Grant an API key or team member access to a device
Dashboard-only
DeviceGrant), and use the Device Control endpoints.This is how an API key gets permission to call device commands it has none by default. Provide exactly one of apiKeyId or membershipId. Requires an Owner or Admin session; API keys cannot create grants for themselves or anyone else.
Authorization
sessionAuth A session token for an existing account, obtained from POST /auth/login (see the Authentication endpoints) - not an API key. Endpoints marked with this scheme reject API key callers outright, regardless of what that key is granted. Outside the Authentication endpoints themselves, everything requiring this scheme manages dashboard resources (schedules, rules, grants, keys, device configuration) and mirrors what a human does in the Nexalware web app - it is not meant to be automated by a third-party integration the way the Device Control endpoints are.
In: header
Path Parameters
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
curl -X POST "https://example.com/api/v1/devices/dev_a1b2c3/grants" \ -H "Content-Type: application/json" \ -d '{ "commands": [ "string" ] }'{ "grantId": "string"}