Update one of the bank's staff members
PATCH/v1/bank-staff/:staff_id
Replaces the role labels and API scopes of an existing staff member (the email is immutable). The new values are staged and only applied once identity provisioning succeeds: the member moves to UPDATING (while remaining live on its previous grants) and back to ACTIVE on success, or to UPDATE_FAILED if provisioning is exhausted. data.id must match staff_id in the path.
Only members in the ACTIVE or UPDATE_FAILED state can be updated; any other state is rejected.
The same scope rules as create apply (no granting scopes the caller lacks, staff-administration scopes only for bank-admin, write implies read). The request is also rejected if it would remove the last active holder of connector:staff:read or connector:staff:write in the bank, so the bank can never be locked out of staff administration.
Requires the connector:staff:write scope.
Request
Responses
- 200
- 400
- 403
- 404
- 422
- 503
Staff member update accepted; re-provisioning queued.
The request is malformed: invalid JSON syntax, an invalid path or query parameter, a
missing required header such as Idempotency-Key, or a single field that fails its own
format rule. Fix the request before retrying; retrying it unchanged fails again.
The token is valid but may not perform this request: it lacks the required scope, has
no bank membership, needs an x-dan-bank-id header to choose between several
memberships, names a bank in x-dan-bank-id it has no membership for, or the caller's
bank is suspended or terminated. A new token with the same configuration fails the same
way. See the Authentication section.
The resource does not exist, or it belongs to another bank. The Lyriq Connector does not distinguish the two cases, so resources of other banks are never disclosed.
The request is well-formed JSON but cannot be processed: the body does not match the
expected shape (a missing or unknown member, a wrong type, or a wrong data.type), or it
breaks a business or cross-field rule. Correct the request before retrying.
The request could not be served right now. Either the network is not fully operational
(OUTBOUND_HALTED or READ_ONLY: mutations are refused while read endpoints keep
working; OPERATIONAL_STATE_UNKNOWN: the state could not be determined), or a platform
dependency is temporarily unavailable. No Retry-After header is sent; retry later with
backoff. When retrying a mutation, reuse the same Idempotency-Key and body.