Switch the Environment's organizations container on or off
/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/organizations-featureSwitches the organizations container of the Environment named by :envSlug on or off with { enabled }. The container is independent of the access model: a flat Environment holds one membership role per identity per organization, a hierarchy Environment hangs its tree beneath each organization. Enabling reserves the tier directly under the root for organizations, so it returns 409 while nodes already sit there (revert to flat first) and 400 while a hierarchy schema is not rooted at organization. Disabling returns 409 while organizations remain (delete them first) or while a hierarchy schema is configured (revert to flat first). A no-op when the setting is unchanged; 404 for a missing slug. Emits environment.organizations_enabled or environment.organizations_disabled.
Authentication
AuthorizationJWT access token. Never send alongside X-API-Key: a request carrying both is refused.
env_organizations.manageDeveloper ConsoleSwitch the organizations container on and off and create, rename, and delete organizations. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.
Path Parameters
envSlugstring Required Request body
application/json
enabledboolean Required `true` to reserve the tier under the root for organizations; `false` to switch the container off (requires an empty container and a flat Environment).
Responses
application/json
data *EnvironmentResponseDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
Errors
When the request can't be completed, the response body includes a stable error code you can branch on.
account.capability_requiredForbiddenThe signed-in user's administrator roles do not grant the capability this endpoint requires.
Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.
Returned object
curl -X PUT "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/value/organizations-feature" \ -H "Authorization: Bearer $CANOPY_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "enabled": false }'
{ "data": { "id": "string", "application_id": "string", "name": "string", "slug": "string", "is_production": false, "settings": {}, "version": 0, "created_at": "2026-04-20T12:00:00.000Z", "updated_at": "2026-04-20T12:00:00.000Z" } }
Tell us how we can improve this guide.