Replaces the scopes of one of the caller's automation tokens (duplicates removed; an empty list disables the token without deleting it) and returns the updated token. Returns 403 while automation tokens are turned off, 400 for an unsupported scope and 404 when the id is not one of the caller's automation tokens.
PATCH
/auth/tokens/{id}/scopes
curl \
--request PATCH 'http://api.example.com/auth/tokens/{id}/scopes' \
--header "Authorization: Bearer $ACCESS_TOKEN" \
--header "Content-Type: application/json" \
--data '{
"scopes": [
"cases:create"
]
}'
Request examples
{
"scopes": [
"cases:create"
]
}
Response examples (200)
{
"data": {
"createdAt": "2026-01-15T14:30:00.000Z",
"updatedAt": "2026-01-15T14:30:00.000Z",
"id": "507f1f77bcf86cd799439011",
"label": "Intake automation",
"scopes": [
"cases:create",
"codes:create"
],
"lastUsed": "2026-01-15T14:30:00.000Z",
"validTill": "2027-01-15T14:30:00.000Z",
"isRevoked": false
},
"statusCode": 200,
"timestamp": "2026-01-15T10:15:00.000Z"
}