Skip to main content
PATCH
Update principal settings

Authorizations

Authorization
string
header
required

Supabase JWT token in Authorization: Bearer header

Headers

Idempotency-Key
string
required

Client-supplied idempotency token. Replays within 24 hours return the stored result verbatim. See ADR-023.

Required string length: 1 - 128
If-Match
string
required

Optimistic concurrency token. Pass the ETag from a recent GET ("sha256:<hex64>" shape). A stale ETag returns 412 Precondition Failed; a missing header returns 428 Precondition Required. See RFC 9110 §13.1.1.

Pattern: ^"sha256:[0-9a-f]{64}"$

Path Parameters

org_id
string
required

Organization identifier (e.g. org-abc12345)

Body

application/json
type
enum<string>
Available options:
human,
organization,
agent,
unspecified
identifier
string
relationship
enum<string>
Available options:
delegated_authority,
advisory,
autonomous
escalation_contact
string

Response

The principal primitive was updated at the org scope.

ok
boolean
required
scope
enum<string>
required
Available options:
org
scope_id
string
required
resource
enum<string>
required
Available options:
alignment
primitive
enum<string>
required
Available options:
principal
verb
enum<string>
required
Available options:
put,
patch
value
object
required
content_hash
string
required

New sha256:<hex64> of the spec at this scope after the write.

agents_flagged_for_recompose
integer
Required range: x >= 0
_warnings
object

Pre-existing structural issues outside the modified primitive. Present only when the existing spec carries unrelated validation problems; never blocks the write.