workspaceId, audience, the guarded-write preconditions, and optional workspaceSessionId (see Create Artifact, Publish Version, Append Rows, Create Task).
Auth: Authorization: Bearer tr_... (an account API key). {id} is always the workspace UUID: slugs are not resolved, and a non-UUID id is a 400.
The operator dashboard uses mirrors under
/v0/operator/workspaces… with a browser session. The operator surface adds artifact create/list, folder rename and removal, GET …/pins, …/browser-context, a browser reader (…/activity, …/activity/peek, …/activity/ack), and the browser-tab routes (…/views, …/views/{viewId}/pair|context|poll|navigation-ack|disconnect). It omits the credential-bound load, end, view, view/open, and changes routes.
Roles and capabilities
Every workspace response that describes the workspace carries your liverole (admin | editor | viewer), membership (internal | external), audiences, and capabilities. Internal members see internal and shared content; external members see only shared.
While a workspace is archived, every capability except
read, navigate, manageWorkspace, and deleteWorkspace reads false.
Shared errors
Writes that accept
workspaceSessionId validate it before writing: