Workspaces API
Workspaces are the primary multi-tenant isolation boundary in Zeotap. Each workspace contains its own sources, models, destinations, Reverse ETL pipelines, audiences, syncs, and other resources. New workspaces are created through their parent organization (see Organizations API), and every workspace belongs to one.
A workspace has no membership of its own. People reach it because a group they belong to holds a role on it, so there is no invitation to send, no member role to change and no member to remove here — all three live on the organization. The two reads below are what this surface offers: who reaches the workspace, and which groups grant that.
Endpoints
| Method | Path | Description |
|---|---|---|
GET | /api/v1/workspaces | List workspaces |
GET | /api/v1/workspaces/{id} | Get a workspace |
DELETE | /api/v1/workspaces/{id} | Delete a workspace |
GET | /api/v1/workspaces/{id}/members | Who reaches this workspace, and the grants that let them |
GET | /api/v1/workspaces/{id}/groups | Which of the organization’s groups reach it, and with what role |
GET | /api/v1/workspaces/{id}/settings | Get workspace settings |
PUT | /api/v1/workspaces/{id}/settings | Update workspace settings |
List Workspaces
GET /api/v1/workspaces
Returns all workspaces the authenticated user is a member of. This endpoint does not require the X-Workspace-ID header.
Response
[
{
"id": "550e8400-e29b-41d4-a716-446655440000",
"name": "Production",
"slug": "production",
"avatar_url": "",
"settings": {},
"organization_id": "660e8400-e29b-41d4-a716-446655440000",
"member_count": 12,
"created_at": "2024-01-01T00:00:00Z",
"updated_at": "2024-01-15T09:30:00Z"
},
{
"id": "770e8400-e29b-41d4-a716-446655440000",
"name": "Staging",
"slug": "staging",
"avatar_url": "",
"settings": {},
"organization_id": "660e8400-e29b-41d4-a716-446655440000",
"member_count": 5,
"created_at": "2024-01-05T00:00:00Z",
"updated_at": "2024-01-10T09:30:00Z"
}
]Example
curl -X GET https://agentic.zeotap.com/api/v1/workspaces \
-H "Authorization: Bearer <token>"Create Workspace
Workspaces are created under an organization. See POST /api/v1/organizations/{orgId}/workspaces in the Organizations API.
Get Workspace
GET /api/v1/workspaces/{id}
Returns a single workspace by ID. The authenticated user must be a member of the workspace.
Example
curl -X GET https://agentic.zeotap.com/api/v1/workspaces/{id} \
-H "Authorization: Bearer <token>" \
-H "X-Workspace-ID: <workspace-id>"Update Workspace
Use the Workspace Settings endpoint (PUT /api/v1/workspaces/{id}/settings) to update workspace name, avatar, default role, and other configuration.
Delete Workspace
DELETE /api/v1/workspaces/{id}
Deletes a workspace and all of its resources. Requires owner role. This action is irreversible.
Response
{
"status": "deleted"
}List Members
GET /api/v1/workspaces/{id}/members
Returns everyone who can act in this workspace. The list is derived from the grants that reach them, so each row carries the group and role behind it rather than a role of its own — which is what lets it answer why somebody has access.
Response
[
{
"account_id": "660e8400-e29b-41d4-a716-446655440000",
"email": "alice@example.com",
"name": "Alice Smith",
"avatar_url": "https://...",
"grants": [
{
"group_id": "8b2c5d19-4e60-4a73-b8f2-1c9d0e6a5432",
"group_name": "Organization admins",
"system_key": "org_admins",
"role_id": "00000000-0000-0000-0000-000000000002",
"role_name": "admin",
"scope": "organization"
}
]
},
{
"account_id": "770e8400-e29b-41d4-a716-446655440000",
"email": "bob@example.com",
"name": "Bob Jones",
"avatar_url": "https://...",
"grants": [
{
"group_id": "7c1f4e2a-9b3d-4f18-a0c6-2d5e8b1f9034",
"group_name": "EMEA Marketing",
"system_key": "",
"role_id": "00000000-0000-0000-0000-000000000003",
"role_name": "member",
"scope": "workspace"
}
]
}
]scope is "workspace" for a grant naming this workspace and "organization" for a wildcard one, which reaches every workspace in the organization and so cannot be revoked from here. Somebody in two groups that both reach this workspace has two entries, and their permissions are the union.
A role_id of null is a real state: the group is attached to the workspace and grants no permissions, which keeps its access policies here meaningful.
Example
curl -X GET https://agentic.zeotap.com/api/v1/workspaces/{id}/members \
-H "Authorization: Bearer <token>" \
-H "X-Workspace-ID: <workspace-id>"List the Groups Reaching This Workspace
GET /api/v1/workspaces/{id}/groups
The workspace-side read behind the Settings → Groups tab: which of the organization’s groups hold a role here.
Response
{
"assignments": [
{
"id": "1a2b3c4d-5e6f-4071-8293-a4b5c6d7e8f9",
"group_id": "7c1f4e2a-9b3d-4f18-a0c6-2d5e8b1f9034",
"group_name": "EMEA Marketing",
"group_system_key": "",
"workspace_id": "550e8400-e29b-41d4-a716-446655440000",
"role_id": "00000000-0000-0000-0000-000000000003"
},
{
"id": "9f8e7d6c-5b4a-4938-2716-0f1e2d3c4b5a",
"group_id": "8b2c5d19-4e60-4a73-b8f2-1c9d0e6a5432",
"group_name": "Organization admins",
"group_system_key": "org_admins",
"role_id": "00000000-0000-0000-0000-000000000002"
}
]
}An assignment with no workspace_id is a wildcard: it reaches every workspace in the organization, so it appears here without naming this one.
Granting and Revoking
There is no write on this surface. A grant is made and revoked on the organization:
PUT /api/v1/organizations/{orgId}/groups/{groupId}/workspaces/{workspaceId}
DELETE /api/v1/organizations/{orgId}/groups/{groupId}/workspaces/{workspaceId}See the Organizations API for both, and Managing Members for the flow around them.
Workspace Settings
Get Settings
GET /api/v1/workspaces/{id}/settings
Returns workspace-level configuration settings.
Update Settings
PUT /api/v1/workspaces/{id}/settings
Updates workspace settings. Requires owner or admin role.
Workspace Object
| Field | Type | Description |
|---|---|---|
id | string (UUID) | Unique identifier |
name | string | Display name |
slug | string | URL-safe identifier |
avatar_url | string | Avatar image URL |
settings | object | Workspace-level settings |
organization_id | string (UUID) | Parent organization. Never null — every workspace belongs to one, because a group is the only thing that grants access and a group lives on an organization |
member_count | integer | Number of workspace members |
created_at | string (ISO 8601) | Creation timestamp |
updated_at | string (ISO 8601) | Last update timestamp |
Workspace Member Object
| Field | Type | Description |
|---|---|---|
workspace_id | string (UUID) | Workspace ID |
account_id | string (UUID) | Account ID |
role | string | Role name |
role_id | string (UUID) or null | Custom role ID |
email | string | Member email |
name | string | Member display name |
avatar_url | string | Member avatar URL |
created_at | string (ISO 8601) | When the member was added |