curl --request PATCH \
--url https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/agents/{agentId}/access/{principalType}/{principalId} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{}'const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/agents/{agentId}/access/{principalType}/{principalId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/agents/{agentId}/access/{principalType}/{principalId}"
payload = {}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"updated": true,
"binding": {
"agent_id": "<string>",
"principal_type": "user",
"principal_id": "<string>",
"email": "<string>",
"orgSlug": "<string>",
"granted_by": "<string>",
"role_slug": "<string>"
}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}Change an agent share's role
Change the role of the binding for the given (principal_type, principal_id) pair, in place. Revoking and re-creating is not equivalent: the two calls have no transaction around them, and the revoke half is refused when the binding is the resource’s last one.
owner is not accepted, although it is a defined agent role: it is the only share role carrying delete, and this endpoint is reachable by anyone holding share. It also never conferred ownership - an agent’s owner is its owner_id, and a binding with that role resolves to admin.
The caller’s own access cannot be changed, for the same reason it cannot be revoked: lowering one’s own role drops them out of the panel they are acting from, on an agent they may be the only administrator of.
curl --request PATCH \
--url https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/agents/{agentId}/access/{principalType}/{principalId} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{}'const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/agents/{agentId}/access/{principalType}/{principalId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/agents/{agentId}/access/{principalType}/{principalId}"
payload = {}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"updated": true,
"binding": {
"agent_id": "<string>",
"principal_type": "user",
"principal_id": "<string>",
"email": "<string>",
"orgSlug": "<string>",
"granted_by": "<string>",
"role_slug": "<string>"
}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}{
"error": "<string>",
"message": "<string>",
"details": {}
}Authorizations
User-bound credential carrying an identity: either a session JWT
or a user access token (at:*) generated from the user settings UI.
Send as Authorization: Bearer <token>.
Org API keys (iak_*) are not accepted here - they carry
no user identity. Use the x-prismeai-api-key header instead
(see OrgApiKeyAuth).
Path Parameters
64user, group, org 32128Body
user, admin 64Response
Binding updated.
Was this page helpful?