> ## Documentation Index
> Fetch the complete documentation index at: https://help.dingtalk.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an access control

> Call this API to add access control to a specified calendar to restrict accessible users or roles, with full request parameters and response field references.

Call this API to add an access control to a specified calendar.

## Request

### Basic information

| Field               | Value                                                                              |
| ------------------- | ---------------------------------------------------------------------------------- |
| HTTP URL            | `https://api.dingtalk.io/v1.0/calendar/users/{userId}/calendars/{calendarId}/acls` |
| HTTP Method         | POST                                                                               |
| Supported app types | appType-Internal app　appType-Third-party personal app                              |
| Permission required | permission-Calendar.Acl.Write-Calendar app access control write permission         |

### Request header

| Name                        | Type   | Required | Description                                                                                                                                                                                                                                                                                                              |
| --------------------------- | ------ | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| x-acs-dingtalk-access-token | String | Yes      | The access credential for calling this API. Obtain it as follows:   - For an internal app, call the [Get the access token of an internal app](/open/development/obtain-the-access-token-of-an-internal-app#) API. - For a third-party personal app, call the [Get user token](/open/development/obtain-user-token#) API. |

### Path parameters

| Name       | Type   | Required | Description                                                                                                                                                                                                                                                                                                                                          |
| ---------- | ------ | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| userId     | String | Yes      | The unionId of the event organizer.   - For an internal app, call the [Query user details](/open/development/query-user-details#) API to obtain the unionid parameter value. - For a third-party personal app, call the [Get user contact profile](/open/development/dingtalk-retrieve-user-information#) API to obtain the unionId parameter value. |
| calendarId | String | Yes      | The ID of the calendar that the event belongs to. The value is fixed to primary, which indicates the user's primary calendar.                                                                                                                                                                                                                        |

### Request body

| Name      | Type    | Required | Description                                                                                                                                                                            |
| --------- | ------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| privilege | String  | Yes      | The permission information. Valid values:   - **free\_busy\_reader**: Check free/busy. - **title\_reader**: View the title. - **reader**: View details. - **writer**: Create and edit. |
| sendMsg   | Boolean | Yes      | Whether to send a message to the authorized user.   - **true**: Send. - **false**: Do not send.                                                                                        |
| scope     | Object  | Yes      | The permission scope.                                                                                                                                                                  |
| scopeType | String  | Yes      | The permission type. Currently, only **user** is supported, which indicates a user.                                                                                                    |
| userId    | String  | Yes      | The user ID. When **scopeType** is set to **user**, pass in the **unionId** of the user.  **Note**  A single user can share with a maximum of 500 users.                               |

### Request example

HTTP

```http theme={"theme":{"light":"github-light","dark":"github-dark"}}
POST /v1.0/calendar/users/U5KXX3QjgiG/calendars/primary/acls HTTP/1.1
Host:api.dingtalk.io
x-acs-dingtalk-access-token:dd438xxx
Content-Type:application/json

{
  "privilege" : "reader",
  "sendMsg" : true,
  "scope" : {
    "scopeType" : "user",
    "userId" : "U5KXX3QjgiG"
  }
}
```

Java

```java theme={"theme":{"light":"github-light","dark":"github-dark"}}
// This file is auto-generated, don't edit it. Thanks.
package com.aliyun.sample;

import com.aliyun.tea.*;

public class Sample {

    /**
     * Initialize the account Client with a Token
     * @return Client
     * @throws Exception
     */
    public static com.aliyun.dingtalkcalendar_1_0.Client createClient() throws Exception {
        com.aliyun.teaopenapi.models.Config config = new com.aliyun.teaopenapi.models.Config();
        config.protocol = "https";
        config.regionId = "central";
        return new com.aliyun.dingtalkcalendar_1_0.Client(config);
    }

    public static void main(String[] args_) throws Exception {
        java.util.List<String> args = java.util.Arrays.asList(args_);
        com.aliyun.dingtalkcalendar_1_0.Client client = Sample.createClient();
        com.aliyun.dingtalkcalendar_1_0.models.CreateAclsHeaders createAclsHeaders = new com.aliyun.dingtalkcalendar_1_0.models.CreateAclsHeaders();
        createAclsHeaders.xAcsDingtalkAccessToken = "<your access token>";
        com.aliyun.dingtalkcalendar_1_0.models.CreateAclsRequest.CreateAclsRequestScope scope = new com.aliyun.dingtalkcalendar_1_0.models.CreateAclsRequest.CreateAclsRequestScope()
                .setScopeType("user");
        com.aliyun.dingtalkcalendar_1_0.models.CreateAclsRequest createAclsRequest = new com.aliyun.dingtalkcalendar_1_0.models.CreateAclsRequest()
                .setPrivilege("reader")
                .setSendMsg(true)
                .setScope(scope);
        try {
            client.createAclsWithOptions("U5KXX3QjgiG", "primary", createAclsRequest, createAclsHeaders, new com.aliyun.teautil.models.RuntimeOptions());
        } catch (TeaException err) {
            if (!com.aliyun.teautil.Common.empty(err.code) && !com.aliyun.teautil.Common.empty(err.message)) {
                // err contains the code and message attributes that help locate the issue
            }

        } catch (Exception _err) {
            TeaException err = new TeaException(_err.getMessage(), _err);
            if (!com.aliyun.teautil.Common.empty(err.code) && !com.aliyun.teautil.Common.empty(err.message)) {
                // err contains the code and message attributes that help locate the issue
            }

        }        
    }
}
```

Python

```python theme={"theme":{"light":"github-light","dark":"github-dark"}}
# -*- coding: utf-8 -*-
# This file is auto-generated, don't edit it. Thanks.
import sys

from typing import List

from alibabacloud_dingtalk.calendar_1_0.client import Client as dingtalkcalendar_1_0Client
from alibabacloud_tea_openapi import models as open_api_models
from alibabacloud_dingtalk.calendar_1_0 import models as dingtalkcalendar__1__0_models
from alibabacloud_tea_util import models as util_models
from alibabacloud_tea_util.client import Client as UtilClient

class Sample:
    def __init__(self):
        pass

    @staticmethod
    def create_client() -> dingtalkcalendar_1_0Client:
        """
        Initialize the account Client with a Token
        @return: Client
        @throws Exception
        """
        config = open_api_models.Config()
        config.protocol = 'https'
        config.region_id = 'central'
        return dingtalkcalendar_1_0Client(config)

    @staticmethod
    def main(
        args: List[str],
    ) -> None:
        client = Sample.create_client()
        create_acls_headers = dingtalkcalendar__1__0_models.CreateAclsHeaders()
        create_acls_headers.x_acs_dingtalk_access_token = '<your access token>'
        scope = dingtalkcalendar__1__0_models.CreateAclsRequestScope(
            scope_type='user'
        )
        create_acls_request = dingtalkcalendar__1__0_models.CreateAclsRequest(
            privilege='reader',
            send_msg=True,
            scope=scope
        )
        try:
            client.create_acls_with_options('U5KXX3QjgiG', 'primary', create_acls_request, create_acls_headers, util_models.RuntimeOptions())
        except Exception as err:
            if not UtilClient.empty(err.code) and not UtilClient.empty(err.message):
                # err contains the code and message attributes that help locate the issue
                pass

    @staticmethod
    async def main_async(
        args: List[str],
    ) -> None:
        client = Sample.create_client()
        create_acls_headers = dingtalkcalendar__1__0_models.CreateAclsHeaders()
        create_acls_headers.x_acs_dingtalk_access_token = '<your access token>'
        scope = dingtalkcalendar__1__0_models.CreateAclsRequestScope(
            scope_type='user'
        )
        create_acls_request = dingtalkcalendar__1__0_models.CreateAclsRequest(
            privilege='reader',
            send_msg=True,
            scope=scope
        )
        try:
            await client.create_acls_with_options_async('U5KXX3QjgiG', 'primary', create_acls_request, create_acls_headers, util_models.RuntimeOptions())
        except Exception as err:
            if not UtilClient.empty(err.code) and not UtilClient.empty(err.message):
                # err contains the code and message attributes that help locate the issue
                pass

if __name__ == '__main__':
    Sample.main(sys.argv[1:])
```

PHP

```java theme={"theme":{"light":"github-light","dark":"github-dark"}}
<?php

// This file is auto-generated, don't edit it. Thanks.
namespace AlibabaCloud\SDK\Sample;

use AlibabaCloud\SDK\Dingtalk\Vcalendar_1_0\Dingtalk;
use \Exception;
use AlibabaCloud\Tea\Exception\TeaError;
use AlibabaCloud\Tea\Utils\Utils;

use Darabonba\OpenApi\Models\Config;
use AlibabaCloud\SDK\Dingtalk\Vcalendar_1_0\Models\CreateAclsHeaders;
use AlibabaCloud\SDK\Dingtalk\Vcalendar_1_0\Models\CreateAclsRequest\scope;
use AlibabaCloud\SDK\Dingtalk\Vcalendar_1_0\Models\CreateAclsRequest;
use AlibabaCloud\Tea\Utils\Utils\RuntimeOptions;

class Sample {

    /**
     * Initialize the account Client with a Token
     * @return Dingtalk Client
     */
    public static function createClient(){
        $config = new Config([]);
        $config->protocol = "https";
        $config->regionId = "central";
        return new Dingtalk($config);
    }

    /**
     * @param string[] $args
     * @return void
     */
    public static function main($args){
        $client = self::createClient();
        $createAclsHeaders = new CreateAclsHeaders([]);
        $createAclsHeaders->xAcsDingtalkAccessToken = "<your access token>";
        $scope = new scope([
            "scopeType" => "user"
        ]);
        $createAclsRequest = new CreateAclsRequest([
            "privilege" => "reader",
            "sendMsg" => true,
            "scope" => $scope
        ]);
        try {
            $client->createAclsWithOptions("U5KXX3QjgiG", "primary", $createAclsRequest, $createAclsHeaders, new RuntimeOptions([]));
        }
        catch (Exception $err) {
            if (!($err instanceof TeaError)) {
                $err = new TeaError([], $err->getMessage(), $err->getCode(), $err);
            }
            if (!Utils::empty_($err->code) && !Utils::empty_($err->message)) {
                // err contains the code and message attributes that help locate the issue
            }
        }
    }
}
$path = __DIR__ . \DIRECTORY_SEPARATOR . '..' . \DIRECTORY_SEPARATOR . 'vendor' . \DIRECTORY_SEPARATOR . 'autoload.php';
if (file_exists($path)) {
    require_once $path;
}
Sample::main(array_slice($argv, 1));
```

Go

```go theme={"theme":{"light":"github-light","dark":"github-dark"}}
// This file is auto-generated, don't edit it. Thanks.
package main

import (
  "os"
  util  "github.com/alibabacloud-go/tea-utils/v2/service"
  dingtalkcalendar_1_0  "github.com/alibabacloud-go/dingtalk/calendar_1_0"
  openapi  "github.com/alibabacloud-go/darabonba-openapi/v2/client"
  "github.com/alibabacloud-go/tea/tea"
)

/**
 * Initialize the account Client with a Token
 * @return Client
 * @throws Exception
 */
func CreateClient () (_result *dingtalkcalendar_1_0.Client, _err error) {
  config := &openapi.Config{}
  config.Protocol = tea.String("https")
  config.RegionId = tea.String("central")
  _result = &dingtalkcalendar_1_0.Client{}
  _result, _err = dingtalkcalendar_1_0.NewClient(config)
  return _result, _err
}

func _main (args []*string) (_err error) {
  client, _err := CreateClient()
  if _err != nil {
    return _err
  }

  createAclsHeaders := &dingtalkcalendar_1_0.CreateAclsHeaders{}
  createAclsHeaders.XAcsDingtalkAccessToken = tea.String("<your access token>")
  scope := &dingtalkcalendar_1_0.CreateAclsRequestScope{
    ScopeType: tea.String("user"),
  }
  createAclsRequest := &dingtalkcalendar_1_0.CreateAclsRequest{
    Privilege: tea.String("reader"),
    SendMsg: tea.Bool(true),
    Scope: scope,
  }
  tryErr := func()(_e error) {
    defer func() {
      if r := tea.Recover(recover()); r != nil {
        _e = r
      }
    }()
    _, _err = client.CreateAclsWithOptions(tea.String("U5KXX3QjgiG"), tea.String("primary"), createAclsRequest, createAclsHeaders, &util.RuntimeOptions{})
    if _err != nil {
      return _err
    }

    return nil
  }()

  if tryErr != nil {
    var err = &tea.SDKError{}
    if _t, ok := tryErr.(*tea.SDKError); ok {
      err = _t
    } else {
      err.Message = tea.String(tryErr.Error())
    }
    if !tea.BoolValue(util.Empty(err.Code)) && !tea.BoolValue(util.Empty(err.Message)) {
      // err contains the code and message attributes that help locate the issue
    }

  }
  return _err
}

func main() {
  err := _main(tea.StringSlice(os.Args[1:]))
  if err != nil {
    panic(err)
  }
}
```

Node.js

```python theme={"theme":{"light":"github-light","dark":"github-dark"}}
// This file is auto-generated, don't edit it
import Util, * as $Util from '@alicloud/tea-util';
import dingtalkcalendar_1_0, * as $dingtalkcalendar_1_0 from '@alicloud/dingtalk/calendar_1_0';
import OpenApi, * as $OpenApi from '@alicloud/openapi-client';
import * as $tea from '@alicloud/tea-typescript';

export default class Client {

  /**
   * Initialize the account Client with a Token
   * @return Client
   * @throws Exception
   */
  static createClient(): dingtalkcalendar_1_0 {
    let config = new $OpenApi.Config({ });
    config.protocol = "https";
    config.regionId = "central";
    return new dingtalkcalendar_1_0(config);
  }

  static async main(args: string[]): Promise<void> {
    let client = Client.createClient();
    let createAclsHeaders = new $dingtalkcalendar_1_0.CreateAclsHeaders({ });
    createAclsHeaders.xAcsDingtalkAccessToken = "<your access token>";
    let scope = new $dingtalkcalendar_1_0.CreateAclsRequestScope({
      scopeType: "user",
    });
    let createAclsRequest = new $dingtalkcalendar_1_0.CreateAclsRequest({
      privilege: "reader",
      sendMsg: true,
      scope: scope,
    });
    try {
      await client.createAclsWithOptions("U5KXX3QjgiG", "primary", createAclsRequest, createAclsHeaders, new $Util.RuntimeOptions({ }));
    } catch (err) {
      if (!Util.empty(err.code) && !Util.empty(err.message)) {
        // err contains the code and message attributes that help locate the issue
      }

    }    
  }

}

Client.main(process.argv.slice(2));
```

C#

```java theme={"theme":{"light":"github-light","dark":"github-dark"}}
// This file is auto-generated, don't edit it. Thanks.

using System;
using System.Collections;
using System.Collections.Generic;
using System.IO;
using System.Threading.Tasks;

using Tea;
using Tea.Utils;

namespace AlibabaCloud.SDK.Sample
{
    public class Sample 
    {

        /**
         * Initialize the account Client with a Token
         * @return Client
         * @throws Exception
         */
        public static AlibabaCloud.SDK.Dingtalkcalendar_1_0.Client CreateClient()
        {
            AlibabaCloud.OpenApiClient.Models.Config config = new AlibabaCloud.OpenApiClient.Models.Config();
            config.Protocol = "https";
            config.RegionId = "central";
            return new AlibabaCloud.SDK.Dingtalkcalendar_1_0.Client(config);
        }

        public static void Main(string[] args)
        {
            AlibabaCloud.SDK.Dingtalkcalendar_1_0.Client client = CreateClient();
            AlibabaCloud.SDK.Dingtalkcalendar_1_0.Models.CreateAclsHeaders createAclsHeaders = new AlibabaCloud.SDK.Dingtalkcalendar_1_0.Models.CreateAclsHeaders();
            createAclsHeaders.XAcsDingtalkAccessToken = "<your access token>";
            AlibabaCloud.SDK.Dingtalkcalendar_1_0.Models.CreateAclsRequest.CreateAclsRequestScope scope = new AlibabaCloud.SDK.Dingtalkcalendar_1_0.Models.CreateAclsRequest.CreateAclsRequestScope
            {
                ScopeType = "user",
            };
            AlibabaCloud.SDK.Dingtalkcalendar_1_0.Models.CreateAclsRequest createAclsRequest = new AlibabaCloud.SDK.Dingtalkcalendar_1_0.Models.CreateAclsRequest
            {
                Privilege = "reader",
                SendMsg = true,
                Scope = scope,
            };
            try
            {
                client.CreateAclsWithOptions("U5KXX3QjgiG", "primary", createAclsRequest, createAclsHeaders, new AlibabaCloud.TeaUtil.Models.RuntimeOptions());
            }
            catch (TeaException err)
            {
                if (!AlibabaCloud.TeaUtil.Common.Empty(err.Code) && !AlibabaCloud.TeaUtil.Common.Empty(err.Message))
                {
                    // err contains the code and message attributes that help locate the issue
                }
            }
            catch (Exception _err)
            {
                TeaException err = new TeaException(new Dictionary<string, object>
                {
                    { "message", _err.Message }
                });
                if (!AlibabaCloud.TeaUtil.Common.Empty(err.Code) && !AlibabaCloud.TeaUtil.Common.Empty(err.Message))
                {
                    // err contains the code and message attributes that help locate the issue
                }
            }
        }

    }
}
```

## Response

### Response body

| Name      | Type   | Description                                                                                                                                                                            |
| --------- | ------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| privilege | String | The permission information. Valid values:   - **free\_busy\_reader**: Check free/busy. - **title\_reader**: View the title. - **reader**: View details. - **writer**: Create and edit. |
| aclId     | String | The permission resource ID.                                                                                                                                                            |
| scope     | Object | The permission scope.                                                                                                                                                                  |
| scopeType | String | The permission type. Currently, only **user** is supported, which indicates a user.                                                                                                    |
| userId    | String | The user ID.  When **scopeType** is set to **user**, the value is the **unionId** of the user.                                                                                         |

### Response body example

```text theme={"theme":{"light":"github-light","dark":"github-dark"}}
HTTP/1.1 200 OK
Content-Type:application/json

{
  "privilege" : "reader",
  "aclId" : "VS4yJgnNiiiSRmsqKttYXXXXXX",
  "scope" : {
    "scopeType" : "user",
    "userId" : "U5KXX3QjgiG"
  }
}
```

### Error codes

If an error is returned when you call this API, look up the solution in the [Global error codes](/open/development/server-api-error-codes-1) document based on the error message.

| HttpCode | Error code       | Error message       | Description                                         |
| -------- | ---------------- | ------------------- | --------------------------------------------------- |
| 400      | invalidParameter | forwardErrorMessage | Invalid parameter.                                  |
| 400      | invalidParameter | shareExceedLimit    | The number of shared users exceeds the upper limit. |
