> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pomerado.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Change who has access to a saved login

> Give one member Use, Edit or Manage on a Business team's saved login, give the whole team Use or Edit, or remove either with level null. Nobody changes its creator's access or an Owner's or Admin's. Removing someone's last access stops their unfinished jobs on the login. Only on the Dashboard, for someone who manages the login: elsewhere this answers the login's Share dropdown on the Dashboard.

**Authentication:** `Authorization: Bearer <token>` with Dashboard session, Pomerado MCP OAuth token, API key.

**Permission:** `logins:manage`.

**Effect:** Write: creates or changes something in your account.

**Errors:** [`invalid_request`](/errors#invalid_request) (400), [`unauthorized`](/errors#unauthorized) (401), [`reauthentication_required`](/errors#reauthentication_required) (401), [`forbidden`](/errors#forbidden) (403), [`login_access_required`](/errors#login_access_required) (403), [`team_unavailable`](/errors#team_unavailable) (403), [`not_found`](/errors#not_found) (404), [`access_fixed`](/errors#access_fixed) (409), [`grantee_not_member`](/errors#grantee_not_member) (409), [`team_level_not_allowed`](/errors#team_level_not_allowed) (409), [`request_too_large`](/errors#request_too_large) (413), [`internal_error`](/errors#internal_error) (500), [`temporarily_unavailable`](/errors#temporarily_unavailable) (503). Every error has the same [envelope](/errors).


## OpenAPI

````yaml /api-reference/openapi.json put /v1/logins/{id}/access
openapi: 3.1.0
info:
  title: Pomerado API
  version: '1'
  description: >-
    Run and build website tools, follow their jobs, and manage logins, API keys
    and webhooks. Authenticate with a Pomerado API key (pom_…), an MCP OAuth
    token or a Dashboard session as a Bearer token.
servers:
  - url: https://api.pomerado.ai
security: []
tags:
  - name: account
    x-group: Account
  - name: api_keys
    x-group: API keys
  - name: connected_apps
    x-group: Connected apps
  - name: usage
    x-group: Usage
  - name: quota
    x-group: Quota
  - name: billing
    x-group: Billing
  - name: integrations
    x-group: Integrations
  - name: connect
    x-group: Connect
  - name: logins
    x-group: Logins
  - name: tools
    x-group: Tools
  - name: webhooks
    x-group: Webhooks
  - name: runs
    x-group: Runs
  - name: builds
    x-group: Builds
  - name: jobs
    x-group: Jobs
  - name: support
    x-group: Support
  - name: team
    x-group: Team
paths:
  /v1/logins/{id}/access:
    put:
      tags:
        - logins
      summary: Change who has access to a saved login
      description: >-
        Give one member Use, Edit or Manage on a Business team's saved login,
        give the whole team Use or Edit, or remove either with level null.
        Nobody changes its creator's access or an Owner's or Admin's. Removing
        someone's last access stops their unfinished jobs on the login. Only on
        the Dashboard, for someone who manages the login: elsewhere this answers
        the login's Share dropdown on the Dashboard.
      operationId: logins.set_access
      parameters:
        - name: id
          in: path
          required: true
          description: 'a saved login ID: login_ and 32 lowercase hex digits'
          schema:
            type: string
            examples:
              - login_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LoginAccessChange'
      responses:
        '200':
          description: 'On the Dashboard: who has access now; Elsewhere: the Share dropdown'
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/LoginAccess'
                  - $ref: '#/components/schemas/DashboardDelivery'
        '400':
          description: invalid_request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: unauthorized, reauthentication_required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: forbidden, login_access_required, team_unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: not_found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: access_fixed, grantee_not_member, team_level_not_allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '413':
          description: request_too_large
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: internal_error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: temporarily_unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - bearer: []
components:
  schemas:
    LoginAccessChange:
      type: object
      required:
        - grantee
        - level
      properties:
        grantee:
          anyOf:
            - type: object
              required:
                - type
              properties:
                type:
                  type: string
                  enum:
                    - team
              additionalProperties: false
            - type: object
              required:
                - type
                - user_id
              properties:
                type:
                  type: string
                  enum:
                    - member
                user_id:
                  $ref: '#/components/schemas/user_id'
              additionalProperties: false
        level:
          anyOf:
            - type: string
              enum:
                - use
                - edit
                - manage
            - type: 'null'
          description: Null removes their access
      additionalProperties: false
    LoginAccess:
      type: object
      required:
        - login_id
        - creator
        - team
        - members
      properties:
        login_id:
          type: string
        creator:
          anyOf:
            - type: object
              required:
                - user_id
                - name
                - email
                - former
              properties:
                user_id:
                  type: string
                  description: Their WorkOS user ID
                name:
                  anyOf:
                    - type: string
                    - type: 'null'
                  description: Null when they gave none
                email:
                  anyOf:
                    - type: string
                    - type: 'null'
                  description: >-
                    Null for someone no longer on the team, except to an Owner
                    or Admin
                former:
                  type: boolean
                  description: They are no longer on the team
              additionalProperties: false
            - type: 'null'
          description: >-
            Who created it, and so manages it; null when a login saved before
            Teams has none
        team:
          anyOf:
            - type: string
              enum:
                - use
                - edit
            - type: 'null'
          description: >-
            The whole team's level, later joiners included; null when the team
            has none
        members:
          type: array
          items:
            type: object
            required:
              - user_id
              - name
              - email
              - former
              - level
            properties:
              user_id:
                type: string
                description: Their WorkOS user ID
              name:
                anyOf:
                  - type: string
                  - type: 'null'
                description: Null when they gave none
              email:
                anyOf:
                  - type: string
                  - type: 'null'
                description: >-
                  Null for someone no longer on the team, except to an Owner or
                  Admin
              former:
                type: boolean
                description: They are no longer on the team
              level:
                type: string
                enum:
                  - use
                  - edit
                  - manage
            additionalProperties: false
          description: >-
            Each member's own level. Every Owner and Admin manages it whatever
            this lists
      additionalProperties: false
    DashboardDelivery:
      type: object
      required:
        - dashboard_url
      properties:
        dashboard_url:
          type: string
          description: >-
            A signed-in Dashboard page where the person finishes this and sees
            the secret once
      additionalProperties: false
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
            - retryable
            - docs_url
          properties:
            code:
              type: string
            message:
              type: string
            retryable:
              type: boolean
            docs_url:
              type: string
            details:
              type: object
              required: []
              properties: {}
              additionalProperties:
                $id: /schemas/unknown
          additionalProperties: false
      additionalProperties: false
    user_id:
      type: string
      description: >-
        a team member ID: the user_id GET /v1/team/members gives: user_ and up
        to 100 letters or digits
      examples:
        - user_01K6QZ8V3N4M5P6R7S8T9W0XYZ
  securitySchemes:
    bearer:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.