> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Internal links on these pages omit the .md extension. Append .md to a docs page URL, or send an Accept: text/markdown header, to get that page as markdown.

# Share app with groups

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Shares the app with one or more workspace groups, giving every member of each group access to the app.

All the groups get the same `role`. A member's role in the app is the highest of the role you gave them directly and the roles of all the groups they're in that the app is shared with. Members usually get access right away, and always by their next sign-in. Members your identity provider synced who don't have a Base44 account yet get access once they have one. Each member who gets access is also sent an invitation email, at most once per app.

Each group succeeds or fails on its own, so read `results` rather than treating a successful response as every group shared. Sending a group the app is already shared with fails that group with `already_shared` and changes nothing, so retrying is safe. Change a share's role afterwards with [Update group share](/api-reference/update-group-share).

You need editor access to the app, and an editor or admin role in the app's workspace. Your workspace's plan must include workspace groups.

This is limited to 30 requests per minute. A signed-in session has its own limit, and every personal access token for the workspace shares one. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json post /api/apps/{app_id}/group-shares
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/group-shares:
    post:
      summary: Share app with groups
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Shares the app with one or more workspace groups, giving every member of
        each group access to the app.


        All the groups get the same `role`. A member's role in the app is the
        highest of the role you gave them directly and the roles of all the
        groups they're in that the app is shared with. Members usually get
        access right away, and always by their next sign-in. Members your
        identity provider synced who don't have a Base44 account yet get access
        once they have one. Each member who gets access is also sent an
        invitation email, at most once per app.


        Each group succeeds or fails on its own, so read `results` rather than
        treating a successful response as every group shared. Sending a group
        the app is already shared with fails that group with `already_shared`
        and changes nothing, so retrying is safe. Change a share's role
        afterwards with [Update group share](/api-reference/update-group-share).


        You need editor access to the app, and an editor or admin role in the
        app's workspace. Your workspace's plan must include workspace groups.


        This is limited to 30 requests per minute. A signed-in session has its
        own limit, and every personal access token for the workspace shares one.
        Some workspaces have a different limit.


        <Note>This endpoint accepts a personal API key belonging to a user with
        editor access to the app. A read-only key is refused, and workspace API
        keys are not accepted.</Note>
      operationId: create_shares_api_apps__app_id__group_shares_post
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateSharesRequest'
      responses:
        '200':
          description: One result per group.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateSharesResponse'
        '401':
          description: Missing or invalid credentials.
        '402':
          description: Your workspace's plan doesn't include workspace groups.
        '403':
          description: >-
            You don't have editor access to this app, you aren't an editor or
            admin in the app's workspace, or your API key is read-only.
        '404':
          description: App not found.
        '422':
          description: >-
            `group_ids` is missing, empty, or has more than 50 IDs, or `role`
            isn't one of the roles defined on the app's User entity.
        '429':
          description: >-
            Rate limit exceeded. The base limit is 30 requests per minute. Wait
            the number of seconds in the `Retry-After` header before you retry.
components:
  schemas:
    CreateSharesRequest:
      properties:
        group_ids:
          items:
            type: string
          type: array
          maxItems: 50
          minItems: 1
          title: Group Ids
          description: >-
            IDs of the workspace groups to share the app with, 1 to 50. A
            repeated ID counts once.
          example:
            - 68c9a0f1d2e4b5001f3a7c90
        role:
          anyOf:
            - type: string
            - type: 'null'
          title: Role
          description: >-
            App role every member of these groups gets, one of the roles defined
            on the app's User entity. Leave it out, or send `null`, to assign no
            role, so members get the default `user` role.
          example: user
      type: object
      required:
        - group_ids
      title: CreateSharesRequest
    CreateSharesResponse:
      properties:
        results:
          items:
            $ref: '#/components/schemas/CreateShareResult'
          type: array
          title: Results
          description: One result per group, in the order you sent them.
          example:
            - group_id: 68c9a0f1d2e4b5001f3a7c90
              success: true
      type: object
      required:
        - results
      title: CreateSharesResponse
    CreateShareResult:
      properties:
        group_id:
          type: string
          title: Group Id
          description: ID of the group, as you sent it.
          example: 68c9a0f1d2e4b5001f3a7c90
        success:
          type: boolean
          title: Success
          description: Whether the app is now shared with the group by this call.
          example: true
        error:
          anyOf:
            - type: string
            - type: 'null'
          title: Error
          description: >-
            Why the group wasn't shared, or `null` on success. `group_not_found`
            means the ID isn't a group in the app's workspace, and
            `already_shared` means the app is already shared with it.
          example: already_shared
      type: object
      required:
        - group_id
        - success
        - error
      title: CreateShareResult
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.