manageWorkspace, which only internal admins hold. MCP: workspace_member_list / _add / _set_role / _remove. CLI: rip workspace member list|add|set-role|remove.
Auth: Authorization: Bearer tr_... (an account API key). {id} is the workspace UUID.
GET /v0/workspaces/{id}/members
POST /v0/workspaces/{id}/members
Returns the member row (201). Adding an account that is already an external member changes its role.
PATCH /v0/workspaces/{id}/members/{accountId}
Body { "role": "viewer" | "editor" }. {accountId} is the account id, not an alias. Returns the member row.
DELETE /v0/workspaces/{id}/members/{accountId}
Returns 204, also when the account was not a member. Access ends on the next request; the account’s contributions remain.
Access changes
A role change or removal takes effect immediately. Claims on, and assignee suggestions for, tasks the account can no longer see are cleared. A downgrade toviewer or a removal also ends the account’s active sessions and disconnects its paired browser views.
When an external member joins the owning team, the external row is removed in the same transaction, so leaving the team later does not revive guest access.