# Update IAM principal

> **PATCH** `https://api.us.nylas.com/v3/iam/principals/{principal_id}`

Source: https://developer.nylas.com/docs/reference/api/iam-principals/update-iam-principal/

Requires `iam.principals.update` on an active principal bound to the authenticated organization. Authenticate with an active, unexpired IAM credential of type `api_key`. Application API keys (including legacy API keys) and provider OAuth tokens cannot authorize IAM management endpoints. Use an existing IAM credential with these permissions, or [create your first management credential in the Dashboard](/docs/v3/auth/nylas-iam/manage-principals-with-api/#create-a-management-credential-in-the-dashboard).

Each supplied field replaces its current value. Omitted fields stay unchanged. An empty roles or direct_permissions array clears that assignment set; an empty description clears the description. resource_binding replaces the single binding. Empty bodies, null values, unknown fields, and add/remove payloads are rejected. When active credentials exist, a non-Organization binding must resolve to exactly one application. A change that violates this invariant returns 409. The last active organization-bound IAM Admin cannot be deleted, disabled, or lose that binding or role.

**Authentication:** IAM_API_KEY

## Parameters

### Path parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `principal_id` | string | Yes | ID of the principal in the authenticated organization. |

## Request body

Content-Type: application/json

- `name` (string, minLength: 1, maxLength: 128) - Descriptive workload name. Surrounding whitespace is removed.
- `description` (string, maxLength: 1024) - Optional workload description.
- `status` (string, one of: `active`, `disabled`) - Whether the principal or credential can authenticate.
- `roles` (array) - System or custom role IDs. Duplicate IDs are removed. Use the Dashboard to manage custom roles. Accepts up to 100 distinct IDs.
- `direct_permissions` (array) - Canonical permission IDs assigned directly to the principal. Duplicate IDs are removed. Accepts up to 100 distinct IDs.
- `resource_binding` (object)
  - `type` (string, one of: `organization`, `application`, `workspace`, `grant`) **(required)** - Resource boundary for this principal.
  - `id` (string, minLength: 1, maxLength: 256) **(required)** - ID of a resource in the authenticated organization.

## Responses

### 200 - OK

- `request_id` (string) - Request ID for troubleshooting.
- `data` (object)
  - `id` (string) **(required)** - Opaque principal ID.
  - `organization_id` (string) **(required)** - Organization inferred from the authenticating IAM API key.
  - `name` (string, minLength: 1, maxLength: 128) **(required)** - Descriptive workload name. Surrounding whitespace is removed.
  - `description` (string, maxLength: 1024, default: `""`) **(required)** - Optional workload description.
  - `status` (string, one of: `active`, `disabled`, default: `"active"`) **(required)** - Whether the principal or credential can authenticate.
  - `roles` (array) **(required)** - System or custom role IDs. Duplicate IDs are removed. Use the Dashboard to manage custom roles. Accepts up to 100 distinct IDs. Accepts up to 100 distinct IDs.
  - `direct_permissions` (array) **(required)** - Canonical permission IDs assigned directly to the principal. Duplicate IDs are removed. Accepts up to 100 distinct IDs. Accepts up to 100 distinct IDs.
  - `resource_binding` (any) **(required)** - The single binding. May be null if its resource was removed and reconciliation cleared the binding.
  - `created_at` (integer, format: int64) **(required)** - Unix timestamp in seconds.
  - `updated_at` (integer, format: int64) **(required)** - Unix timestamp in seconds.

### 400 - Invalid request or object quota exceeded

- `request_id` (string) - Request ID for troubleshooting.
- `error` (object)
  - `code` (string) - Error code.
  - `type` (string) **(required)** - Error category.
  - `message` (string) **(required)** - Description of the failure.
  - `details` (object) - Additional error context. Quota errors include resource_type, limit, and current.
    - `resource_type` (string)
    - `limit` (integer)
    - `current` (integer)

### 401 - Invalid, disabled, deleted, or expired authentication credential

- `request_id` (string) - Request ID for troubleshooting.
- `error` (object)
  - `code` (string) - Error code.
  - `type` (string) **(required)** - Error category.
  - `message` (string) **(required)** - Description of the failure.
  - `details` (object) - Additional error context. Quota errors include resource_type, limit, and current.
    - `resource_type` (string)
    - `limit` (integer)
    - `current` (integer)

### 403 - Missing management permission or organization binding

- `request_id` (string) - Request ID for troubleshooting.
- `error` (object)
  - `code` (string) - Error code.
  - `type` (string) **(required)** - Error category.
  - `message` (string) **(required)** - Description of the failure.
  - `details` (object) - Additional error context. Quota errors include resource_type, limit, and current.
    - `resource_type` (string)
    - `limit` (integer)
    - `current` (integer)

### 404 - Principal or credential not found in this organization

- `request_id` (string) - Request ID for troubleshooting.
- `error` (object)
  - `code` (string) - Error code.
  - `type` (string) **(required)** - Error category.
  - `message` (string) **(required)** - Description of the failure.
  - `details` (object) - Additional error context. Quota errors include resource_type, limit, and current.
    - `resource_type` (string)
    - `limit` (integer)
    - `current` (integer)

### 409 - Conflicting principal or credential state

- `request_id` (string) - Request ID for troubleshooting.
- `error` (object)
  - `code` (string) - Error code.
  - `type` (string) **(required)** - Error category.
  - `message` (string) **(required)** - Description of the failure.
  - `details` (object) - Additional error context. Quota errors include resource_type, limit, and current.
    - `resource_type` (string)
    - `limit` (integer)
    - `current` (integer)

### 429 - Too many requests

- `request_id` (string) - Request ID for troubleshooting.
- `error` (object)
  - `code` (string) - Error code.
  - `type` (string) **(required)** - Error category.
  - `message` (string) **(required)** - Description of the failure.
  - `details` (object) - Additional error context. Quota errors include resource_type, limit, and current.
    - `resource_type` (string)
    - `limit` (integer)
    - `current` (integer)

## Code samples

### cURL

```bash
curl --request PATCH \
  --url "https://api.us.nylas.com/v3/iam/principals/${NYLAS_PRINCIPAL_ID}" \
  --header "Authorization: Bearer $NYLAS_IAM_ADMIN_KEY" \
  --header "Content-Type: application/json" \
  --data '{"direct_permissions": ["messages.read"]}'

```
