> ## Documentation Index
> Fetch the complete documentation index at: https://openworklabs.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For agents: install the OpenWork desktop app with `brew install --cask openwork` (macOS) or from https://openworklabs.com/download. Do not run `npx openwork`; the npm package named `openwork` is a different project.
> Connect an agent to OpenWork with the MCP Gateway: `claude mcp add --transport http openwork https://api.openworklabs.com/mcp/agent`. Teams sign up at https://app.openworklabs.com?mode=sign-up.
> Step-by-step agent guide: https://openworklabs.com/docs/start-here/use-openwork-from-an-ai-agent.md
> OpenWork in Slack is private alpha for approved organizations. Setup guide: https://openworklabs.com/docs/slack/overview.md. Agent skill: https://openworklabs.com/.well-known/agent-skills/set-up-openwork-slack/SKILL.md.

# Change permissions in a set

> Turns permissions on (allow) or off (deny) in one set. Only keys whose status actually changes are recorded; every change is kept in the set's history. Only the owner and admins can change Admin permissions. Permissions locked on for admins can't be turned off in Admin permissions, you can only turn on permissions you have yourself (except turning a permission back on in Member or Admin permissions where it is on by default), and archived sets can't be changed. The linked team can't be changed. Returns the set's new state. Requires permissions.manage (only the owner has it by default), a recent sign-in, and the Permissions feature.



## OpenAPI

````yaml /openapi.json put /v1/permissions/sets/{permissionSetId}/permissions
openapi: 3.1.0
info:
  title: Den API
  description: >-
    OpenAPI spec for the Den control plane API.


    Authentication:

    - API keys (they start with `den_`) go in the `x-api-key` header as the raw
    value. Do not send them as `Authorization: Bearer`; that header only accepts
    Den session tokens, so an API key there returns 401.
      Example: `curl https://api.openworklabs.com/v1/me -H "x-api-key: den_..."`.
      API keys resolve to the issuing user and the organization member they were scoped to when created, so they can call ordinary user and organization routes without a separate signed-in session.
    - Use `Authorization: Bearer <session-token>` for user-authenticated routes
    that require a Den session.

    - Session-only flows still require a signed-in user session, including
    organization creation, invitation acceptance, active-organization switching,
    and MCP token minting.

    - Public routes like health and documentation do not require authentication.


    Swagger tip: use the security schemes in the Authorize dialog to set
    `denApiKey` (your API key) or `bearerAuth` (a session token) before trying
    protected endpoints.
  version: 0.18.46
  contact:
    name: OpenWork
    url: https://openworklabs.com
    email: team@openworklabs.com
  license:
    name: OpenWork Enterprise Edition License
    url: https://github.com/different-ai/openwork/blob/dev/ee/LICENSE
servers:
  - url: https://api.openworklabs.com
security:
  - denApiKey: []
  - bearerAuth: []
tags:
  - name: System
    description: >-
      Service health, readiness, API documentation, and desktop version
      metadata.
  - name: Authentication
    description: >-
      Sign-in discovery, administrator bootstrap, OAuth provider connections,
      and MCP token minting.
  - name: OAuth
    description: >-
      OAuth 2.0 / OpenID Connect authorization-server and protected-resource
      metadata and dynamic client registration (RFC 8414, RFC 9728, RFC 7591),
      used by MCP clients.
  - name: SCIM
    description: >-
      SCIM 2.0 provisioning endpoints for identity providers (RFC 7644) and the
      organization SCIM connector management routes.
  - name: SSO
    description: Organization single sign-on connector management routes.
  - name: Bootstrap
    description: Agent-first provisional workspace setup routes.
  - name: Users
    description: Current user and membership routes.
  - name: Organizations
    description: Organization creation, context, brand assets, and install links.
  - name: Invitations
    description: Invitation preview, acceptance, creation, and cancellation routes.
  - name: Members
    description: Organization member management routes.
  - name: Teams
    description: Organization team management routes.
  - name: Permissions
    description: >-
      Organization permissions: the permission catalog, Member, Admin and team
      permission sets, their history, and each member's effective permissions.
  - name: API Keys
    description: Organization API key management routes.
  - name: Desktop Policies
    description: Desktop app policies applied to the organization, members, or teams.
  - name: LLM Providers
    description: Organization LLM provider catalog, configuration, and access routes.
  - name: Inference
    description: Organization inference settings.
  - name: Inference Providers
    description: >-
      Organization inference Gateway providers, model groups, credential sets,
      access grants, member connections, and usage.
  - name: Gateway Usage Limits
    description: >-
      Estimated-cost policies, independent member calendar buckets, assignments,
      and audited usage-extension requests.
  - name: Cloud
    description: Organization Cloud instance lifecycle and browser gateway resolution.
  - name: Workers
    description: >-
      List and delete the organization's workers, including OpenWork Web
      instances.
  - name: Worker Activity
    description: Worker heartbeat and activity reporting routes.
  - name: Managed deployments
    description: >-
      OpenWork installations in an organization's own cloud account: launch
      approval, installer milestones and health reports.
  - name: Automations
    description: Scheduled Automations, their runs, and desktop runner presence.
  - name: Workbot
    description: The signed-in member's single Workbot conversation.
  - name: Workflows
    description: Saved Workflows (Code Mode scripts), their versions, snapshots, and views.
  - name: Workflow Runs
    description: Durable Workflow run history.
  - name: Codemode Runs
    description: Generated Artifact views produced by Code Mode runs.
  - name: Apps
    description: >-
      Saved reusable apps built from Workflows and Artifact views, and their
      sharing.
  - name: Config Objects
    description: >-
      Versioned configuration objects (skills, workflows, and other plugin
      content).
  - name: Plugins
    description: Plugin packages, access grants, and imports.
  - name: Marketplaces
    description: Marketplaces that distribute plugins to members and teams.
  - name: Resources
    description: >-
      Aggregated snapshot of the resources and marketplace capabilities
      available to the caller.
  - name: Dashboards
    description: Shared dashboards and their access grants.
  - name: Capability Sources
    description: >-
      Native provider capabilities (Google Workspace, Microsoft 365) and
      external MCP connections executed as the calling member.
  - name: Direct uploads
    description: Multipart uploads that stream workspace files straight to a provider.
  - name: Connectors
    description: >-
      Connector accounts and instances (GitHub and other sources) and their sync
      state.
  - name: GitHub
    description: >-
      GitHub App installation, repository discovery, and plugin import from
      GitHub.
  - name: Diagnostics
    description: Controlled egress diagnostics for self-hosted deployments.
  - name: Telemetry
    description: Telemetry event ingestion and adoption analytics.
  - name: Webhooks
    description: Signed inbound webhooks from third-party providers.
  - name: Admin
    description: Platform administration routes for allowlisted OpenWork administrators.
  - name: Deprecated
    description: Removed features that answer with 410 or an empty result for old clients.
paths:
  /v1/permissions/sets/{permissionSetId}/permissions:
    put:
      tags:
        - Permissions
      summary: Change permissions in a set
      description: >-
        Turns permissions on (allow) or off (deny) in one set. Only keys whose
        status actually changes are recorded; every change is kept in the set's
        history. Only the owner and admins can change Admin permissions.
        Permissions locked on for admins can't be turned off in Admin
        permissions, you can only turn on permissions you have yourself (except
        turning a permission back on in Member or Admin permissions where it is
        on by default), and archived sets can't be changed. The linked team
        can't be changed. Returns the set's new state. Requires
        permissions.manage (only the owner has it by default), a recent sign-in,
        and the Permissions feature.
      operationId: putV1PermissionsSetsByPermissionSetIdPermissions
      parameters:
        - in: path
          name: permissionSetId
          schema:
            format: typeid
            type: string
            minLength: 30
            maxLength: 30
          required: true
          description: Den TypeID with 'pms_' prefix and a 26-character base32 suffix.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdatePermissionSetPermissionsBody'
      responses:
        '200':
          description: Permissions updated; the set's current state is returned.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PermissionSetResponse'
        '400':
          description: >-
            The body was invalid, named an unknown or repeated permission, or
            tried to turn off a locked permission.
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/InvalidRequestError'
                  - $ref: '#/components/schemas/PermissionEditError'
        '401':
          description: The caller must be signed in.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedError'
        '403':
          description: >-
            The caller lacks permissions.manage, needs a recent sign-in, tried
            to turn on a permission they don't have, or tried to change Admin
            permissions without being the owner or an admin.
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/ForbiddenError'
                  - $ref: '#/components/schemas/PermissionDeniedError'
                  - $ref: '#/components/schemas/PermissionEditError'
        '404':
          description: >-
            The permission set or organization was not found, or Permissions is
            turned off.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PermissionsNotFoundError'
        '409':
          description: The permission set is archived.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PermissionSetConflictError'
      security:
        - denApiKey: []
        - bearerAuth: []
components:
  schemas:
    UpdatePermissionSetPermissionsBody:
      type: object
      properties:
        changes:
          minItems: 1
          maxItems: 500
          type: array
          items:
            type: object
            properties:
              key:
                type: string
                minLength: 1
                maxLength: 128
                description: >-
                  Permission key from GET /v1/permissions/catalog, e.g.
                  llm_provider.delete.
              status:
                type: string
                enum:
                  - allow
                  - deny
            required:
              - key
              - status
          description: >-
            Requested status per key. Each key at most once. Keys already at the
            requested status are left unchanged.
      required:
        - changes
    PermissionSetResponse:
      type: object
      properties:
        set:
          $ref: '#/components/schemas/PermissionSetDetail'
      required:
        - set
    InvalidRequestError:
      type: object
      properties:
        error:
          type: string
          const: invalid_request
        message:
          type: string
        details:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
              path:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: number
            required:
              - message
            additionalProperties: {}
        capability:
          type: string
      required:
        - error
        - details
    PermissionEditError:
      type: object
      properties:
        error:
          type: string
          enum:
            - unknown_permission
            - duplicate_permission
            - admin_permissions_require_admin
            - permission_locked
            - permission_not_held
        message:
          type: string
        keys:
          type: array
          items:
            type: string
      required:
        - error
        - message
        - keys
    UnauthorizedError:
      type: object
      properties:
        error:
          type: string
          const: unauthorized
      required:
        - error
    ForbiddenError:
      type: object
      properties:
        error:
          type: string
          enum:
            - forbidden
            - reauth
        reason:
          type: string
        message:
          type: string
      required:
        - error
    PermissionDeniedError:
      type: object
      properties:
        error:
          type: string
          const: forbidden
        message:
          type: string
        requiredPermission:
          type: string
      required:
        - error
      additionalProperties: {}
    PermissionsNotFoundError:
      type: object
      properties:
        error:
          type: string
          enum:
            - organization_not_found
            - feature_disabled
            - permission_set_not_found
            - team_not_found
            - permission_not_found
            - member_not_found
        feature:
          type: string
        message:
          type: string
      required:
        - error
    PermissionSetConflictError:
      type: object
      properties:
        error:
          type: string
          enum:
            - permission_set_archived
            - team_permission_set_exists
        message:
          type: string
        permissionSetId:
          type: string
      required:
        - error
        - message
    PermissionSetDetail:
      type: object
      properties:
        id:
          type: string
        name:
          type: string
        kind:
          type: string
          enum:
            - member_default
            - admin_default
            - team
        team:
          anyOf:
            - $ref: '#/components/schemas/PermissionSetTeam'
            - type: 'null'
        allowedCount:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
        createdAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
        archivedAt:
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
            - type: 'null'
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/PermissionSetKeyState'
        appliesTo:
          $ref: '#/components/schemas/PermissionSetAppliesTo'
      required:
        - id
        - name
        - kind
        - team
        - allowedCount
        - createdAt
        - archivedAt
        - permissions
        - appliesTo
    PermissionSetTeam:
      type: object
      properties:
        id:
          type: string
        name:
          anyOf:
            - type: string
            - type: 'null'
          description: Null when the team no longer exists.
      required:
        - id
        - name
    PermissionSetKeyState:
      type: object
      properties:
        key:
          type: string
        status:
          type: string
          enum:
            - allow
            - deny
        locked:
          type: boolean
          description: Always on in this set; it can't be turned off.
        lastChangedAt:
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
            - type: 'null'
        lastChangedBy:
          anyOf:
            - $ref: '#/components/schemas/PermissionChangedBy'
            - type: 'null'
        lastChangeSource:
          anyOf:
            - type: string
              enum:
                - user
                - seed
                - reconcile
                - migration
            - type: 'null'
      required:
        - key
        - status
        - locked
        - lastChangedAt
        - lastChangedBy
        - lastChangeSource
    PermissionSetAppliesTo:
      oneOf:
        - type: object
          properties:
            kind:
              type: string
              const: everyone
            memberCount:
              type: integer
              minimum: -9007199254740991
              maximum: 9007199254740991
          required:
            - kind
            - memberCount
        - type: object
          properties:
            kind:
              type: string
              const: admins
            directAdminCount:
              type: integer
              minimum: -9007199254740991
              maximum: 9007199254740991
            directAdmins:
              anyOf:
                - type: array
                  items:
                    $ref: '#/components/schemas/PermissionPerson'
                - type: 'null'
              description: >-
                Names and emails of members with the admin role. Null unless the
                caller holds teams.view; directAdminCount is always returned.
            adminTeams:
              type: array
              items:
                type: object
                properties:
                  id:
                    type: string
                  name:
                    type: string
                  memberCount:
                    type: integer
                    minimum: -9007199254740991
                    maximum: 9007199254740991
                required:
                  - id
                  - name
                  - memberCount
          required:
            - kind
            - directAdminCount
            - directAdmins
            - adminTeams
        - type: object
          properties:
            kind:
              type: string
              const: team
            team:
              anyOf:
                - $ref: '#/components/schemas/PermissionSetTeam'
                - type: 'null'
            memberCount:
              type: integer
              minimum: -9007199254740991
              maximum: 9007199254740991
            members:
              anyOf:
                - type: array
                  items:
                    $ref: '#/components/schemas/PermissionPerson'
                - type: 'null'
              description: >-
                Names and emails of the team's members. Null unless the caller
                holds teams.view; memberCount is always returned.
          required:
            - kind
            - team
            - memberCount
            - members
    PermissionChangedBy:
      type: object
      properties:
        memberId:
          type: string
        name:
          anyOf:
            - type: string
            - type: 'null'
        email:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Null unless the caller holds teams.view, or when the member has no
            email.
      required:
        - memberId
        - name
        - email
    PermissionPerson:
      type: object
      properties:
        memberId:
          type: string
        name:
          type: string
        email:
          type: string
      required:
        - memberId
        - name
        - email
  securitySchemes:
    denApiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        Organization API key passed as the `x-api-key` header. The raw key is
        the header value; do not prefix it with `Bearer`.
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: session-token
      description: >-
        Den session token passed as `Authorization: Bearer <session-token>` for
        user-authenticated Den routes. Not for API keys: send `den_` keys in the
        `x-api-key` header instead.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.