Set Account-wide is_active flag
/portal/v1/accounts/{accountSlug}/identities/{id}/statusAuthentication
- Bearer Token
AuthorizationJWT access token
Path Parameters
| Name | Required | Type | Description |
|---|---|---|---|
id | string |
Request body
is_active *booleanTarget value for the Identity row's `is_active` flag. `false` deactivates Account-wide; `true` reactivates (per-App access still depends on AppMembership status).
Code samples
curl -X PATCH "https://api.canopy.dev/portal/v1/accounts/{accountSlug}/identities/value/status" \
-H "Authorization: Bearer $CANOPY_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"is_active": false
}'const response = await fetch("https://api.canopy.dev/portal/v1/accounts/{accountSlug}/identities/value/status", {
method: "PATCH",
headers: {
"Authorization": "Bearer $CANOPY_TOKEN",
"Content-Type": "application/json"
},
body: JSON.stringify({
"is_active": false
}),
});
const data = await response.json();import requests
response = requests.patch(
"https://api.canopy.dev/portal/v1/accounts/{accountSlug}/identities/value/status",
headers={
"Authorization": "Bearer $CANOPY_TOKEN",
"Content-Type": "application/json"
},
json={
"is_active": False,
},
)
data = response.json()package main
import (
"bytes"
"encoding/json"
"net/http"
)
func main() {
payload := map[string]interface{}{
"is_active": false,
}
body, _ := json.Marshal(payload)
req, _ := http.NewRequest("PATCH", "https://api.canopy.dev/portal/v1/accounts/{accountSlug}/identities/value/status", bytes.NewBuffer(body))
req.Header.Set("Authorization", "Bearer $CANOPY_TOKEN")
req.Header.Set("Content-Type", "application/json")
resp, _ := http.DefaultClient.Do(req)
defer resp.Body.Close()
}Responses
200 Flips the Identity row's `is_active` master kill switch. Deactivation is Account-wide and revokes access in every App; reactivation restores the row but the dual-gate still requires an active AppMembership for each App. Writes Account-tier audit row.
{
"id": "string",
"email": "string",
"first_name": "string",
"last_name": "string",
"avatar_url": "string",
"external_id": "string",
"metadata": {},
"is_active": false,
"email_verified": false,
"email_verified_at": "2026-04-20T12:00:00.000Z",
"locked_until": "2026-04-20T12:00:00.000Z",
"password_changed_at": "2026-04-20T12:00:00.000Z",
"app_membership_count": 0,
"total_assignments": 0,
"created_at": "2026-04-20T12:00:00.000Z",
"app_memberships": [
{
"id": "string",
"application_id": "string",
"application_slug": "string",
"application_name": "string",
"status": "active",
"created_at": "2026-04-20T12:00:00.000Z",
"assignment_count": 0
}
]
}application/json
id *stringemail *stringfirst_name *stringlast_name *stringavatar_urlstringexternal_idstringmetadataany objectis_active *booleanemail_verified *booleanemail_verified_atstring (date-time)locked_untilstring (date-time)When non-null and in the future, the identity is locked out from login attempts. Set by the progressive lockout policy on repeated failed logins.
password_changed_atstring (date-time)app_membership_count *numbertotal_assignments *numbercreated_at *string (date-time)app_memberships *AccountIdentityAppMembershipDto[]Every active AppMembership for this identity, ordered by Application name. Each entry carries the App's slug + name so the drawer can render links without an additional lookup, plus the per-App assignment count.
401 Invalid or expired token
403 This token is not authorized for this endpoint (wrong principal type — e.g., admin token on identity-only endpoint, or vice versa)
404 Identity not found
409 Identity is already in the requested state (no-op rejected to keep audit signal clean)