change member role
Requires a current admin. Preserve at least one admin and enforce Clerk membership and plan limits.
/api/v1/organizations/{organizationId}/members/{userId}Authorization
ManagementOAuth managementUser-based Clerk OAuth. CLI is a public Authorization Code client using S256 PKCE and browser loopback redirect. Hosted MCP uses resource-bound OAuth. Verify issuer, token type, intended audience/resource, scopes, live membership and current role. Do not forward arbitrary OAuth tokens into Convex session JWT auth. OAuth URLs below are placeholders for deployment configuration.
In: header
Scope: management
Path Parameters
Permanent organizationId; selected organization must be authorized for the current user.
Permanent userId; selected organization must be authorized for the current user.
Header Parameters
Management writes: scoped to OAuth user+client+organization+operation. Store request digest and response for at least 24 hours. Same key/body replays original response, including after completion; different body fails idempotency_conflict. Exception: create_retrieval_key stores a non-secret receipt referencing the created key, never its secret. Same-key/body retries return 409 secret_unavailable with existing key metadata and do not create another key. Evaluation creation must not execute twice.
8 <= length <= 128Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X PATCH "https://example.com/api/v1/organizations/string/members/string" \ -H "Idempotency-Key: stringst" \ -H "Content-Type: application/json" \ -d '{ "role": "admin" }'{ "userId": "string", "name": "string", "role": "admin"}list members GET
Uses the selected organization and the authenticated user’s current permissions. Applies the same setup and archive rules as the dashboard.
remove member DELETE
Remove a member under current admin rules. Membership loss revokes their management access, but does not revoke organization-owned retrieval keys.