manageContext (internal admins and editors). Visibility is resolved on load: an external member never learns that an internal pin exists. MCP: workspace_pin / workspace_unpin. CLI: rip workspace pin add|remove.
Auth: Authorization: Bearer tr_... (an account API key). {id} is the workspace UUID.
POST /v0/workspaces/{id}/pins
Returns (201):
DELETE /v0/workspaces/{id}/pins/{artifactId}
{artifactId} is the public id or alias. Returns 204, also when the artifact was not pinned. The artifact itself is untouched, and later pins move up one slot.