1. Docs
  2. API Reference
  3. Bulk-attach EnvironmentMemberships for the Add-from-directory picker

Bulk-attach EnvironmentMemberships for the Add-from-directory picker

POST/portal/v1/accounts/{accountSlug}/identities/environment-memberships/bulk-attach

Partial-success bulk attach for the add-from-directory picker: creates an EnvironmentMembership in one target Environment for each identity in identity_ids. Each identity is processed independently so pre-existing memberships and validation errors fail individually without aborting the batch. Returns 200 on full success or 207 Multi-Status on mixed outcomes, with a { summary, results } body either way. Grants membership only — assigning a role at a node is a separate env-scoped call.

Authentication

Bearer TokenAuthorization

JWT access token. Never send alongside X-API-Key: a request carrying both is refused.

Requires capability identities.manageIdentities

Manage end-user identities across the account. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.

Request body

application/json

environment_idstring Required

The Environment ID to attach the identities to. Must belong to the same Account.

identity_idsstring[] Required

Identity IDs to attach to the Environment as active EnvironmentMembership rows. Each row is processed independently — pre-existing memberships and validation failures are reported per-item rather than failing the batch. Max 200 per request.

Responses

application/json

  • summaryobject*
  • resultsobject[]*

application/json

  • summaryobject*
  • results("success" | "error")[]*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

Errors

When the request can't be completed, the response body includes a stable error code you can branch on.

403account.capability_requiredForbidden
When it happens

The signed-in user's administrator roles do not grant the capability this endpoint requires.

Remediation

Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.

Request
curl -X POST "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/identities/environment-memberships/bulk-attach" \
  -H "Authorization: Bearer $CANOPY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "environment_id": "string",
    "identity_ids": [
      "id_01HXABC...",
      "id_01HXDEF..."
    ]
  }'
Response
{
  "summary": {
    "total": 0,
    "succeeded": 0,
    "failed": 0
  },
  "results": [
    {
      "index": 0,
      "status": "success",
      "code": 0,
      "data": {
        "id": "string",
        "identity_id": "string",
        "environment_id": "string",
        "status": "invited",
        "invited_at": "2026-04-20T12:00:00.000Z",
        "activated_at": "2026-04-20T12:00:00.000Z",
        "deactivated_at": "2026-04-20T12:00:00.000Z",
        "created_at": "2026-04-20T12:00:00.000Z"
      }
    }
  ]
}
Related endpoints
GETList identities in Account
POSTCreate an Account identity
POSTBulk-create Account identities
GETGet directory counts for the Account
GETGet an Account identity
PATCHUpdate an Account identity profile
PATCHSet Account-wide is_active flag
POSTErase an identity (GDPR/CCPA right to be forgotten)
POSTAdmin-trigger a password reset email
POSTRe-send email verification
POSTRevoke all active sessions for an identity
GETList audit events for an Account identity
POSTAdd an identity to an Environment (create EnvironmentMembership)
DELETERemove an identity from an Environment (revoke EnvironmentMembership)
Was this page helpful?

Tell us how we can improve this guide.