Two Minute Reports Logo
Teams

Update member role

Change a team member's role.
PUT /teams/{teamId}/members/{userId}/role

Changes a member's role on the team.

Authentication: Bearer token · Permission:teams:write · Team permission:members.set_role · Rate limit: default (120 / 60s)
Breaking change, September 2026: viewer, editor and owner are no longer accepted.They named a model the product no longer has. On this endpoint owner meant "runs the team" and mapped to Admin — not the account owner — and there was no name at all for Deputy Admin, Data Manager, or a role your team built for itself. A caller sending owner was granting something other than what they asked for.Send one of admin, deputy_admin, data_manager, editor, viewer — or a roleId, which is the only way to name a custom role. There is no deprecation window; the old names return 400 BAD_REQUEST.
The Owner role cannot be assigned. It belongs to whoever pays for the account, follows the billing email, and there is exactly one per team — so it is absent from the list above rather than merely discouraged.

Beyond the key's own scope, the person who created the key must hold members.set_role on the team, and the containment rules apply exactly as they do in the Hub: you cannot change your own role, you cannot change somebody whose role is not smaller than yours, and the team owner cannot be re-roled at all. Each of those has its own error code — see Errors.

Path parameters

teamId
string · uuid v7 required
The ID of the team.
userId
string · uuid v7 required
The ID of the member to update, from list members.

Request body

Send exactly one of role or roleId.

role
string
A standard role's code: admin, deputy_admin, data_manager, editor or viewer. owner is not assignable.
roleId
string · uuid
A role by ID, from Roles & permissions. The only way to assign a custom role, and unambiguous for standard ones.
{ "role": "data_manager" }
{ "roleId": "01930000-0000-7000-8000-000000000004" }

Request

curl -X PUT https://api.twominutereports.com/v1/teams/0190f8b0-1a2b-7c3d-8e4f-5a6b7c8d9e0f/members/0190f8a4-5e6f-7a8b-9c0d-1e2f3a4b5c6d/role \
  -H "Authorization: Bearer tmrc_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" \
  -H "Content-Type: application/json" \
  -d '{ "role": "data_manager" }'

Response

{
  "success": true,
  "data": { "updated": true }
}
Copyright © 2026