Skip to content

Change a member’s role

PATCH
/orgs/{org}/members/{userId}
curl --request PATCH \
--url https://api.sloose.com/orgs/org_9f3c/members/usr_4b19 \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "role": "operator" }'

Sets the role. Nothing resets it afterwards: a sign-in says who somebody is and nothing about their role.

You may lower your own role but not raise it, you cannot change somebody who outranks you, and you cannot leave the org without an owner.

Session only: managing people takes a person, never an org’s API token (D5).

org
required

The org id the session was issued for. A token for one org can never read another.

string
Example
org_9f3c

The org id the session was issued for. A token for one org can never read another.

userId
required

The member’s user id, from the member list.

string
Example
usr_4b19

The member’s user id, from the member list.

Media typeapplication/json
object
role
required

Ranked: operator < builder < admin < owner.

string
Allowed values: operator builder admin owner

The member as they now stand.

Media typeapplication/json
object
member
required
object
userId
required
string
email
required
string
displayName
required
string | null
role
required

The invitation’s, or what an administrator set here. A sign-in never changes it.

string
Allowed values: operator builder admin owner
lastSeenAt
required
string | null
key
additional properties
Example
{
"member": {
"role": "operator"
}
}

The request — its body or its query — did not match the schema. issues carries the Zod issue list.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

No bearer, or one that is expired, revoked or no longer resolves to a member.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

An API token was used (SESSION_REQUIRED), you tried to raise your own role (SELF_CHANGE), or to change somebody who outranks you or grant a role above your own (OUTRANKED), or the session is a staff member’s view of the org: a read-only one as on any write (IMPERSONATION_READ_ONLY), and a write-capable one when the role would go UP (IMPERSONATION_REFUSED), since the access would outlast the view. A write-capable view may still lower a role.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

That person is not in this org (MEMBER_NOT_FOUND).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

The org would be left with no owner (LAST_OWNER), or the person’s role changed between your reading it and this request, so the decision has to be made again (MEMBER_CHANGED).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Report a problem with this page