Skip to content

Roles & permissions

Invite people by email and give each one a role. Gate features in your code with one function call.

The four roles

Roles are ordered: each one can do everything the role below it can.

RoleTypical useIn the Foyr dashboard
ownerYouEverything, including deleting the app
adminA co-builderDeploy, roll back, manage members and env vars
memberA teammate who uses the appOpen the app
viewerA client who needs to lookOpen the app

member and viewer differ only inside your app: you decide what each can do with hasPermission.

Inviting people

Open Members, add one or more emails and pick a role. Each person gets an email with a sign-in link. Until they use it, they show as Invited. Removing someone, or changing their role, applies within a few seconds.

Gating a feature

Name the actions your app cares about and the minimum role for each in foyr.json:

foyr.json
{
  "permissions": {
    "reports:export": "member",
    "billing:edit": "admin"
  }
}

Then check them in code:

import { getUser, hasPermission } from "@foyr/auth";
 
export async function GET(req: Request) {
  const user = getUser(req);
  if (!hasPermission(user, "reports:export")) {
    return new Response("Forbidden", { status: 403 });
  }
  return Response.json(await exportReports());
}

An action that isn't listed in foyr.json requires admin. That way a typo fails closed.

Note Custom roles beyond these four are not planned for the first release.
Last updated 26 Sep 2026
Esc
Getting started
Introduction
↵
Quickstart
Concepts
How auth works
Roles & permissions
Deployments
Reference
JavaScript SDK
Python SDK
foyr.json
Architecture
Architecture
FAQ
FAQ

Get early access

We're onboarding developers in small batches.

What will you deploy? Optional

One email when your spot opens. No spam.