Skip to main content

Update Group

PATCH 

/:namespace/Groups/:id

Status: Trusted Tester

Add members to or remove members from a group. Only add and remove on members are supported — groups themselves cannot be created, renamed or deleted, so the other operations are rejected with 400.

Members must belong to {namespace}. Create one who doesn't here first with POST /{namespace}/Users by email — otherwise the add is rejected with 400.

Members are applied one at a time, and a failure part-way through is not rolled back. Each member is read and committed before the next is read, so if the third of three fails, the first two have already been applied. A member id that cannot be read returns 404. Send one member per request if you need to know exactly what landed.

A remove naming a member who is not in this namespace is a no-op rather than an error, so deprovisioning stays idempotent.

Both add and remove accept the array form "value": [{"value": "<userId>"}]; remove also accepts an RFC 7644 value filter, "path": "members[value eq \"<userId>\"]". A single request is limited to 100 members.

Send a group id exactly as it appears in the group reference, and check it before granting — a mistyped id will not necessarily be reported as an error.

Granting pc:access also grants the other pc: platform features listed in the group reference.

PATCH /{namespace}/Users/{id} changes the same memberships and is the preferred path: unlike this operation, it preserves the member's externalId. A membership change made here clears the externalId stored for that user in this namespace.

Request​

Responses​

No Content