Add Share
POST/api/v2/custom-reports/:id/shares
Add a user as an explicit share recipient. Upserts (updateOrCreate) so calling twice with a different permission updates the existing record.
reports:writeGrant this scope to your token under Settings → Developer → Personal Access Tokens.
Request body:
user_id(integer, required): Recipient user ID (cannot be self)permission(string, required):vieworedit
Returns 403 if the caller is not the report owner. Returns 422 if sharing with self or invalid permission.
Request
Responses
- 200
- 401
- 403
- 404
- 422
- 429
Successful response
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not found — no record with the given identifier (or the route does not exist). Verify the ID before retrying.
Validation failed — the body is a field → messages map (Laravel shape) or the platform envelope with a stable machine-readable code. Fix the payload and resubmit.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.