https://api.us.nylas.com/v3/iam/principals/{principal_id}Update IAM principal
Requires iam.principals.update on an active principal bound to the authenticated organization. Authenticate with an active, unexpired IAM credential of type api_key. Application API keys (including legacy API keys) and provider OAuth tokens cannot authorize IAM management endpoints. Use an existing IAM credential with these permissions, or create your first management credential in the Dashboard.
Each supplied field replaces its current value. Omitted fields stay unchanged. An empty roles or direct_permissions array clears that assignment set; an empty description clears the description. resource_binding replaces the single binding. Empty bodies, null values, unknown fields, and add/remove payloads are rejected. When active credentials exist, a non-Organization binding must resolve to exactly one application. A change that violates this invariant returns 409. The last active organization-bound IAM Admin cannot be deleted, disabled, or lose that binding or role.