1. Docs
  2. API Reference
  3. Set Account-wide is_active flag

Set Account-wide is_active flag

PATCH/portal/v1/accounts/{accountSlug}/identities/{id}/status

Activates or deactivates one identity via the is_active body flag — a reversible lifecycle toggle that retains all data (profile, memberships, assignments), distinct from erasure. Rejects a no-op with 409 when the identity is already in the requested state, keeping the audit signal clean, and writes an identity.status_set row. Returns 404 when the identity is not found in this Account.

Authentication

Bearer TokenAuthorization

JWT access token. Never send alongside X-API-Key: a request carrying both is refused.

Requires capability identities.manageIdentities

Manage end-user identities across the account. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.

Path Parameters

idstring Required

Request body

application/json

is_activeboolean Required

Target value for the Identity row's `is_active` flag. `false` deactivates Account-wide; `true` reactivates (per-Environment access still depends on EnvironmentMembership status).

Responses

application/json

  • dataAccountIdentityDetailResponseDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

Errors

When the request can't be completed, the response body includes a stable error code you can branch on.

403account.capability_requiredForbidden
When it happens

The signed-in user's administrator roles do not grant the capability this endpoint requires.

Remediation

Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.

Returned object

Request
curl -X PATCH "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/identities/value/status" \
  -H "Authorization: Bearer $CANOPY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "is_active": false
  }'
Response
{
  "data": {
    "id": "string",
    "email": "string",
    "first_name": "string",
    "last_name": "string",
    "avatar_url": "string",
    "external_id": "string",
    "metadata": {},
    "is_active": false,
    "erased_at": "2026-04-20T12:00:00.000Z",
    "email_verified": false,
    "email_verified_at": "2026-04-20T12:00:00.000Z",
    "locked_until": "2026-04-20T12:00:00.000Z",
    "password_changed_at": "2026-04-20T12:00:00.000Z",
    "environment_membership_count": 0,
    "total_assignments": 0,
    "created_at": "2026-04-20T12:00:00.000Z",
    "environment_memberships": [
      {
        "id": "string",
        "environment_id": "string",
        "environment_slug": "string",
        "environment_name": "string",
        "application_slug": "string",
        "application_name": "string",
        "status": "active",
        "created_at": "2026-04-20T12:00:00.000Z",
        "assignment_count": 0
      }
    ]
  }
}
Related endpoints
GETList identities in Account
POSTCreate an Account identity
POSTBulk-create Account identities
GETGet directory counts for the Account
GETGet an Account identity
PATCHUpdate an Account identity profile
POSTErase an identity (GDPR/CCPA right to be forgotten)
POSTAdmin-trigger a password reset email
POSTRe-send email verification
POSTRevoke all active sessions for an identity
GETList audit events for an Account identity
POSTAdd an identity to an Environment (create EnvironmentMembership)
POSTBulk-attach EnvironmentMemberships for the Add-from-directory picker
DELETERemove an identity from an Environment (revoke EnvironmentMembership)
Was this page helpful?

Tell us how we can improve this guide.