Switch organization
Moves this session into another workspace.
- Authentication
- Bearer token
- Retries
- Idempotency-Key
- Body
- application/json
- Version
- 2026-09-03
Any workspace the user is a member of, or one beneath it - an agency entering a client's workspace acts there with the role it holds above. Returns a token pair for the new workspace and rotates the refresh cookie into it, so the switch survives every later refresh.
Needs both credentials: the access token says who is asking, the refresh cookie is what gets moved. A stolen access token alone cannot mint a long-lived session this way.
404 rather than 403 for a workspace the user cannot enter, so the endpoint does not confirm which workspace ids exist.
Headers#
Request body#
Responses#
Errors#
Failures use one envelope on every endpoint, described in Retries, versioning and limits. The codes you are most likely to meet here:
validation_error· 422 — The payload was well-formed JSON but failed schema validation.unauthenticated· 401 — The request carried no API key, or one the API could not verify.forbidden· 403 — The key is valid, but it is not allowed to do this — either the scope is missing or the resource belongs to another workspace.idempotency_key_reused· 422 — This `Idempotency-Key` was used before, for a request with a different body.rate_limited· 429 — Too many requests in the current window. The limit is per workspace, and some endpoints add a per-agent limit on top.
More Auth endpoints#
Something unclear or missing? Tell us and we’ll fix it.