> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://developer.staging.frame.io/platform/v4/api-reference/workspace-permissions/workspace-user-roles-update/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.staging.frame.io/_mcp/server. # Update user roles for the given workspace PATCH https://api.frame.io/v4/accounts/{account_id}/workspaces/{workspace_id}/users/{user_id} Content-Type: application/json Update user roles for the given workspace if the user is already added to the workspace. If the user is not added to the workspace, the user will be added with the given role. Rate Limits: 10 calls per 1.00 minute(s) per account\_user Reference: https://developer.staging.frame.io/platform/api-reference/workspace-permissions/workspace-user-roles-update ## Authentication - `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer `, where token is your auth token. ## Request ### Path parameters - `account_id` (string, required) - `workspace_id` (string, required) - `user_id` (string, required) ### Body (application/json) This endpoint expects an UpdateUserRolesParams. - `data` (UpdateUserRolesParamsData, required) ## Response ### 200 OK - `data` (UpdateUserRolesResponseData, required) ## Errors ### 400 Bad Request Error Bad Request - `errors` (list of BadRequestErrorsItems, required) ### 401 Unauthorized Error Unauthorized - `errors` (list of UnauthorizedErrorsItems, required) ### 403 Forbidden Error Forbidden - `errors` (list of ForbiddenErrorsItems, required) ### 404 Not Found Error Not Found - `errors` (list of NotFoundErrorsItems, required) ### 422 Unprocessable Entity Error Unprocessable Entity - `errors` (list of UnprocessableEntityErrorsItems, required) ### 429 Too Many Requests Error Too Many Requests - `errors` (list of TooManyRequestsErrorsItems, required) ## Types ### UpdateUserRolesParamsData - `role` (enum, required) - Allowed values: `full_access`, `editor`, `edit_only`, `commenter`, `viewer` ### UpdateUserRolesResponseData - `role` (enum, optional) - Allowed values: `full_access`, `editor`, `edit_only`, `commenter`, `viewer` ### BadRequestErrorsItems - `detail` (string, required) - `source` (BadRequestErrorsItemsSource, optional) - `title` (string, optional) ### UnauthorizedErrorsItems - `detail` (string, required) - `source` (UnauthorizedErrorsItemsSource, optional) - `title` (string, optional) ### ForbiddenErrorsItems - `detail` (string, required) - `source` (ForbiddenErrorsItemsSource, optional) - `title` (string, optional) ### NotFoundErrorsItems - `detail` (string, required) - `source` (NotFoundErrorsItemsSource, optional) - `title` (string, optional) ### UnprocessableEntityErrorsItems - `detail` (string, required) - `source` (UnprocessableEntityErrorsItemsSource, optional) - `title` (string, optional) ### TooManyRequestsErrorsItems - `detail` (string, required) - `source` (TooManyRequestsErrorsItemsSource, optional) - `title` (string, optional) ### BadRequestErrorsItemsSource - `pointer` (string, optional) ### UnauthorizedErrorsItemsSource - `pointer` (string, optional) ### ForbiddenErrorsItemsSource - `pointer` (string, optional) ### NotFoundErrorsItemsSource - `pointer` (string, optional) ### UnprocessableEntityErrorsItemsSource - `pointer` (string, optional) ### TooManyRequestsErrorsItemsSource - `pointer` (string, optional) ## Examples **Request** ```json { "data": { "role": "editor" } } ``` **Response** ```json { "data": { "role": "editor" } } ``` **SDK Code** ```python import requests url = "https://api.frame.io/v4/accounts/416cb880-814b-4c4c-903e-cf80cef9b0a1/workspaces/41e0f507-2f40-4f06-b230-1b51d768077c/users/da8abeca-efcf-4bc4-ba1c-79c0a7509e43" payload = { "data": { "role": "editor" } } headers = { "Authorization": "Bearer ", "Content-Type": "application/json" } response = requests.patch(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api.frame.io/v4/accounts/416cb880-814b-4c4c-903e-cf80cef9b0a1/workspaces/41e0f507-2f40-4f06-b230-1b51d768077c/users/da8abeca-efcf-4bc4-ba1c-79c0a7509e43'; const options = { method: 'PATCH', headers: {Authorization: 'Bearer ', 'Content-Type': 'application/json'}, body: '{"data":{"role":"editor"}}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.frame.io/v4/accounts/416cb880-814b-4c4c-903e-cf80cef9b0a1/workspaces/41e0f507-2f40-4f06-b230-1b51d768077c/users/da8abeca-efcf-4bc4-ba1c-79c0a7509e43" payload := strings.NewReader("{\n \"data\": {\n \"role\": \"editor\"\n }\n}") req, _ := http.NewRequest("PATCH", url, payload) req.Header.Add("Authorization", "Bearer ") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api.frame.io/v4/accounts/416cb880-814b-4c4c-903e-cf80cef9b0a1/workspaces/41e0f507-2f40-4f06-b230-1b51d768077c/users/da8abeca-efcf-4bc4-ba1c-79c0a7509e43") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Patch.new(url) request["Authorization"] = 'Bearer ' request["Content-Type"] = 'application/json' request.body = "{\n \"data\": {\n \"role\": \"editor\"\n }\n}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.patch("https://api.frame.io/v4/accounts/416cb880-814b-4c4c-903e-cf80cef9b0a1/workspaces/41e0f507-2f40-4f06-b230-1b51d768077c/users/da8abeca-efcf-4bc4-ba1c-79c0a7509e43") .header("Authorization", "Bearer ") .header("Content-Type", "application/json") .body("{\n \"data\": {\n \"role\": \"editor\"\n }\n}") .asString(); ``` ```php request('PATCH', 'https://api.frame.io/v4/accounts/416cb880-814b-4c4c-903e-cf80cef9b0a1/workspaces/41e0f507-2f40-4f06-b230-1b51d768077c/users/da8abeca-efcf-4bc4-ba1c-79c0a7509e43', [ 'body' => '{ "data": { "role": "editor" } }', 'headers' => [ 'Authorization' => 'Bearer ', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api.frame.io/v4/accounts/416cb880-814b-4c4c-903e-cf80cef9b0a1/workspaces/41e0f507-2f40-4f06-b230-1b51d768077c/users/da8abeca-efcf-4bc4-ba1c-79c0a7509e43"); var request = new RestRequest(Method.PATCH); request.AddHeader("Authorization", "Bearer "); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"data\": {\n \"role\": \"editor\"\n }\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "Authorization": "Bearer ", "Content-Type": "application/json" ] let parameters = ["data": ["role": "editor"]] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api.frame.io/v4/accounts/416cb880-814b-4c4c-903e-cf80cef9b0a1/workspaces/41e0f507-2f40-4f06-b230-1b51d768077c/users/da8abeca-efcf-4bc4-ba1c-79c0a7509e43")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "PATCH" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```