1. Docs
  2. API Reference
  3. Switch the Environment's organizations container on or off

Switch the Environment's organizations container on or off

PUT/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/organizations-feature

Switches the organizations container of the Environment named by :envSlug on or off with { enabled }. The container is independent of the access model: a flat Environment holds one membership role per identity per organization, a hierarchy Environment hangs its tree beneath each organization. Enabling reserves the tier directly under the root for organizations, so it returns 409 while nodes already sit there (revert to flat first) and 400 while a hierarchy schema is not rooted at organization. Disabling returns 409 while organizations remain (delete them first) or while a hierarchy schema is configured (revert to flat first). A no-op when the setting is unchanged; 404 for a missing slug. Emits environment.organizations_enabled or environment.organizations_disabled.

Authentication

Bearer TokenAuthorization

JWT access token. Never send alongside X-API-Key: a request carrying both is refused.

Requires capability env_organizations.manageDeveloper Console

Switch the organizations container on and off and create, rename, and delete organizations. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.

Path Parameters

envSlugstring Required

Request body

application/json

enabledboolean Required

`true` to reserve the tier under the root for organizations; `false` to switch the container off (requires an empty container and a flat Environment).

Responses

application/json

  • dataEnvironmentResponseDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

Errors

When the request can't be completed, the response body includes a stable error code you can branch on.

403account.capability_requiredForbidden
When it happens

The signed-in user's administrator roles do not grant the capability this endpoint requires.

Remediation

Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.

Returned object

Request
curl -X PUT "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/value/organizations-feature" \
  -H "Authorization: Bearer $CANOPY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "enabled": false
  }'
Response
{
  "data": {
    "id": "string",
    "application_id": "string",
    "name": "string",
    "slug": "string",
    "is_production": false,
    "settings": {},
    "version": 0,
    "created_at": "2026-04-20T12:00:00.000Z",
    "updated_at": "2026-04-20T12:00:00.000Z"
  }
}
Related endpoints
GETList Environments in an Application
POSTCreate a new Environment in an Application
GETGet a single Environment by slug
PATCHRename or re-slug an Environment
DELETEDelete an Environment
GETGet an Environment's sign-in settings
PATCHChange an Environment's sign-in settings
GETExport an Environment's configuration as JSON
POSTReplace an Environment's configuration from a JSON payload (destructive)
GETGet the Environment's access model
PUTSwitch the Environment's access model
GETGet hierarchy schema for the active Environment
PATCHUpdate hierarchy schema for the active Environment
GETList hierarchy node types with existing nodes
POSTRevert this Environment from hierarchy to flat
Was this page helpful?

Tell us how we can improve this guide.