Skip to content

Change a member's role in a workspace: role (owner or member) and the roles they hold besides it (org_roles, a list of billing_manager and security_manager, which replaces the one they have).

PATCH/workspaces/{workspace}/members/{username}

Only the fields given are changed. A billing manager manages the workspace’s billing as an owner does, and gets nothing on repositories from it; a security manager reads every repository and sees and manages its security alerts and security settings. Refused with 409 when it would leave the workspace without an owner. Owners only, signed in as a person. Returns the member.

Only the fields given change; org_roles replaces the list. 409 when it would leave the workspace without an owner. Refused with 403 for anyone but an owner signed in as a person. Recorded in the audit log as member.role_changed, member.org_role_added or member.org_role_removed. See Workspaces.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: workspace with action update_member, and the same inputs
  • Scope: An access token needs workspace:admin.
Name Type Required Description
workspace string Yes The workspace’s slug, e.g. “flagon-io”.
username string Yes The member’s username.

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
role string No owner or member. One of owner, member.
org_roles array of strings No The roles they hold besides owner or member: billing_manager, security_manager. Replaces the list; [] takes them all away. One of billing_manager, security_manager.
curl -X PATCH https://api.g1t.sh/workspaces/acme-labs/members/grace \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"role": "member",
"org_roles": [
"security_manager"
]
}'

A successful request answers 200 with:

{
"username": "grace",
"display_username": "grace",
"role": "member",
"org_roles": [
"security_manager"
],
"two_factor": null,
"name": "Grace Hopper",
"avatar": null
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.