Update a permission group. Omitted fields remain unchanged; config keys are patched and supplied arrays replace their lists. Promoting a group to default demotes the previous default; demoting without workspaceIds leaves it inactive. Overlapping member or all-member scopes conflict. Requires organization admin or owner access and active Access Control. Workspace API keys return 403; use a personal API key or scoped OAuth token.
OAuth scope: api:write.
/api/v2/organizations/{organizationId}/permission-groups/{groupId}Your Sim API key, personal or workspace-scoped. Generate one under Settings, then API Keys. Operations that reject workspace keys say so in their own description.
In: header
Path Parameters
Organization that owns the permission groups.
1 <= lengthPermission group identifier.
1 <= lengthRequest Body
application/json
Update Permission Group inputs.
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X PATCH "https://www.sim.ai/api/v2/organizations/string/permission-groups/string" \ -H "X-API-Key: YOUR_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "description": "Restricted workspace access" }'{
"data": {
"id": "group-123",
"organizationId": "org-123",
"name": "Restricted",
"description": null,
"config": {
"allowedIntegrations": null,
"allowedModelProviders": null,
"deniedModels": [],
"deniedTools": [],
"hideTraceSpans": false,
"hideKnowledgeBaseTab": false,
"hideTablesTab": false,
"hideCopilot": false,
"hideIntegrationsTab": false,
"hideSecretsTab": false,
"hideApiKeysTab": false,
"hideInboxTab": false,
"hideFilesTab": false,
"disableMcpTools": false,
"disableCustomTools": false,
"disableSkills": false,
"disableInvitations": false,
"disablePublicApi": false,
"disablePublicFileSharing": false,
"allowedFileShareAuthTypes": null,
"hideDeployApi": false,
"hideDeployMcp": false,
"hideDeployChatbot": false,
"allowedChatDeployAuthTypes": null,
"disablePersonalApiKeys": false,
"disableLogExport": false,
"hideCostInfo": false,
"disableKnowledgeBaseCreation": false,
"disableKnowledgeBaseFileUpload": false,
"allowedKnowledgeConnectors": null,
"disableTableCreation": false,
"disableTableExport": false,
"disableBulkFileDownload": false,
"disablePersonalCredentials": false,
"disableWorkspaceCreation": false,
"hideOrgMemberDirectory": false,
"disableCliAccess": false,
"disableWebhookTriggers": false,
"disableToolAutoApproval": false,
"hideSandboxesTab": false,
"disableOAuthAppAccess": false,
"disableKnowledgeBaseExport": false
},
"isDefault": false,
"membershipMode": "inherit",
"workspaceIds": [
"workspace-123"
],
"createdBy": "admin-123",
"createdAt": "2026-06-01T09:00:00.000Z",
"updatedAt": "2026-06-01T09:00:00.000Z"
}
}{
"error": {
"code": "BAD_REQUEST",
"message": "Invalid request"
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Authentication required"
}
}{
"error": {
"code": "FORBIDDEN",
"message": "Insufficient workspace permissions",
"details": {
"code": "INSUFFICIENT_WORKSPACE_ROLE"
}
}
}{
"error": {
"code": "NOT_FOUND",
"message": "Not found"
}
}{
"error": {
"code": "CONFLICT",
"message": "The request conflicts with the current state of the resource"
}
}{
"error": {
"code": "PAYLOAD_TOO_LARGE",
"message": "Request body is too large"
}
}{
"error": {
"code": "UNSUPPORTED_MEDIA_TYPE",
"message": "Request body must be sent as application/json"
}
}{
"error": {
"code": "RATE_LIMITED",
"message": "API rate limit exceeded",
"details": {
"retryAfter": "2026-01-01T00:00:30.000Z"
}
}
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "Internal server error"
}
}{
"error": {
"code": "SERVICE_UNAVAILABLE",
"message": "Service temporarily unavailable"
}
}