          type:
            - string
            - 'null'
        expires_at:
          type: string
          description: 'Unless used before: 90 days after the last use (or the grant).'
      required:
        - id
        - org_id
        - user_id
        - user_name
        - client_id
        - client_name
        - capability
        - created_at
        - last_used_at
        - expires_at
  securitySchemes:
    session:
      type: apiKey
      in: cookie
      name: apsio_session
      description: >-
        The console session, set by /v1/auth/callback (`__Host-apsio_session`
        when host-only).

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.