Skip to main content
Neon Docs

Search documentation

Type to search this documentation.

Remove an org member's role on a project

DELETE/projects/{project_id}/members/{member_id}/roleRemove an org member's role on a project

Idempotently removes the explicit project grant. The member's organization-role default project permission still applies. Self-DELETE requires confirm_self_lockout=true when effective manage access would be lost.

Parameters

project_idstringpathrequired

pattern ^[a-z0-9-]{1,60}$

member_idstring · uuidpathrequired
confirm_self_lockoutbooleanquery

Responses

200Role removed, or no-op if no explicit row existedapplication/json
objectProjectMemberRoleResponse
credential_rotation_recommendedboolean

Hint that database credentials may need rotation after the role change.

effective_project_permissionstring

The caller's effective permission for a project when per-project permissions are enabled. `VIEWER` grants read access, `EDITOR` adds update access, and `ADMIN` grants full management. Omitted for personal projects, flag-off organizations, and non-user subjects.

one of "VIEWER", "EDITOR", "ADMIN"

emailstring · email

Email address of the user who has been granted access to the project.

maxLength 256 · minLength 1

explicit_project_permissionstring

The caller's effective permission for a project when per-project permissions are enabled. `VIEWER` grants read access, `EDITOR` adds update access, and `ADMIN` grants full management. Omitted for personal projects, flag-off organizations, and non-user subjects.

one of "VIEWER", "EDITOR", "ADMIN"

member_idstring · uuidrequired
namestring

The user's display name.

org_api_key_rotation_recommendedboolean

Hint that project-scoped org API keys created by the target user may need rotation.

org_default_project_permissionstring

The caller's effective permission for a project when per-project permissions are enabled. `VIEWER` grants read access, `EDITOR` adds update access, and `ADMIN` grants full management. Omitted for personal projects, flag-off organizations, and non-user subjects.

one of "VIEWER", "EDITOR", "ADMIN"

org_rolestringrequired

Organization-level role used by project member role management.

one of "admin", "member", "editor", "viewer", "collaborator"

project_idstringrequired

pattern ^[a-z0-9-]{1,60}$

project_rolestring

Per-project role. `viewer` maps to `VIEWER`, `editor` maps to `EDITOR`, and `admin` maps to `ADMIN`.

one of "viewer", "editor", "admin"

user_idstring · uuidrequired
Example response
{
  "credential_rotation_recommended": true,
  "effective_project_permission": "ADMIN",
  "email": "user@example.com",
  "explicit_project_permission": "ADMIN",
  "member_id": "00000000-0000-0000-0000-000000000000",
  "name": "string",
  "org_api_key_rotation_recommended": true,
  "org_default_project_permission": "ADMIN",
  "org_role": "admin",
  "project_id": "string",
  "project_role": "admin",
  "user_id": "00000000-0000-0000-0000-000000000000"
}
defaultGeneral Error. The request may or may not be safe to retry, depending on the HTTP method, response status code, and whether a response was received. - If no response is returned from the API, a network error or timeout likely occurred. - In some cases, the request may have reached the server and been successfully processed, but the response failed to reach the client. As a result, retrying non-idempotent requests can lead to unintended results. The following HTTP methods are considered non-idempotent: `POST`, `PATCH`, `DELETE`, and `PUT`. Retrying these methods is generally **not safe**. The following methods are considered idempotent: `GET`, `HEAD`, and `OPTIONS`. Retrying these methods is **safe** in the event of a network error or timeout. Any request that returns a `503 Service Unavailable` response is always safe to retry. Any request that returns a `423 Locked` response is safe to retry. `423 Locked` indicates that the resource is temporarily locked, for example, due to another operation in progress. application/json
objectGeneralError
codestringrequired

default ""

messagestringrequired

Error message

request_idstring

Unique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.

Example response
{
  "code": "",
  "message": "string",
  "request_id": "string"
}
Documentation menu