> Documentation index: [Saleor](/llms.txt) · [This section](/developer/llms.txt)
> Source: https://docs.saleor.io/developer/permissions

# Permissions

<a id="user-permissions"></a>

## User permissions

The user permissions are divided into data and channel permissions. Data permissions allow access to certain data types, such as `orders` and `products`. Channel permissions allow access to that data with restrictions to specific channels.

For example, a user with `MANAGE_ORDERS` and `channel_USD` permissions can only access orders from the `channel_USD` channel.

The channel restriction affects the access to data restricted by the following permissions:

-   `MANAGE_ORDERS`

Instead of assigning permissions directly to the user, we define them on a group basis. Organizing access rights in [`Groups`](/api-reference/users/objects/group.md) helps in determining the roles of team members.

Examples of groups:

-   Translators - `MANAGE_TRANSLATIONS` permission.
-   Customer support - `MANAGE_ORDERS` and `MANAGE_USERS` permissions.
-   Customer support for USD channel - `MANAGE_ORDERS` and `MANAGE_USERS` permissions, `channel_USD` channel.

important

When a user is a member of multiple groups, their permissions are summed up. This means that if the user is in at least one group that has not restricted channel access, they will have access to data from all channels.

<a id="creating-and-removing-groups"></a>

### Creating and removing groups

You can create permission group either via the Saleor Dashboard or using the GraphQL API.

<a id="saleor-dashboard"></a>

#### Saleor Dashboard

1.  Navigate to Configuration → Permission Groups.
2.  Click Create Permission group
3.  Name the group, select permissions and channels. Once saved you can assign group members from existing staff users.

<a id="api"></a>

#### API

To create a group programmatically, use the [`permissionGroupCreate`](/api-reference/users/mutations/permission-group-create.md) mutation. This method allows for assigning users during group creation.

<a id="creating-the-group-without-channel-restriction"></a>

#### Creating the group without channel restriction

**Mutation**

```graphql
mutation PermissionGroupCreate($input: PermissionGroupCreateInput!) {
  permissionGroupCreate(input: $input) {
    errors {
      message
    }
    group {
      id
      name
      permissions {
        name
      }
      restrictedAccessToChannels
      accessibleChannels {
        slug
      }
    }
  }
}
```

**Variables**

```json
{
  "input": {
      "addPermissions": ["MANAGE_GIFT_CARD", "MANAGE_DISCOUNTS"],
      "addUsers": [],
      "name": "Sale managers",
      "restrictedAccessToChannels": false,
      "addChannels": []
    }
}
```

**Result**

```json
{
  "data": {
    "permissionGroupCreate": {
      "errors": [],
      "group": {
        "id": "R3JvdXA6NDM=",
        "name": "Sale managers",
        "permissions": [
          {
            "name": "Manage sales and vouchers."
          },
          {
            "name": "Manage gift cards."
          }
        ]
        "restrictedAccessToChannels": false,
        "accessibleChannels": [
          {
            "slug": "channel-pln"
          },
          {
            "slug": "default-channel"
          }
        ]
      }
    }
  }
}
```

<a id="creating-a-group-with-channel-restrictions"></a>

#### Creating a group with channel restrictions

**Mutation**

```graphql
mutation PermissionGroupCreate($input: PermissionGroupCreateInput!) {
  permissionGroupCreate(input: $input) {
    errors {
      message
    }
    group {
      id
      name
      permissions {
        name
      }
      restrictedAccessToChannels
      accessibleChannels {
        slug
      }
    }
  }
}
```

**Variables**

```json
{
  "input": {
    "addPermissions": [
      "MANAGE_ORDERS"
    ],
    "addUsers": [],
    "name": "Order managers for channel USD",
    "restrictedAccessToChannels": true,
    "addChannels": [
      "Q2hhbm5lbDoy"
    ]
  }
}
```

**Result**

```json
{
  "data": {
    "permissionGroupCreate": {
      "errors": [],
      "group": {
        "id": "R3JvdXA6MjY=",
        "name": "Order managers for USD channel",
        "permissions": [
          {
            "name": "Manage orders."
          }
        ],
        "restrictedAccessToChannels": true,
        "accessibleChannels": [
          {
            "slug": "channel-pln"
          }
        ]
      }
    }
  }
}
```

As we can see, the `accessibleChannels` field differs from the previous example. The users from this group will have access only to data from the `channel-pln` channel.

important

When the `restrictedAccessToChannels` flag is set to `false`, the channels provided in `addChannels` field will be ignored.

<a id="removing-a-group"></a>

### Removing a group

To remove a group, use the [`permissionGroupDelete`](/api-reference/users/mutations/permission-group-delete.md) mutation:

**Mutation**

```graphql
mutation PermissionGroupDelete($id: ID!) {
  permissionGroupDelete(id: $id) {
    errors {
      code
      message
    }
  }
}
```

**Variables**

```json
{
  "id": "R3JvdXA6NDM=",
}
```

<a id="modifying-a-group"></a>

### Modifying a group

<a id="managing-the-group-members"></a>

#### Managing the group members

The [`permissionGroupUpdate`](/api-reference/users/mutations/permission-group-update.md) mutation takes a list of user IDs you would like to add or remove from the group. Having the same user in both lists will result in an error.

Example request:

**Mutation**

```graphql
mutation PermissionGroupUpdate($id: ID!, $input: PermissionGroupUpdateInput!) {
  permissionGroupUpdate(id: $id, input: $input) {
    errors {
      message
    }
  }
}
```

**Variables**

```json
{
  "id": "R3JvdXA6NDM=",
  "input": {
    "name": "Sale managers",
    "addPermissions": [],
    "removePermissions": [],
    "addUsers": [
      "VXNlcjozMg=="
    ],
    "removeUsers": []
  }
}
```

<a id="managing-the-group-channels"></a>

#### Managing the group channels

The [`permissionGroupUpdate`](/api-reference/users/mutations/permission-group-update.md) mutation takes a list of channel IDs you would like to add or remove from the group. Having the same channels in both lists will result in an error.

Example request:

**Mutation**

```graphql
mutation PermissionGroupUpdate($id: ID!, $input: PermissionGroupUpdateInput!) {
  permissionGroupUpdate(id: $id, input: $input) {
    errors {
      message
    }
  }
}
```

**Variables**

```json
{
  "id": "R3JvdXA6MjY=",
  "input": {
    "addPermissions": [],
    "removePermissions": [],
    "addChannels": [
      "Q2hhbm5lbDox"
    ],
    "removeChannels": [
      "Q2hhbm5lbDoy"
    ]
  }
}
```

important

When the `restrictedAccessToChannels` flag is changed from `true` to `false`, all currently assigned channels will be cleared.

When the `restrictedAccessToChannels` flag is set to `false`, the channels provided in `addChannels` and `removeChannels` fields will be ignored.

<a id="app-permissions"></a>

## App permissions

info

App permissions are described in the [App permissions](/developer/extending/apps/architecture/app-permissions.md) article.

<a id="jwt-token-and-permissions"></a>

## JWT token and permissions

JWT tokens have a list of assigned permissions. By decoding payload using RS256 algorithm you will get:

```json
{
  "iat": 1624013260,
  "iss": "example.com",
  "token": "AixxXXXxzF",
  "email": "john@example.com",
  "type": "access",
  "user_id": "VXNlcjozMg==",
  "is_staff": true,
  "exp": 1624049260,
  "oauth_access_key": "",
  "permissions": [
    "MANAGE_TRANSLATIONS",
    "MANAGE_PRODUCTS",
    "MANAGE_PRODUCT_TYPES_AND_ATTRIBUTES"
  ]
}
```

To check the token online and learn more about JWT visit [https://jwt.io](https://jwt.io).

note

Since Saleor reads permissions from the JWT token, generating a new token is necessary when the user changes permissions.

<a id="queryme-vs-queryuser"></a>

## `Query.me` vs `Query.user`

When working with permissions in Saleor, it's important to understand:

-   **`Query.me`** returns the _effective permissions_ of the currently authenticated user, as encoded in the access token. This includes permissions granted dynamically, such as through Single Sign-On (SSO) or Role-Based Access Control (RBAC). These may not be stored on the User object in the database.
-   **`Query.user`** returns only the permissions stored for a specific user in the database. It does _not_ include any permissions granted dynamically.

<a id="available-permissions"></a>

## Available permissions

Available permissions are kept in the [PermissionEnum](/api-reference/users/enums/permission-enum.md).

| Name | Description |
| --- | --- |
| HANDLE\_PAYMENTS | Process payments, refunds, and manage payment transactions. |
| HANDLE\_CHECKOUTS | Permission for apps to process some checkout operations like overriding price. |
| HANDLE\_TAXES | Permission for apps to delegate tax calculation external systems. |
| IMPERSONATE\_USER | Allows attaching customer to checkout by external app or staff user. |
| MANAGE\_APPS | Install, configure, and manage third-party extensions (apps, plugins). |
| MANAGE\_CHANNELS | Create, view and manage channels. |
| MANAGE\_CHECKOUTS | Permission for quering checkouts details. |
| MANAGE\_DISCOUNTS | Create, view and manage vouchers and promotions. |
| MANAGE\_GIFT\_CARD | Create, activate, deactivate, manage and export gift cards. |
| MANAGE\_MENUS | Create, view and manage navigation menus and their structure. |
| MANAGE\_ORDERS | Create, view and manage all orders data. Update order metadata. |
| MANAGE\_ORDERS\_IMPORT | Import orders from external sources. |
| MANAGE\_PAGES | Create, view, publish, and manage content pages. |
| MANAGE\_PLUGINS | View, configure and manage plugins. |
| MANAGE\_PRODUCT\_TYPES\_AND\_ATTRIBUTES | Create and manage product types, product attributes, and their relationships. |
| MANAGE\_PAGE\_TYPES\_AND\_ATTRIBUTES | Create and manage model types, content attributes, and their relationships. |
| MANAGE\_PRODUCTS | Create, view and manage products, variants, categories, collections and warehouses. Enable export products and stock updates. |
| MANAGE\_SETTINGS | Configure store settings. |
| MANAGE\_SHIPPING | Create, view and manage shipping zones and shipping methods. |
| MANAGE\_STAFF | Create, view and manage staff accounts, and permissions groups. |
| MANAGE\_TAXES | Create, view and manage tax configuration, tax classes. |
| MANAGE\_TRANSLATIONS | Create, view and manage translations for products, categories, and content etc. |
| MANAGE\_USERS | Create, view and manage customer accounts and their information. |
