Skip to main content
Update Workspace
Edits a workspace’s own name and/or metadata. Gated by the edit-workspace capability (or owner).
This does not flip inheritsFromParent — that is a separate owner-only action.

Path Parameters

string
required
The workspace UUID.

Body Parameters

string
New display name. 1–100 characters.
object
New metadata (opaque JSON).
string
Service/master keys only — the user to act as. Enforced: the edit-workspace capability (or ownership) is required of the named user, so a key naming someone without it is refused exactly as that user would be. Omit it to act as the app itself (unbounded). See Acting on behalf of a user.The node SDK is stricter than this endpoint: it types actingUserId as required here, so omitting it is only possible by calling the REST route directly.Several shapes are refused rather than ignored on this path. actingUserId: "" or null is a 400 — it reads as an attempt to name someone, not as “nobody”. So is every top-level field this endpoint does not declare, in the body and in the query string alike, for every caller: onBehalfOf, acting_user_id and impersonate all come back as Unrecognized key: "…" rather than being quietly dropped. A key that differs from actingUserId only in capitalization — actingUserID, actinguserid — is refused too, but with a “did you mean actingUserId?” message instead of the generic one. And when the request names nobody, so is any body whose Content-Type is not application/json — an unparsed body discards the actingUserId inside it just as surely as a misspelling would. See Shapes the server rejects.

Response

Returns the updated Workspace object.

Error Responses

Every path id on the workspaces bundle is checked for UUID shape before the route runs, so a malformed one is a plain 400 rather than a 500 from the database.
Every workspaces endpoint declares its fields exactly, and a top-level field it does not declare is refused rather than ignored — in the request body and in the query string alike, for every caller. Two or more at once are named together: Unrecognized keys: "onBehalfOf", "impersonate". An offender in the query string carries workspace/invalid-query instead. Send only the fields documented above, plus actingUserId and projectId, which every workspaces route accepts. See Shapes the server rejects.
Returned when a service/master key sends a body with a Content-Type other than application/json and no actingUserId was read. Sublay parses only application/json, so the actor inside such a body is discarded and the request would fall through to the unbounded path. fetch() sends text/plain;charset=UTF-8 when you pass a stringified body and set no headers — set the header. An empty JSON body and a bodiless request both pass. See Shapes the server rejects.