Skip to content

Change a member's role​

PATCH
/org-admin/{slug}/members/{userId}

Moves a member to a different org role. Setting the role they already hold is an idempotent no-op that still answers 200.

Roles rank org_owner > org_admin > org_viewer. Rules enforced, each a 403 when broken:

  • only an org_owner may promote anyone to org_owner, or change the role of another owner;
  • nobody may change the role of a member whose role is equal to or above their own (an
    org_admin manages org_viewers, not other admins);
  • nobody may grant a role above their own.

Lowering your own role (stepping down) is always allowed. The organization's last remaining owner cannot be demoted (400) — promote another member to owner first.

Requires permission: org.manage_members

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Parameters​

Path Parameters

slug*

The organization's slug (not its UUID).

Type
string
Required
Example"local-food-bank-a1b2c3"
Pattern
"^[a-z0-9][a-z0-9-]{0,254}$"
userId*

The member's profile id. A non-UUID answers 404 Member not found.

Type
string
Required
Format
"uuid"

Request Body​

application/json
JSON
{
"role": "string"
}

Responses​

Role updated (or already held)

application/json
JSON
{
"data": {
"user_id": "string",
"role_name": "string"
}
}

Playground​

Server
Authorization
Variables
Key
Value
Body

Samples​

Powered by VitePress OpenAPI

Built with VitePress