1. Docs
  2. API Reference
  3. Remove an identity from an Environment (revoke EnvironmentMembership)

Remove an identity from an Environment (revoke EnvironmentMembership)

DELETE/portal/v1/accounts/{accountSlug}/identities/{id}/environment-memberships/{envId}

Deactivates the EnvironmentMembership joining one identity to the Environment identified by envId and revokes every role assignment that identity holds at the Environment's hierarchy nodes. The identity row itself is retained (it may still belong to other Environments). Returns 404 when the identity is unknown or holds no membership in that Environment, and responds 204.

Authentication

Bearer TokenAuthorization

JWT access token. Never send alongside X-API-Key: a request carrying both is refused.

Requires capability identities.manageIdentities

Manage end-user identities across the account. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.

Path Parameters

idstring Required
envIdstring Required

Responses

Deactivates the EnvironmentMembership row and revokes every role assignment the identity holds at this Environment's hierarchy nodes. The Identity row itself stays (it may still belong to other Environments).

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

Errors

When the request can't be completed, the response body includes a stable error code you can branch on.

403account.capability_requiredForbidden
When it happens

The signed-in user's administrator roles do not grant the capability this endpoint requires.

Remediation

Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.

Request
curl -X DELETE "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/identities/value/environment-memberships/value" \
  -H "Authorization: Bearer $CANOPY_TOKEN"
Response
HTTP/1.1 204 Deactivates the EnvironmentMembership row and revokes every role assignment the identity holds at this Environment's hierarchy nodes. The Identity row itself stays (it may still belong to other Environments).

(empty body)
Related endpoints
GETList identities in Account
POSTCreate an Account identity
POSTBulk-create Account identities
GETGet directory counts for the Account
GETGet an Account identity
PATCHUpdate an Account identity profile
PATCHSet Account-wide is_active flag
POSTErase an identity (GDPR/CCPA right to be forgotten)
POSTAdmin-trigger a password reset email
POSTRe-send email verification
POSTRevoke all active sessions for an identity
GETList audit events for an Account identity
POSTAdd an identity to an Environment (create EnvironmentMembership)
POSTBulk-attach EnvironmentMemberships for the Add-from-directory picker
Was this page helpful?

Tell us how we can improve this guide.