Change a member’s role
const url = 'https://api.sloose.com/orgs/org_9f3c/members/usr_4b19';const options = { method: 'PATCH', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"role":"operator"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request PATCH \ --url https://api.sloose.com/orgs/org_9f3c/members/usr_4b19 \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "role": "operator" }'Sets the role. Nothing resets it afterwards: a sign-in says who somebody is and nothing about their role.
You may lower your own role but not raise it, you cannot change somebody who outranks you, and you cannot leave the org without an owner.
Session only: managing people takes a person, never an org’s API token (D5).
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”The org id the session was issued for. A token for one org can never read another.
Example
org_9f3cThe org id the session was issued for. A token for one org can never read another.
The member’s user id, from the member list.
Example
usr_4b19The member’s user id, from the member list.
Request Bodyrequired
Section titled “Request Bodyrequired”object
Ranked: operator < builder < admin < owner.
Responses
Section titled “Responses”The member as they now stand.
object
object
The invitation’s, or what an administrator set here. A sign-in never changes it.
Example
{ "member": { "role": "operator" }}The request — its body or its query — did not match the schema. issues carries the Zod issue list.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}No bearer, or one that is expired, revoked or no longer resolves to a member.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}An API token was used (SESSION_REQUIRED), you tried to raise your own role (SELF_CHANGE), or to change somebody who outranks you or grant a role above your own (OUTRANKED), or the session is a staff member’s view of the org: a read-only one as on any write (IMPERSONATION_READ_ONLY), and a write-capable one when the role would go UP (IMPERSONATION_REFUSED), since the access would outlast the view. A write-capable view may still lower a role.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}That person is not in this org (MEMBER_NOT_FOUND).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}The org would be left with no owner (LAST_OWNER), or the person’s role changed between your reading it and this request, so the decision has to be made again (MEMBER_CHANGED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}