access

PATCH /v1/orgs/{orgId}/members/{userId}

Change a member's role.

Semua titik akhir access

Pengesahan

Hantar kunci API sebagai token pembawa. Kunci tersebut mesti membawa kebenaran members.role.assign; kunci yang tidak mempunyainya akan ditolak dengan 403, bukan 404.

Tempat ID organisasi anda diletakkan

Titik akhir ini mengambil ID organisasi anda dalam URL itu sendiri, sebagai orgId. Gantikannya ke dalam laluan — tiada pengepala atau parameter pertanyaan yang akan melakukan sebaliknya.

ID organisasi anda terletak pada skrin kekunci API dalam papan pemuka anda, di sebelah kekunci itu sendiri. Ia adalah ID yang sama dalam setiap panggilan yang anda buat.

Cuba

Gantikan apa sahaja di dalam kurungan sudut dengan nilai anda sendiri, dan pemegang tempat kunci dengan kunci dari papan pemuka anda.

curl -X PATCH https://api.zinndigital.com/v1/orgs/{orgId}/members/{userId} \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "role": <string> }'

Sudah log masuk? Konsol API dalam papan pemuka anda mengisi id organisasi sebenar dan kunci anda sendiri, serta menjalankan permintaan terhadap API langsung supaya anda boleh melihat respons sebenar. Buka penamat ini dalam konsol API

Butiran

Sets this member's role in the organization. Requires `members.role.assign` **on that org**. ⛔ **Replaces** the member's roles with the one given rather than adding to them — a person may hold several `Membership` rows, and collapsing them can only ever reduce what they hold, so no path through this endpoint escalates by accident. Three refusals, and they are the same rules an invitation is held to: **403** if the member holds a permission the caller does not (`more_privileged`), **403** if the *role being granted* holds one (`role_not_grantable` — this is what stops any holder of the key promoting themselves to `owner`), and **409** for the org's last owner (`last_owner`). An unknown role is a **422**, never a 403, so a typo is distinguishable from a permission you lack.

Parameter

NamaJenisDiperlukanApakah ia
orgId (path)UuidYaOrganization ID (UUIDv7).
userId (path)UuidYaThe user to remove from the organization.

Badan permintaan

NamaJenisDiperlukanApakah ia
rolestringYaA role key from `GET /v1/orgs/{orgId}/roles`.

Respons

NamaJenisDiperlukanApakah ia
user_idUuidYaUUIDv7 identifier — sortable by creation time (docs/02 §8).
emailstringYa
namestringYaDisplay name; may be empty for an account that never set one.
rolesstring[]YaEvery role this person holds in this org, sorted.
joined_atstringYaWhen their EARLIEST membership of this org was created.
is_selfbooleanYaWhether this row is the calling user.
removablebooleanYa
not_removable_reasonOrgMemberRemovalBlock | nullYaWhy not, when `removable` is false. Null when removable — and also null for a caller lacking `members.remove`, because "you cannot remove anyone here" is a fact about the caller…
role_assignablebooleanYaWhether `PATCH` on this member would be accepted — the caller holds `members.role.assign` here, does not outrank themselves, and this is not the last owner. ⛔ *Which* role may t…

Ralat yang boleh dikembalikan oleh titik akhir ini

401 · 403 · 404 · 409 · 422 · 429