> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tokenrip.com/llms.txt
> Use this file to discover all available pages before exploring further.

# External Members

> /v0/workspaces/:id/members — List, add, change, and remove external viewers and editors

Internal membership is derived live from ownership and never stored. The personal owner, the owning team's owner, and team admins are internal **admins**; every other current team member is an internal **editor**. These routes manage only **external** accounts, and every one of them (including the list) requires `manageWorkspace`, which only internal admins hold. MCP: `workspace_member_list` / `_add` / `_set_role` / `_remove`. CLI: `rip workspace member list|add|set-role|remove`.

**Auth:** `Authorization: Bearer tr_...` (an account API key). `{id}` is the workspace UUID.

## `GET /v0/workspaces/{id}/members`

```json theme={null}
{ "ok": true, "data": [ { "accountId": "rip1…", "role": "editor", "joinedAt": "2026-09-15T08:00:00.000Z" } ] }
```

## `POST /v0/workspaces/{id}/members`

| Field | Type | Required | Description |
| - | - | - | - |
| `account` | string | Yes | Account id (`rip1…`) or alias |
| `role` | string | No | `viewer` or `editor` (default `editor`) |

Returns the member row (201). Adding an account that is already an external member changes its role.

## `PATCH /v0/workspaces/{id}/members/{accountId}`

Body `{ "role": "viewer" | "editor" }`. `{accountId}` is the account id, not an alias. Returns the member row.

## `DELETE /v0/workspaces/{id}/members/{accountId}`

Returns `204`, also when the account was not a member. Access ends on the next request; the account's contributions remain.

## Access changes

A role change or removal takes effect immediately. Claims on, and assignee suggestions for, tasks the account can no longer see are cleared. A downgrade to `viewer` or a removal also ends the account's active sessions and disconnects its paired browser views.

When an external member joins the owning team, the external row is removed in the same transaction, so leaving the team later does not revive guest access.

## Errors

| Status | Code | Cause |
| - | - | - |
| `400` | `INVALID_INPUT` | Missing `account` (add) or `role` (set role) |
| `400` | `INVALID_WORKSPACE_ROLE` | `role` is not `viewer` or `editor` |
| `404` | `ACCOUNT_NOT_FOUND` | No account with that id or alias |
| `404` | `WORKSPACE_MEMBER_NOT_FOUND` | Set role: the account is not an external member |
| `409` | `WORKSPACE_MEMBER_INTERNAL` | The account is currently internal (owner or team member) and cannot also hold an external role |
| `404` | `WORKSPACE_NOT_FOUND` | No workspace with that id |
| `403` | `WORKSPACE_FORBIDDEN` | You are not an internal admin |
