Update a tenant.
const url = 'https://shiftagent.example.com/tenants/example';const options = { method: 'PATCH', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"name":"example","status":"active","settings":{"filler_enabled":true,"default_agent_type":"claude-agent-sdk","max_idle_ttl_seconds":3600,"max_concurrent_warm":5},"metadata":{"additionalProperty":"example"}}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request PATCH \ --url https://shiftagent.example.com/tenants/example \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "name": "example", "status": "active", "settings": { "filler_enabled": true, "default_agent_type": "claude-agent-sdk", "max_idle_ttl_seconds": 3600, "max_concurrent_warm": 5 }, "metadata": { "additionalProperty": "example" } }'Partial update. Merge semantics as everywhere: provided → replaced,
omitted → unchanged, null → cleared (nullable fields).
status: "suspended"immediately rejects new conversation and message writes with403tenant-suspended(reads keep working).- The repository assignment is managed via
PUT /tenants/{tenant_id}/repository, not here. settingstightening applies to future conversations; existing warm sandboxes run out their current idle timer.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”Internal tenant ID.
Request Body required
Section titled “Request Body required ”Partial update for updateTenant. Provided → replaced, omitted → unchanged, null → cleared.
object
Display name.
Suspend or reactivate the tenant.
Replaces the settings object wholesale when provided.
object
Default filler-agent enablement — root of the filler cascade (tenant → conversation → message; most specific wins).
Default runtime.agent_type for new conversations (open enum; e.g. claude-agent-sdk, codex, deepagent).
Cap on any conversation’s warm-sandbox sliding idle timeout (runtime.idle_ttl_seconds).
Cap on simultaneously warm-held sandboxes.
Replaces the metadata map wholesale when provided.
object
Responses
Section titled “ Responses ”Updated tenant.
Unit of isolation mirroring one host-system tenant. Child of the integration key’s root tenant.
object
Host system’s tenant ID (namespaced by the adapter). Unique across the integration; natural key for upsertTenantByExternalId. Null only for tenants created via plain createTenant without one.
Display name. Nullable — external-ID-only creation is valid.
Suspended tenants reject conversation/message writes with 403 tenant-suspended; reads keep working.
The tenant’s assigned repository (read-only here — manage via PUT /tenants/{tenant_id}/repository). Null when the tenant has no assignment of its own; child tenants then inherit the nearest ancestor’s (see getTenantRepository). Every role, conversation, and message in the tenant resolves to this single repository.
Tenant-level runtime defaults and caps. Downstream scopes (conversation, message) may only narrow within these.
object
Default filler-agent enablement — root of the filler cascade (tenant → conversation → message; most specific wins).
Default runtime.agent_type for new conversations (open enum; e.g. claude-agent-sdk, codex, deepagent).
Cap on any conversation’s warm-sandbox sliding idle timeout (runtime.idle_ttl_seconds).
Cap on simultaneously warm-held sandboxes.
Free-form string key–value map for host/adapter bookkeeping (e.g. a host-side reference ID). Max 50 keys; values max 500 chars. Replaced wholesale when provided in updates.
object
RFC 3339 / ISO 8601 timestamp, UTC.
RFC 3339 / ISO 8601 timestamp, UTC.
Example
{ "object": "tenant", "status": "active", "settings": { "filler_enabled": true, "default_agent_type": "claude-agent-sdk", "max_idle_ttl_seconds": 3600, "max_concurrent_warm": 5 }}Missing or invalid credentials — no bearer token, an unknown/revoked sk_int_ key, or an expired platform JWT.
RFC 9457 problem+json error envelope. type is a URI under https://shiftagent.example.com/problems/{slug} (deployment host substituted); see the API-level problem registry for every slug.
object
Problem type URI (registry slug).
Short, human-readable summary of the problem type.
HTTP status code.
Human-readable explanation specific to this occurrence.
URI reference identifying this occurrence.
Correlation ID for support and log lookup.
On name-conflict, external-id-conflict, and resource-in-use: the ID of the existing/depended-on resource — fetch it and continue (replay recovery).
On validation-error, field-level details.
object
JSON pointer to the offending field.
What failed.
Examples
Missing or invalid bearer token
{ "type": "https://shiftagent.example.com/problems/insufficient-scope", "title": "Unauthorized", "status": 401, "detail": "Provide a valid sk_int_ service key or platform JWT.", "request_id": "req_01hzx8auth001"}Not found — the resource does not exist, was deprovisioned, or lies outside the integration key’s subtree (indistinguishable by design).
RFC 9457 problem+json error envelope. type is a URI under https://shiftagent.example.com/problems/{slug} (deployment host substituted); see the API-level problem registry for every slug.
object
Problem type URI (registry slug).
Short, human-readable summary of the problem type.
HTTP status code.
Human-readable explanation specific to this occurrence.
URI reference identifying this occurrence.
Correlation ID for support and log lookup.
On name-conflict, external-id-conflict, and resource-in-use: the ID of the existing/depended-on resource — fetch it and continue (replay recovery).
On validation-error, field-level details.
object
JSON pointer to the offending field.
What failed.
Examples
Unknown resource
{ "type": "https://shiftagent.example.com/problems/not-found", "title": "Not found", "status": 404, "detail": "No tenant with external_id acme:tenant:999999.", "request_id": "req_01hzx8nf001"}Unprocessable — validation-error (schema/semantic validation failed; errors[] lists JSON-pointer details), role-required (the user has no role assigned, so no conversation context can resolve), or missing-secret (a referenced alias is vaulted at no scope).
RFC 9457 problem+json error envelope. type is a URI under https://shiftagent.example.com/problems/{slug} (deployment host substituted); see the API-level problem registry for every slug.
object
Problem type URI (registry slug).
Short, human-readable summary of the problem type.
HTTP status code.
Human-readable explanation specific to this occurrence.
URI reference identifying this occurrence.
Correlation ID for support and log lookup.
On name-conflict, external-id-conflict, and resource-in-use: the ID of the existing/depended-on resource — fetch it and continue (replay recovery).
On validation-error, field-level details.
object
JSON pointer to the offending field.
What failed.
Examples
Field-level validation failure
{ "type": "https://shiftagent.example.com/problems/validation-error", "title": "Validation error", "status": 422, "detail": "One or more fields failed validation.", "errors": [ { "pointer": "/skill_access/skill_ids/0", "message": "skl_01hzx8unknown does not belong to the tenant's repository." } ], "request_id": "req_01hzx8val001"}User has no role at conversation creation
{ "type": "https://shiftagent.example.com/problems/role-required", "title": "Role required", "status": 422, "detail": "User usr_01hzx8jane001 has no role assigned; assign one before starting conversations.", "request_id": "req_01hzx8role01"}