Skip to main content
PATCH
Set a user's access and visibility

Authorizations

Authorization
string
header
required

An API key from your Devic console, sent as Authorization: Bearer <key>. An embedded front end sends a tenant-session token instead, so no API key reaches the browser, and an OAuth integration sends its access token. Missing, invalid or expired credentials get a 401. See Authentication.

Path Parameters

toolServerId
string
required

Id of the MCP Gateway tool server

userUID
string
required

Devic user id

Body

application/json
allowed
boolean
profileId
string | null

Profile to assign, or null to clear it

userHiddenToolNames
string[]

Response

Access row saved

What one user is allowed to reach on a gateway.

_id
string
toolServerId
string
userUID
string
allowed
boolean

Whether the user can use the gateway at all

profileId
string | null

Visibility profile assigned to the user

userHiddenToolNames
string[]

Extra tools hidden for this user, on top of the profile

creationTimestampMs
integer<int64>
lastEditTimestampMs
integer<int64>