Apply a privileged action
Apply one allowlisted privileged action. `choice` is `on`/`off`/`set`, with an optional integer `value` for `set` (minutes). Requires the **admin** role.
In: cookie
Path Parameters
The privileged action key, e.g. power.sleep.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
curl -X POST "https://example.com/api/system/privileged/string" \ -H "Content-Type: application/json" \ -d '{ "choice": "on" }'{ "escalated": true, "helperRoot": true, "needsElevation": true, "fullDiskAccess": true, "fullDiskAccessStatus": "granted", "needsFullDiskAccess": true, "daemonExecutable": "string", "fullDiskAccessDetail": "string", "categories": [ "string" ], "actions": [ { "key": "string", "category": "string", "label": "string", "kind": "string", "note": "string", "current": "string", "enabled": true, "minutes": 0 } ]}Revoke a paired device POST
Cuts a device off immediately. A device may revoke itself, so a lost phone can be cut off from another phone, but revoking a different device requires a signed-in session. Requires the **viewer** role.
Privileged status GET
Helper status, Full Disk Access diagnostics, and the list of privileged actions. Available to every signed-in role so a blocked dashboard can explain the missing grant.