> ## Documentation Index
> Fetch the complete documentation index at: https://docs.devic.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Set a user’s access and visibility

> Creates or updates the access row of one user. `userHiddenToolNames` applies on top of the assigned profile, so a single user can be given a narrower surface without a profile of their own.



## OpenAPI

````yaml PATCH /v1/tool-servers/{toolServerId}/users/{userUID}
openapi: 3.0.0
info:
  title: Devic.ai Public API
  description: >-
    Devic.ai is an AI platform that allows you to create, manage, and use AI
    agents for various tasks.
  version: 1.0.0
  contact:
    name: Devic.ai Support
    url: https://devic.ai
  x-logo:
    url: https://devic.ai/logo.png
    altText: Devic.ai Logo
  x-summary: Public API for interacting with Devic.ai platform
servers:
  - url: https://api.devic.ai
    description: Production server
  - url: https://staging-api.devic.ai
    description: Staging server
security:
  - bearerAuth: []
tags:
  - name: Projects
    description: Group agents, assistants, documents and costs into projects
  - name: Documents
    description: >-
      Knowledge base documents: create, version, attach and index markdown
      content for RAG
  - name: Document Folders
    description: Organise knowledge base documents into folders and attach them in bulk
  - name: Files
    description: Upload files and obtain shareable download URLs to attach to messages
  - name: Agents
    description: Endpoints related to AI agents and their operations
  - name: Assistants
    description: Endpoints for interacting with assistants and their specializations
  - name: Tool Servers
    description: Endpoints for managing tool servers and their tool definitions
  - name: Health
    description: API health check endpoints
  - name: Documentation
    description: Endpoints for retrieving markdown documentation
  - name: Integrations
    description: Connect third-party apps and turn them into tools
  - name: Triggers
    description: Start an agent or an assistant from an app event
  - name: Tenant Integrations
    description: Apps that each end user connects for themselves
  - name: Memory
    description: What an assistant remembers between conversations
  - name: Skills
    description: Reusable instruction packs for agents and assistants
  - name: Speech to Text
    description: Audio transcription
  - name: Tenants
    description: Tenants, subtenants and their usage
  - name: MCP Gateway
    description: One MCP endpoint over many servers, with visibility per user
  - name: Tenant Sessions
    description: Tokens that prove which end user is calling
paths:
  /v1/tool-servers/{toolServerId}/users/{userUID}:
    patch:
      tags:
        - MCP Gateway
      summary: Set a user's access and visibility
      description: >-
        Creates or updates the access row of one user. `userHiddenToolNames`
        applies on top of the assigned profile, so a single user can be given a
        narrower surface without a profile of their own.
      operationId: setGatewayUserAccess
      parameters:
        - name: toolServerId
          in: path
          required: true
          description: Id of the MCP Gateway tool server
          schema:
            type: string
        - name: userUID
          in: path
          required: true
          description: Devic user id
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SetMcpGatewayUserAccessRequest'
      responses:
        '200':
          description: Access row saved
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/McpGatewayUserAccess'
        '401':
          description: Unauthorized - Invalid or missing token
        '404':
          description: Not Found
        '500':
          description: Internal Server Error
      security:
        - bearerAuth: []
components:
  schemas:
    SetMcpGatewayUserAccessRequest:
      type: object
      properties:
        allowed:
          type: boolean
        profileId:
          type: string
          nullable: true
          description: Profile to assign, or null to clear it
        userHiddenToolNames:
          type: array
          items:
            type: string
    McpGatewayUserAccess:
      type: object
      description: What one user is allowed to reach on a gateway.
      properties:
        _id:
          type: string
        toolServerId:
          type: string
        userUID:
          type: string
        allowed:
          type: boolean
          description: Whether the user can use the gateway at all
        profileId:
          type: string
          nullable: true
          description: Visibility profile assigned to the user
        userHiddenToolNames:
          type: array
          items:
            type: string
          description: Extra tools hidden for this user, on top of the profile
        creationTimestampMs:
          type: integer
          format: int64
        lastEditTimestampMs:
          type: integer
          format: int64
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Use JWT token for authentication

````