Skip to main content
PATCH
cURL

Authorizations

Authorization
string
header
required

Access token JWT. Use as Authorization: Bearer . In the API playground, paste the JWT only.

X-Fluide-Api-Key
string
header
default:fl_dev_your_key
required

Developer API key (fl_dev_...). Required on every API call with a machine access token.

X-Fluide-Client-Id
string
header
default:fluide-developer
required

First-party client audience. Must match the fluide_client_id claim on the JWT. Use fluide-developer for Connect.

Body

application/json
requireMfaForOperators
boolean

Require MFA for partner operators on delegated engagements

sessionTimeoutMinutes
number

Session idle timeout in minutes (5–480)

Required range: 5 <= x <= 480
Example:

60

ipAllowlist
string[]

Optional CIDR/IP allowlist entries for firm admin consoles

Maximum array length: 50
Maximum string length: 64

Response

Patch organization security posture for partner firm

success
boolean
required

Whether the request succeeded

Example:

true

message
string
required

Human-readable outcome message (localized when i18n is configured)

Example:

"Operation completed successfully"

data
object

Endpoint-specific payload