> ## Documentation Index
> Fetch the complete documentation index at: https://onecli.sh/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Replace a user

> `active: false` suspends the member; `true` reinstates.



## OpenAPI

````yaml /openapi.yaml put /Users/{id}
openapi: 3.1.0
info:
  title: OneCLI API
  version: '1.0'
  description: >
    The OneCLI API manages everything behind the gateway: workspaces, agents and
    what each agent may use (grants), secrets, app connections, organization
    policy, hosted-agent conversations, schedules, memory, skills, Slack
    channels, and the organization's directory.


    **Base URL:** `https://api.onecli.sh/v1` (OneCLI Cloud) or
    `http://localhost:10254/v1` (self-hosted).


    ## Authentication


    Every endpoint takes an `Authorization: Bearer <token>` header unless its
    description says otherwise.


    - **Workspace API key** (`oc_…`) — acts inside one workspace. Read it from
    the dashboard or `GET /user/api-key`.

    - **Organization API key** (`oc_org_…`) — acts for the whole organization.
    Workspace-scoped endpoints additionally need an `X-Workspace-Id` header
    naming the workspace; without it they answer `401`.

    - **Dashboard session** — the browser's own session (Cloud: a bearer JWT;
    self-hosted: the session cookie).


    `X-Workspace-Id` replaced `X-Project-Id`. The old header, the `?_project`
    query bridge, and the `/v1/projects` path alias still work for a deprecation
    window and answer with a `Deprecation: true` header; migrate to the new
    names.


    ## Editions


    Each endpoint states where it is available. Unless marked otherwise an
    endpoint exists on **OneCLI Cloud**, the **Community** self-hosted edition,
    and the **Enterprise** self-hosted edition. Endpoints tagged **Enterprise**
    answer `403` with `error.type: "enterprise_license_required"` on a
    self-hosted deployment that has not set `ENTERPRISE_ENABLED=true`; on Cloud
    they are always present, though some features are additionally gated by the
    organization's plan. Endpoints tagged **Cloud** do not exist on self-hosted
    deployments at all.


    ## Roles


    Organization-level endpoints (`/org/…`) require the **admin** or **owner**
    role wherever roles are enforced (Cloud and Enterprise). The Community
    edition runs a flat team: every active member passes the role check.
servers:
  - url: https://api.onecli.sh/v1
    description: OneCLI Cloud
  - url: http://localhost:10254/v1
    description: Self-hosted
security:
  - bearerAuth: []
tags:
  - name: Workspaces
    description: >-
      Workspaces partition an organization's agents, secrets, and connections.
      Every workspace-scoped endpoint resolves its workspace from the API key
      (or `X-Workspace-Id` with an organization key).
  - name: Agents
    description: >-
      Manage agents, their gateway access tokens, and hosted-agent
      configuration.
  - name: Grants
    description: >-
      Which credentials each agent may use — attach app connections (with
      optional per-tool allow/approval lists and resource scoping) and secrets.
      Writes take effect immediately.
  - name: Secrets
    description: >-
      Credentials the gateway injects into outbound requests that match a host
      pattern.
  - name: Apps
    description: >-
      The app catalog, OAuth and direct-credential connects, your own OAuth
      client configuration, permission catalogs, and blocklists.
  - name: Connections
    description: Connected app accounts as a top-level resource.
  - name: Effective policy
    description: >-
      Read-only reflections of what the enforced policy means for an agent, a
      connection, or an app — workspace grants composed with organization rules.
  - name: Conversations
    description: >-
      Talk to a hosted agent. A conversation owns its turns, transcript, and
      attachments.
  - name: Schedules
    description: Cron-style schedules on a hosted agent.
  - name: Memories
    description: A hosted agent's memory files and their revision history.
  - name: Skills
    description: >-
      Skills reachable from a workspace — the organization's, the workspace's
      own, and per-agent ones.
  - name: Channels
    description: >-
      Where a hosted agent is reachable (Slack), who may reach it, who it may
      message, and which other agents it may talk to.
  - name: Approvals
    description: Long-poll for the gateway's manual-approval requests and submit decisions.
  - name: User
    description: Your profile, API keys, SSH keys, and account deletion.
  - name: Instance
    description: Unauthenticated deployment facts and bootstrap endpoints.
  - name: Utility
    description: Counts, vaults, and agent bootstrap helpers.
  - name: Organization
    description: The current organization and its invitations. Free on every edition.
  - name: Organization secrets
    description: Secrets shared into every workspace of the organization.
  - name: Organization policy
    description: >-
      The organization's first-match rule set — blocks, allows, rate limits,
      approvals, and app permissions that bind every workspace.
  - name: Organization connections
    description: App connections shared into every workspace of the organization.
  - name: Organization apps
    description: >-
      Connect apps and configure your own OAuth clients at the organization
      level.
  - name: Organization skills
    description: Skills every workspace in the organization receives.
  - name: Organization channels
    description: The organization's Slack integration and identity links.
  - name: Organization approvals
    description: Long-poll for manual-approval requests across every workspace.
  - name: Members
    description: The organization directory — list, provision, suspend, and remove members.
  - name: Groups
    description: Directory groups and group-to-role mappings.
  - name: Workspace access
    description: Share a workspace with people and groups.
  - name: Domains
    description: Verified email domains, the anchor for SSO and home-realm discovery.
  - name: SSO
    description: SAML and OIDC sign-in connections and organization-wide enforcement.
  - name: SCIM tokens
    description: Bearer tokens for the organization's SCIM endpoint.
  - name: App availability
    description: Restrict which apps each workspace may connect.
  - name: Provisioning
    description: >-
      Pre-create members with a ready workspace and API key, then let them claim
      the account.
  - name: Resource browsing
    description: Browse a connected account's folders to pick resource scopes for a grant.
  - name: SCIM
    description: >-
      The SCIM 2.0 provisioning endpoint for identity providers (Okta, Entra ID,
      and others).
paths:
  /Users/{id}:
    put:
      tags:
        - SCIM
      summary: Replace a user
      description: '`active: false` suspends the member; `true` reinstates.'
      operationId: scimReplaceUser
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/scim+json:
            schema:
              $ref: '#/components/schemas/ScimUser'
      responses:
        '200':
          description: The User
          content:
            application/scim+json:
              schema:
                $ref: '#/components/schemas/ScimUser'
        '403':
          description: Not entitled — the SCIM surface is dark on a Community deployment
          content:
            application/scim+json:
              schema:
                $ref: '#/components/schemas/ScimError'
        '404':
          description: Not found
          content:
            application/scim+json:
              schema:
                $ref: '#/components/schemas/ScimError'
      servers:
        - url: https://api.onecli.sh/scim/v2
          description: OneCLI Cloud
        - url: http://localhost:10254/scim/v2
          description: Self-hosted
components:
  schemas:
    ScimUser:
      type: object
      description: >-
        RFC 7643 User. OneCLI maps `userName` and `emails[0]` to the member's
        email, `displayName` (or `name`) to the display name, and `active` to
        the membership status (`false` = suspended). Group membership is managed
        through `/Groups`.
      properties:
        schemas:
          type: array
          items:
            type: string
          example:
            - urn:ietf:params:scim:schemas:core:2.0:User
        id:
          type: string
        userName:
          type: string
        displayName:
          type: string
        name:
          type: object
          description: The name components as supplied by the identity provider.
          properties:
            givenName:
              type: string
            familyName:
              type: string
            formatted:
              type: string
        emails:
          type: array
          items:
            type: object
            properties:
              value:
                type: string
              primary:
                type: boolean
        active:
          type: boolean
        meta:
          type: object
          properties:
            resourceType:
              type: string
            created:
              type: string
            lastModified:
              type: string
            location:
              type: string
    ScimError:
      type: object
      properties:
        schemas:
          type: array
          items:
            type: string
          example:
            - urn:ietf:params:scim:api:messages:2.0:Error
        status:
          type: string
        scimType:
          type: string
        detail:
          type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        A workspace API key (`oc_…`) or organization API key (`oc_org_…`).
        Workspace-scoped endpoints called with an organization key also need
        `X-Workspace-Id`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.