Skip to main content
PATCH
Narrow or widen what an installation may read

Authorizations

Authorization
string
header
required

Bearer token authentication

Path Parameters

id
integer
required

The installation, which is always read within the authenticated company.

Body

application/json

Changes the grant without moving the version.

granted_capabilities
string[]
required

A full replacement rather than an addition, so an omitted or malformed list is refused rather than read as an empty one.

Response

The installation and the company's new grant epoch

widget_installation
object
required

A company's adoption of a published widget package version. granted is the merchant's decision and is stored apart from the manifest's own declaration, so narrowing a grant never edits an artifact: the effective set is the intersection, computed per request, which is why a revocation takes effect on the next call rather than at the next publish.

grant_epoch
integer
required

The company's grant epoch after this write. Descriptors are cached by (version, company, epoch), so a bumped epoch is what retires every cached descriptor at once.