Skip to content

Update member access

PATCH/v1/practices/{practiceId}/team/members/{memberId}

Requires team:write. Supply role, status, or locationIds; omitted values stay unchanged. A role replaces existing roles. Disable access with status disabled. An empty locationIds array grants all practice locations. Ownership changes require an active practice owner using a personal API key; service keys manage non-owner memberships. The final active owner cannot be removed. Changes apply to both Test and Live. Sign-in email and account security remain account settings.

Request example

Replace example values with your Test data. Check the field rules below before you send a request.

{
  "role": "owner",
  "roles": [
    "owner"
  ],
  "status": "active",
  "locationIds": [
    "loc_01j2y8m6jcc9tt24af5pw9x1bc"
  ]
}
curl -X PATCH 'https://api.affinityrx.com/v1/practices/{practiceId}/team/members/{memberId}' \
  -H "Authorization: Bearer $AFFINITY_API_KEY" \
  -H 'Affinity-Version: 2026-09-28' \
  -H 'Idempotency-Key: <Idempotency-Key>' \
  -H 'Content-Type: application/json' \
  --data @request.json

Response example

These examples show the body structure. Values can differ. Select a status code to see its response.

{
  "id": "mbr_01j2y8m6jcc9tt24af5pw9x1bc",
  "externalId": "<string>",
  "name": "<string>",
  "email": "<string>",
  "locationIds": [
    "loc_01j2y8m6jcc9tt24af5pw9x1bc"
  ],
  "account": {
    "accountId": "<string>",
    "emailVerified": false,
    "membershipId": "mbr_01j2y8m6jcc9tt24af5pw9x1bc",
    "membershipStatus": "<string>",
    "roles": [
      {
        "id": "role_01j2y8m6jcc9tt24af5pw9x1bc",
        "name": "<string>",
        "key": "<string>"
      }
    ],
    "prescriberConnection": {
      "status": "<string>",
      "provider": {
        "id": "prov_01j2y8m6jcc9tt24af5pw9x1bc",
        "name": "<string>",
        "legalName": "<string>",
        "credentials": "<string>",
        "phone": "<string>",
        "address": {
          "line1": "<string>",
          "line2": "<string>",
          "city": "<string>",
          "state": "<string>",
          "postalCode": "<string>",
          "country": "<string>"
        },
        "npi": "<string>",
        "practiceStatus": "<string>",
        "licenses": [
          {
            "id": "lic_01j2y8m6jcc9tt24af5pw9x1bc",
            "state": "<string>",
            "licenseNumber": "<string>",
            "expiresAt": "<string>"
          }
        ]
      }
    }
  },
  "nextActions": [
    "<string>"
  ]
}
{
  "code": "<string>",
  "data": "<string>",
  "detail": "<string>",
  "instance": "<string>",
  "requestId": "<string>",
  "status": 400,
  "title": "<string>",
  "traceId": "<string>",
  "type": "<string>"
}
{
  "code": "<string>",
  "data": "<string>",
  "detail": "<string>",
  "instance": "<string>",
  "requestId": "<string>",
  "status": 401,
  "title": "<string>",
  "traceId": "<string>",
  "type": "<string>"
}
{
  "code": "<string>",
  "data": "<string>",
  "detail": "<string>",
  "instance": "<string>",
  "requestId": "<string>",
  "status": 403,
  "title": "<string>",
  "traceId": "<string>",
  "type": "<string>"
}
{
  "code": "<string>",
  "data": "<string>",
  "detail": "<string>",
  "instance": "<string>",
  "requestId": "<string>",
  "status": 404,
  "title": "<string>",
  "traceId": "<string>",
  "type": "<string>"
}
{
  "code": "<string>",
  "data": "<string>",
  "detail": "<string>",
  "instance": "<string>",
  "requestId": "<string>",
  "status": 409,
  "title": "<string>",
  "traceId": "<string>",
  "type": "<string>"
}
{
  "code": "<string>",
  "data": "<string>",
  "detail": "<string>",
  "instance": "<string>",
  "requestId": "<string>",
  "status": 429,
  "title": "<string>",
  "traceId": "<string>",
  "type": "<string>"
}

Implementation specification

Use these field types and limits to build your integration. Download the OpenAPI document for the complete contract.

Path parameters

practiceIdstringrequired

Pattern: ^prac_[0-7][0-9a-hjkmnp-tv-z]{25}$

memberIdstringrequired

Pattern: ^mbr_[0-7][0-9a-hjkmnp-tv-z]{25}$

Headers

Affinity-Versionstring

Selects the HTTP API contract for this request only. When omitted, API-key requests use their service account’s stored version. Does not change the stored default.

Pin requests to 2026-09-28.

Idempotency-Keystringrequired

Request body specification application/json

rolestring | null
Show role fields
Any of · 1: string

string

Allowed: "owner", "administrator", "prescriber", "clinical_staff", "billing", "developer"

Any of · 2: null

null

rolesstring[] | null
Show roles fields
Any of · 1: string[]

Array items · string

string

Allowed: "owner", "administrator", "prescriber", "clinical_staff", "billing", "developer"

Any of · 2: null

null

statusstring | null
Show status fields
Any of · 1: string

string

Allowed: "active", "disabled"

Any of · 2: null

null

locationIdsstring[] | null

Replace location access. An empty array grants access to all practice locations.

Show locationIds fields
Any of · 1: string[]

Array items · string

string

Pattern: ^loc_[0-7][0-9a-hjkmnp-tv-z]{25}$

Any of · 2: null

null

Response specifications

200Successful response

application/json

idstringrequired

Pattern: ^mbr_[0-7][0-9a-hjkmnp-tv-z]{25}$

externalIdstring | nullrequired

This integration's external ID for the accepted invitee in the API key's mode. Null for members invited outside this integration.

Show externalId fields
Any of · 1: string

string

Any of · 2: null

null

namestringrequired
emailstring | nullrequired
Show email fields
Any of · 1: string

string

Any of · 2: null

null

locationIdsany[]required
Show locationIds fields

Array items · any

All of · 1: any

any

Pattern: ^loc_[0-7][0-9a-hjkmnp-tv-z]{25}$

accountobjectrequired

No additional properties

Show account fields
accountIdstringrequired
emailVerifiedbooleanrequired
membershipIdanyrequired
Show membershipId fields
All of · 1: any

any

Pattern: ^mbr_[0-7][0-9a-hjkmnp-tv-z]{25}$

membershipStatusstringrequired
rolesobject[]required
Show roles fields

Array items · object

idanyrequired
Show id fields
All of · 1: any

any

Pattern: ^role_[0-7][0-9a-hjkmnp-tv-z]{25}$

namestringrequired
keystring | nullrequired
Show key fields
Any of · 1: string

string

Any of · 2: null

null

prescriberConnectionobject | nullrequired
Show prescriberConnection fields
Any of · 1: object
statusstringrequired
providerobjectrequired

No additional properties

Show provider fields
idanyrequired
Show id fields
All of · 1: any

any

Pattern: ^prov_[0-7][0-9a-hjkmnp-tv-z]{25}$

namestringrequired
legalNamestringrequired
credentialsstring | nullrequired
Show credentials fields
Any of · 1: string

string

Any of · 2: null

null

phonestring | nullrequired
Show phone fields
Any of · 1: string

string

Any of · 2: null

null

addressobject | nullrequired
Show address fields
Any of · 1: object
line1stringrequired
line2string | null
Show line2 fields
Any of · 1: string

string

Any of · 2: null

null

citystringrequired
statestringrequired
postalCodestringrequired
countrystringrequired
Any of · 2: null

null

npistringrequired
practiceStatusstringrequired
licensesobject[]required
Show licenses fields

Array items · object

idanyrequired
Show id fields
All of · 1: any

any

Pattern: ^lic_[0-7][0-9a-hjkmnp-tv-z]{25}$

statestringrequired
licenseNumberstringrequired
expiresAtstring | nullrequired
Show expiresAt fields
Any of · 1: string

string

Any of · 2: null

null

Any of · 2: null

null

nextActionsstring[]required
Show nextActions fields

Array items · string

string

400HTTP 400

application/json

codestringrequired
dataobject
detailstringrequired
instancestringrequired
requestIdstringrequired
statusintegerrequired

Minimum: 400

Maximum: 599

titlestringrequired
traceIdstring
typestringrequired

Format: uri

401Unauthorized

application/json

codestringrequired
dataobject
detailstringrequired
instancestringrequired
requestIdstringrequired
statusintegerrequired

Minimum: 400

Maximum: 599

titlestringrequired
traceIdstring
typestringrequired

Format: uri

403Forbidden

application/json

codestringrequired
dataobject
detailstringrequired
instancestringrequired
requestIdstringrequired
statusintegerrequired

Minimum: 400

Maximum: 599

titlestringrequired
traceIdstring
typestringrequired

Format: uri

404Not found

application/json

codestringrequired
dataobject
detailstringrequired
instancestringrequired
requestIdstringrequired
statusintegerrequired

Minimum: 400

Maximum: 599

titlestringrequired
traceIdstring
typestringrequired

Format: uri

409Conflict

application/json

codestringrequired
dataobject
detailstringrequired
instancestringrequired
requestIdstringrequired
statusintegerrequired

Minimum: 400

Maximum: 599

titlestringrequired
traceIdstring
typestringrequired

Format: uri

429Too many requests

application/json

codestringrequired
dataobject
detailstringrequired
instancestringrequired
requestIdstringrequired
statusintegerrequired

Minimum: 400

Maximum: 599

titlestringrequired
traceIdstring
typestringrequired

Format: uri

Type to search…

↑↓ navigate↵ selectEsc close