Version
DESTRUCTIVE

update_group

Rename a group or replace its permission set. Membership is a separate tool.

Renames a group or replaces the permissions it grants. code is immutable, so a rename never breaks a reference.

Who is in the group is sync_group_members, not this — a rename is cosmetic, while changing the permission set silently re-scopes everyone already in the group.

Permissions replace, they do not merge

Sending permissions sets the group's permissions to exactly that list. Omit the key entirely to leave the existing set untouched while changing only the name.

Growth-tier capability. On a lower tier this returns TEAM_TIER_REQUIRED and changes nothing.

Requires ability

The token behind the MCP session must hold it, or the call is refused with TOKEN_MISSING_ABILITY.

Runs the same action as

The REST endpoint and this tool share one action, so validation, permissions and events are identical.

Fires one event

Delivered to every endpoint subscribed to it once the change is made.

Annotations

DestructiveOpen world

A client that honours annotations asks a person before running it. It reaches beyond Subscriby: a connector, a provider or a member.

Arguments

group_id*string

UUID of the group to update.

namestringoptional

New group name. Omit to keep the current one.

permissionsarrayoptional

Complete replacement permission set. Omit to leave permissions untouched.

What it returns

{  "data": {    "id": "1f68d92a-04c5-4e83-97b1-3d6a05e2f847",    "team_id": "a83f0d51-4c92-4b7e-8615-2fd9e70a3c86",    "code": "billing-team",    "name": "Billing & Finance",    "permissions": ["project-subscription:view-any", "payment:view-any"]  }}

How it fails

AUTHENTICATION_REQUIRED

no authenticated user on the request.

TOKEN_MISSING_ABILITY

token lacks group:update.

TEAM_TIER_REQUIRED

the caller's platform tier does not include Teams.

RESOURCE_NOT_FOUND

no such group in any team the caller belongs to.

VALIDATION_FAILED

an unknown permission string.

How is this guide?

Last updated on