KintsugiKintsugi

Update an organization user's role

PATCH/users/{user_id}

Change a member's role in the organization (optionally replacing their additional roles). Requires a user credential (an API key is rejected) that is an Owner or Admin of the organization. Select a client organization with Organization-Id, or omit it for the partner firm team. You cannot change your own membership, only an Owner can change another Owner, and only an Owner can assign the Owner role; each returns 403. A PENDING user has no role to change and returns 409: revoke their invitation and send a new one. Returns 404 if the organization is not accessible; the response is empty on success.

Authorization

AuthorizationstringRequired

A signed-in user's session token, sent as Authorization: Bearer <token>. It authorizes the organizations that user can reach. Operations that manage people accept only this credential; operations on data also accept an API key.

Headers

Api-Versiondate

Release date, as YYYY-MM-DD. Defaults to 2026-07-21.

Organization-Idstring

Target client organization. Omit to manage the partner firm team when the bearer is an Owner or Admin of exactly one portfolio.

Connection-Idstring

Target connection id; resolves to its organization.

Entity-Idstring

Platform entity id; resolves to a connection's organization.

Entity-Sourcestring

Optional source to disambiguate an Entity-Id.

Path parameters

user_idstringRequired

Opaque identifier of the user to update. Treat as opaque.

Body

rolePublicUserRoleEnumRequired

New primary role for the user in the organization.

Available options:OWNERADMINMEMBER
additionalRolesstring[]

Optional additional role names to assign alongside the primary role. When provided, replaces the user's current additional roles; omit the field to leave them unchanged, or send an empty list to clear them.

Response

204

Successful Response

400

The request was invalid.

401

Authentication failed or was missing.

403

The credential is not permitted for this request.

404

The requested resource was not found.

409

The request conflicts with existing state.

422

The request failed validation.

503

A service this request depends on was unavailable. Retry the request.

cURL
PATCH /users/{user_id}
-H "Authorization: Bearer ***"
-H "Api-Version: 2026-07-21"
{
"role": "OWNER",
"additionalRoles": [
"additional role"
]
}
Example request
https://api.trykintsugi.com/users/{user_id}
Response
{
"code": "invalid_request",
"message": "The user's role could not be updated as requested.",
"requestId": "req_8f3k2mNpQr7Ls",
"errors": []
}
Update an organization user's role (2026-07-21) | Kintsugi API Reference