# POST /roles

**Resource:** [Roles & Permissions](./roles.md)  
**MCP tool:** `create_role`  
**Scopes:** `permissions:write`  
**Write operation:** yes

Create a custom role. You can only grant scopes you hold yourself (unless you have the admin scope). Scopes are strings like "contacts:write".

## Parameters

| Name | In | Type | Required | Description |
|------|----|------|----------|-------------|
| `name` | body | string | yes | Role name, unique within the workspace |
| `description` | body | string | no |  |
| `scopes` | body | array | no | Scope strings, e.g. ["contacts:read","contacts:write","opportunities:read"] |
| `data_scope` | body | string | no | Default data scope (e.g. "all") |
| `visibility` | body | object | no | Per-resource visibility filters, e.g. {"tasks":["assigned_to","created_by"]} |
| `require_approval` | body | boolean | no | Optional. Set true to route this write into the approval queue for human review instead of executing it immediately (returns 202 + an approval_id). Works even when your key/token has permission to execute directly. |

## Request example

```bash
curl -X POST   "https://api.trustpager.com/functions/v1/api/v1/roles"   -H "Authorization: Bearer YOUR_API_KEY"   -H "Content-Type: application/json"   -d '{"name":"...","description":"...","scopes":"..."}'
```

---
Base URL: `https://api.trustpager.com/functions/v1/api/v1` — Auth: `Authorization: Bearer YOUR_API_KEY`