Permission denied for usergroups.users.update

Viewed 1249

I'm trying to add a user to a usergroup (and by that trying to use the API call usergroups.users.update)

I'm using a workspace token that has the scope usergroups:write and usergroups:read (complete list: channels:read, channels:write, chat:write, groups:write, im:write, identity:read:user, usergroups:read, usergroups:write, users:read, users:read.email, users.profile:write)

The payload is:

{"usergroup":"SCGM0xxxx","users":"U5W2Rxxxx"}

(Lower case xxxx to hide identity)

POST from Curl:

POST /api/usergroups.users.update HTTP/1.1

The result from the POST request to usergroups.users.update simply returns

    {
     "ok" => false
     "error"  => "permission_denied"
     }

The documentation states:

The user does not have permission to update the list of users for a User Group.

Is there any other setting I need to configure to make this work? I have reinstalled the app after changing the oauth scopes. I added both usergroups:read and usergroups:write at the same time and I can use the API call usergroups.list.

2 Answers

According to slack support:

There’s a workspace preference that limits who can manage user groups. It’s likely that your workspace owners have locked this down. If the token you’re using does not belong to one of the members permitted to manage user groups, you’ll get back the “permission_denied” error. The settings would look like this: User Groups To find a list of workspace Owners you can head to your Account page: https://my.slack.com/account/workspace-settings#admins

I had the same issue, and I think it's a bug that the workspace token doesn't work. As a workaround, I had the luxury of being able to go into the admin settings and temporarily set the People who can create and disable user groups: Everyone, except guests. That allowed me to proceed with the API calls. Then switched it back.

Related