RocketChat/Rocket.Chat · error · Meteor.Error
error-action-not-allowed
error-action-not-allowed
Error message
This is an enterprise feature
What it means
POST /v1/roles.create is an enterprise endpoint: a route-level license gate plus an in-action License.hasModule('custom-roles') check both guard it. On Community edition, or with an enterprise license lacking the custom-roles module, creating a role throws Meteor.Error('error-action-not-allowed', 'This is an enterprise feature').
Solutions
- Install and activate an enterprise license that includes the custom-roles module
- Verify the license first (workspace license banner / enterprise resources endpoint) before calling roles.create
- Without a license, use only built-in roles — CE has no route for creating custom roles
- Start a trial or contact sales if the feature is needed
Example fix
// before
await POST('/api/v1/roles.create', { name: 'auditor' }); // CE workspace → error-action-not-allowed
// after: gate the call on license state
if (!(await licenseHasModule('custom-roles'))) throw new Error('custom-roles license required');
await POST('/api/v1/roles.create', { name: 'auditor' }); Defensive patterns
Strategy: validation
Validate before calling
import { License } from '@rocket.chat/license';
const canCreateRoles = License.hasModule('custom-roles');
if (!canCreateRoles) {
throw new Error('roles.create requires an enterprise license with the custom-roles module');
}
await POST('/api/v1/roles.create', payload); Try / catch
try {
await POST('/api/v1/roles.create', payload);
} catch (error) {
if (error.error === 'error-action-not-allowed' && /enterprise/i.test(error.reason)) {
// license problem, not a code problem: surface a licensing message
throw new LicenseRequiredError('custom-roles');
}
throw error;
} Prevention
- Gate role-management UI and automation on the workspace license state
- Document which integrations require EE modules so CE deployments fail gracefully
- Re-verify the license after upgrades and trial expirations
When it happens
Trigger: POST /api/v1/roles.create with valid auth on a workspace whose license does not include 'custom-roles' — Community edition, expired trial, or an EE license without that module.
Common situations: Role-management automation written against EE later deployed on CE; license expired after scripts shipped; local dev environment without a license file.
Related errors
- error-max-guests-number-reached
- error-action-not-allowed
- error-action-not-allowed
- error-action-not-allowed
- error-ai-not-enabled
AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18).
Data as JSON: /api/errors/6657c7446c97957c.
Report an issue: GitHub.
Appendix: source
Thrown at apps/meteor/ee/server/api/roles.ts:115
required: ['role', 'success'],
additionalProperties: false,
});
API.v1.post(
'roles.create',
{
authRequired: true,
license: ['custom-roles'],
body: isRoleCreateProps,
response: {
200: roleResponseSchema,
401: validateUnauthorizedErrorResponse,
400: validateBadRequestErrorResponse,
},
},
async function action() {
if (!License.hasModule('custom-roles')) {
throw new Meteor.Error('error-action-not-allowed', 'This is an enterprise feature');
}
const { userId } = this;
if (!userId || !(await hasPermissionAsync(userId, 'access-permissions'))) {
throw new Meteor.Error('error-action-not-allowed', 'Accessing permissions is not allowed');
}
const { name, scope, description, mandatory2fa } = this.bodyParams;
if (await Roles.findOneByIdOrName(name)) {
throw new Meteor.Error('error-duplicate-role-names-not-allowed', 'Role name already exists');
}
const roleData = {
description: description || '',
...(mandatory2fa !== undefined && { mandatory2fa }),
name,View on GitHub (pinned to b2c16d5842)