RocketChat/Rocket.Chat · error · Meteor.Error

error-action-not-allowed

error-action-not-allowed

Error message

This is an enterprise feature

What it means

POST /v1/roles.create is an enterprise endpoint: a route-level license gate plus an in-action License.hasModule('custom-roles') check both guard it. On Community edition, or with an enterprise license lacking the custom-roles module, creating a role throws Meteor.Error('error-action-not-allowed', 'This is an enterprise feature').

Solutions

  1. Install and activate an enterprise license that includes the custom-roles module
  2. Verify the license first (workspace license banner / enterprise resources endpoint) before calling roles.create
  3. Without a license, use only built-in roles — CE has no route for creating custom roles
  4. Start a trial or contact sales if the feature is needed

Example fix

// before
await POST('/api/v1/roles.create', { name: 'auditor' }); // CE workspace → error-action-not-allowed

// after: gate the call on license state
if (!(await licenseHasModule('custom-roles'))) throw new Error('custom-roles license required');
await POST('/api/v1/roles.create', { name: 'auditor' });
Defensive patterns

Strategy: validation

Validate before calling

import { License } from '@rocket.chat/license';

const canCreateRoles = License.hasModule('custom-roles');
if (!canCreateRoles) {
  throw new Error('roles.create requires an enterprise license with the custom-roles module');
}
await POST('/api/v1/roles.create', payload);

Try / catch

try {
  await POST('/api/v1/roles.create', payload);
} catch (error) {
  if (error.error === 'error-action-not-allowed' && /enterprise/i.test(error.reason)) {
    // license problem, not a code problem: surface a licensing message
    throw new LicenseRequiredError('custom-roles');
  }
  throw error;
}

Prevention

When it happens

Trigger: POST /api/v1/roles.create with valid auth on a workspace whose license does not include 'custom-roles' — Community edition, expired trial, or an EE license without that module.

Common situations: Role-management automation written against EE later deployed on CE; license expired after scripts shipped; local dev environment without a license file.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/6657c7446c97957c. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/ee/server/api/roles.ts:115

	required: ['role', 'success'],
	additionalProperties: false,
});

API.v1.post(
	'roles.create',
	{
		authRequired: true,
		license: ['custom-roles'],
		body: isRoleCreateProps,
		response: {
			200: roleResponseSchema,
			401: validateUnauthorizedErrorResponse,
			400: validateBadRequestErrorResponse,
		},
	},
	async function action() {
		if (!License.hasModule('custom-roles')) {
			throw new Meteor.Error('error-action-not-allowed', 'This is an enterprise feature');
		}

		const { userId } = this;

		if (!userId || !(await hasPermissionAsync(userId, 'access-permissions'))) {
			throw new Meteor.Error('error-action-not-allowed', 'Accessing permissions is not allowed');
		}

		const { name, scope, description, mandatory2fa } = this.bodyParams;

		if (await Roles.findOneByIdOrName(name)) {
			throw new Meteor.Error('error-duplicate-role-names-not-allowed', 'Role name already exists');
		}

		const roleData = {
			description: description || '',
			...(mandatory2fa !== undefined && { mandatory2fa }),
			name,

View on GitHub (pinned to b2c16d5842)