Change member role
Change a member's role. Owners can manage every other member, owners included, and are the only ones who may assign owner or change an owner's role; admins can manage guests and members and assign guest, member or admin. Nobody changes their own role. The caller is judged on their current role in the organization. Granting owner or changing an owner's role requires a dashboard session — any token (API key, OAuth/MCP client, CLI) is refused with 403 even when its user is an owner.
PUT
/api/orgs/{orgId}/members/{userId}better-auth.session_token<token>
Cookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.
In: cookie
Path Parameters
orgId*string
userId*string
Request Body
application/json
curl -X PUT "https://your-instance/api/orgs/string/members/string" \ -H "Content-Type: application/json" \ -d '{ "role": "owner" }'{
"userId": "usr_def456",
"displayName": "Bob",
"email": "[email protected]",
"role": "admin",
"joinedAt": "2026-01-12T10:00:00Z"
}{
"type": "https://docs.appstrate.dev/errors/validation-failed",
"title": "Validation Failed",
"status": 400,
"detail": "name: Invalid input: expected string, received undefined (+2 more)",
"code": "validation_failed",
"request_id": "req_abc123",
"errors": [
{
"field": "name",
"code": "required",
"message": "Invalid input: expected string, received undefined"
},
{
"field": "email",
"code": "invalid_format",
"message": "Invalid email address"
},
{
"field": "age",
"code": "invalid_type",
"message": "Invalid input: expected number, received string"
}
]
}{
"type": "https://docs.appstrate.dev/errors/unauthorized",
"title": "Unauthorized",
"status": 401,
"detail": "Invalid or missing session",
"code": "unauthorized",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/forbidden",
"title": "Forbidden",
"status": 403,
"detail": "Insufficient permissions",
"code": "forbidden",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/not-found",
"title": "Not Found",
"status": 404,
"detail": "Resource not found",
"code": "not_found",
"request_id": "req_abc123"
}