Update an account
const url = 'https://api.aletheia-ops.com/api/v1/aws/accounts/example';const options = { method: 'PATCH', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"included":true,"regions":["example"],"name":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request PATCH \ --url https://api.aletheia-ops.com/api/v1/aws/accounts/example \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "included": true, "regions": [ "example" ], "name": "example" }'Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Request Bodyrequired
Section titled “Request Bodyrequired”Edits an account’s inclusion, regions, or name
object
Examplegenerated
{ "included": true, "regions": [ "example" ], "name": "example"}Responses
Section titled “Responses”OK
Public shape of an onboarded account
object
Structured probe summary on an account
object
One validation probe outcome
object
Role template an account actually has deployed, read back from the role’s own critias:template-version tag. An absent version means unknown — a role deployed before the template stamped its version, or one Aletheia currently cannot read — which is never the same as being out of date
object
Examplegenerated
{ "id": "example", "account_id": "example", "name": "example", "email": "example", "ou_path": "example", "role_arn": "example", "included": true, "status": "example", "regions": [ "example" ], "effective_regions": [ "example" ], "validation": { "checks": [ { "check": "example", "ok": true, "message": "example" } ], "missing_permissions": [ "example" ], "error": "example" }, "last_validated_at": "2026-04-15T12:00:00Z", "template": { "version": "example", "behind": true }}The request is malformed or fails validation.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "validation_failed", "message": "name: must not be blank"}{ "code": "invalid_state", "message": "invalid or expired install state"}{ "code": "unsafe_base_url", "message": "base URL is not permitted"}{ "code": "invalid_body", "message": "could not read request body"}No valid credential was presented, or it has expired.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "unauthorized", "message": "authentication required"}{ "code": "invalid_credentials", "message": "invalid email or password"}{ "code": "invalid_token", "message": "invalid or expired token"}{ "code": "token_reuse", "message": "session revoked"}{ "code": "webhook_unauthorized", "message": "webhook verification failed"}Authenticated, but not permitted to perform this action.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "forbidden", "message": "you do not have permission to perform this action"}{ "code": "csrf_failed", "message": "missing or invalid CSRF token"}{ "code": "account_deactivated", "message": "your account is deactivated; contact your administrator"}{ "code": "ai_disabled", "message": "the AI assistant is disabled for this organization"}The resource does not exist, or belongs to another organization. The two are deliberately indistinguishable.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "not_found", "message": "resource not found"}The request conflicts with the current state.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "email_taken", "message": "an account with this email already exists"}{ "code": "slug_taken", "message": "organization slug already taken"}{ "code": "name_taken", "message": "a connection with this name already exists"}{ "code": "account_exists", "message": "this AWS account is already connected"}{ "code": "connection_exists", "message": "a connection for this organization already exists"}{ "code": "scan_conflict", "message": "an equivalent scan is already queued or running"}{ "code": "invitation_invalid", "message": "this invitation is no longer valid"}{ "code": "last_admin", "message": "the organization must keep at least one active platform administrator"}{ "code": "conflict", "message": "a resource with this identifier already exists"}{ "code": "turn_in_progress", "message": "a turn is already in progress on this conversation"}An unexpected failure. Diagnostic detail is logged server-side and
deliberately not returned. Quote the X-Request-Id response header when
reporting one.
object
Stable, machine-readable identifier. Branch on this.
Human-readable explanation. Safe to display; do not parse.
Examples
{ "code": "internal_error", "message": "internal server error"}