# Update an organization's settings

PUT`/v1/organizations/{org_id}/settings`[Token scope: `org:write`](https://docs.taskadence.com/guides/authentication/#scopes)

Request

**curl**


```bash
curl -X PUT "https://api.taskadence.com/v1/organizations/<org_id>/settings" \
  -H "Authorization: Bearer $TASKADENCE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"default_visibility":"public","domain_join_mode":"instant"}'
```

**Python**


```python
from taskadence import Taskadence

tm = Taskadence()  # reads TASKADENCE_TOKEN
result = tm.organizations.update_settings("<org_id>", {"default_visibility": "public", "domain_join_mode": "instant"})
print(result)
```

Response 200

```json
{
  "org_id": "string",
  "default_visibility": "public",
  "domain_join_mode": "approval",
  "audit_retention_days": 0,
  "allow_personal_tokens": true,
  "max_token_ttl_days": 0,
  "require_token_expiry": false,
  "agent_task_review": "private_projects",
  "require_mfa": "off",
  "idle_timeout_minutes": 60,
  "restrict_to_verified_domains": false,
  "deleted_item_retention_days": 30,
  "attachment_retention_days": 30,
  "mfa_not_enrolled": {
    "admins": 0,
    "all": 0
  },
  "created_at": "2026-09-25T12:00:00Z",
  "updated_at": "2026-09-25T12:00:00Z",
  "updated_by": "string",
  "is_default": false
}
```

Upsert the org’s settings. Owners and admins only; `require_mfa` owners only, and turning it on needs your session signed in with two steps.

## Authorizations

-   **[bearerAuth](https://docs.taskadence.com/reference/#bearerauth)**
-   **[TaskadenceToken](https://docs.taskadence.com/reference/#taskadencetoken)**

## Parameters

### Path Parameters

**org\_id**

required

_Org Id_

Organization ID

string

Organization ID

### Header Parameters

**If-Match**

string

The `ETag` you read; a stale one is a 412 and nothing is written.

## Request Bodyrequired

application/json

_OrganizationSettingsUpdate_

`PUT /organizations/{org_id}/settings` body. Every field optional; omitted ones keep their value.

object

**default\_visibility**

Any of:

**ProjectVisibilityEnum**
_ProjectVisibilityEnum_

Who can see a project: `public` - every member of the organization; `private` - the project’s members and org admins. Also the organization’s default for new projects.

string

Allowed values: public private

**null**


null

**domain\_join\_mode**

Any of:

**OrgJoinModeEnum**
_OrgJoinModeEnum_

What a sign-in from one of the organization’s verified domains gets: `instant` makes the person a member immediately; `approval` files a join request for an admin to decide.

string

Allowed values: instant approval

**null**


null

**audit\_retention\_days**

Any of:

**integer**


integer

\>= 1

**null**


null

**allow\_personal\_tokens**

Any of:

**boolean**


boolean

**null**


null

**max\_token\_ttl\_days**

Any of:

**integer**


integer

\>= 1 <= 3650

**null**


null

**require\_token\_expiry**

Any of:

**boolean**


boolean

**null**


null

**agent\_task\_review**

Any of:

**AgentTaskReviewEnum**
_AgentTaskReviewEnum_

Which tasks created by an agent (through the MCP server, the API or the SDK) wait for a person’s review.

-   `private_projects` (default): only a task aimed at a private project. It is created with no project, the project kept as `proposed_project_id`, until a person accepts it.
-   `always`: every agent task, where it was asked to go.
-   `never`: none (agent tasks stay marked by `created_via`).

string

Allowed values: private\_projects always never

**null**


null

**require\_mfa**

Any of:

**MfaRequirementEnum**
_MfaRequirementEnum_

Who must sign in with two-step sign-in (an authenticator app) to reach the organization’s data.

-   `off` (default): nobody is required to.
-   `admins`: owners and admins.
-   `all`: every member, guests included.

string

Allowed values: off admins all

**null**


null

**idle\_timeout\_minutes**

Any of:

**integer**


integer

Allowed values: 15 30 60 240 480

**null**


null

**restrict\_to\_verified\_domains**

Any of:

**boolean**


boolean

**null**


null

**deleted\_item\_retention\_days**

Any of:

**integer**


integer

\>= 1 <= 3650

**null**


null

**attachment\_retention\_days**

Any of:

**integer**


integer

<= 3650

**null**


null

Example

```json
{
  "default_visibility": "public",
  "domain_join_mode": "instant",
  "audit_retention_days": 1,
  "allow_personal_tokens": false,
  "max_token_ttl_days": 1,
  "require_token_expiry": false,
  "agent_task_review": "private_projects",
  "require_mfa": "off",
  "idle_timeout_minutes": 15,
  "restrict_to_verified_domains": false,
  "deleted_item_retention_days": 1,
  "attachment_retention_days": 0
}
```

## Responses

### 200

Successful Response

application/json

_OrganizationSettingsOut_

Returned by `organizations.settings` and `organizations.update_settings`.

object

**org\_id**

required

_Org Id_

string

**default\_visibility**

_ProjectVisibilityEnum_

Who can see a project: `public` - every member of the organization; `private` - the project’s members and org admins. Also the organization’s default for new projects.

string

default: public

Allowed values: public private

**domain\_join\_mode**

_OrgJoinModeEnum_

What a sign-in from one of the organization’s verified domains gets: `instant` makes the person a member immediately; `approval` files a join request for an admin to decide.

string

default: approval

Allowed values: instant approval

**audit\_retention\_days**

Any of:

**integer**


integer

**null**


null

**allow\_personal\_tokens**

_Allow Personal Tokens_

Members may mint personal access tokens.

boolean

default: true

**max\_token\_ttl\_days**

Any of:

**integer**


integer

**null**


null

**require\_token\_expiry**

_Require Token Expiry_

Every new token must carry an `expires_at`.

boolean

**agent\_task\_review**

_AgentTaskReviewEnum_

Which tasks created by an agent wait for a person’s review.

string

default: private\_projects

Allowed values: private\_projects always never

**require\_mfa**

_MfaRequirementEnum_

Who must sign in with two-step sign-in (an authenticator app) to reach the organization’s data: `off`, `admins` (owners and admins) or `all`. A session below it gets 403 `mfa-required`; access tokens are not affected.

string

default: off

Allowed values: off admins all

**idle\_timeout\_minutes**

_Idle Timeout Minutes_

S.6: the web app signs people out after this many idle minutes (15, 30, 60, 240 or 480)

integer

default: 60

**restrict\_to\_verified\_domains**

_Restrict To Verified Domains_

S.7: only people with an email at a verified domain get in by themselves (invites to other domains need an owner)

boolean

**deleted\_item\_retention\_days**

_Deleted Item Retention Days_

S.13: days a deleted task, project, goal, milestone, sprint, team or test run stays restorable before it is purged

integer

default: 30

**attachment\_retention\_days**

_Attachment Retention Days_

S.13: days a deleted attachment’s file is kept in storage before it is removed

integer

default: 30

**mfa\_not\_enrolled**

Any of:

**MfaEnrolmentCounts**
_MfaEnrolmentCounts_

Members who have not set up two-step sign-in yet, per policy value (as last seen by Taskadence).

object

**admins**

_Admins_

Owners and admins without two-step sign-in

integer

0

**all**

_All_

Members of any role without two-step sign-in

integer

0

**null**


null

**created\_at**

Any of:

**string**


string format: date-time

**null**


null

**updated\_at**

Any of:

**string**


string format: date-time

**null**


null

**updated\_by**

Any of:

**string**


string

**null**


null

**is\_default**

_Is Default_

True when the org has no settings row yet (these are the defaults)

boolean

Example

```json
{
  "org_id": "string",
  "default_visibility": "public",
  "domain_join_mode": "approval",
  "audit_retention_days": 0,
  "allow_personal_tokens": true,
  "max_token_ttl_days": 0,
  "require_token_expiry": false,
  "agent_task_review": "private_projects",
  "require_mfa": "off",
  "idle_timeout_minutes": 60,
  "restrict_to_verified_domains": false,
  "deleted_item_retention_days": 30,
  "attachment_retention_days": 30,
  "mfa_not_enrolled": {
    "admins": 0,
    "all": 0
  },
  "created_at": "2026-09-25T12:00:00Z",
  "updated_at": "2026-09-25T12:00:00Z",
  "updated_by": "string",
  "is_default": false
}
```

### 400

Bad request - a query parameter outside what the operation accepts (`invalid-parameter`)

application/problem+json

_Problem_

An RFC 9457 problem details object - the body of every error response. `detail` is the human-readable explanation; `request_id` identifies the request for support.

object

**type**

required

`about:blank` or a `urn:taskadence:problem:*` identifier

string

Allowed values: about:blank urn:taskadence:problem:validation urn:taskadence:problem:invalid-parameter urn:taskadence:problem:precondition-failed urn:taskadence:problem:idempotency-key-reused urn:taskadence:problem:idempotency-key-in-flight urn:taskadence:problem:idempotency-key-invalid urn:taskadence:problem:rate-limit urn:taskadence:problem:internal urn:taskadence:problem:token-invalid urn:taskadence:problem:token-expired urn:taskadence:problem:token-revoked urn:taskadence:problem:insufficient-scope urn:taskadence:problem:test-token-read-only urn:taskadence:problem:token-policy urn:taskadence:problem:url-refused urn:taskadence:problem:mfa-required urn:taskadence:problem:email-unverified urn:taskadence:problem:upload-too-large urn:taskadence:problem:upload-type-not-allowed urn:taskadence:problem:upload-type-mismatch urn:taskadence:problem:upload-rejected

**title**

required

string

**status**

required

integer

**detail**

required

Human-readable explanation (a string; for a 422, the list of validation errors)

**instance**

required

string

**request\_id**

required

string

**errors**

Structured failures: validation errors, or `{loc, msg, allowed}` for a bad parameter

Array<object>

object

**mfa**

On an `mfa-required` problem only: `enrolled` (does the person have an authenticator app set up), `required_for` (`all` or `admins`) and `reason` (`org_policy`: the organization’s requirement; `step_up`: this action needs a second step)

object

**enrolled**

boolean

**required\_for**

string

Allowed values: all admins

**reason**

string

Allowed values: org\_policy step\_up

Example

```json
{
  "type": "about:blank",
  "title": "Bad request",
  "status": 400,
  "detail": "…",
  "instance": "/v1/…",
  "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"
}
```

### 401

Missing or invalid bearer token

application/problem+json

_Problem_

An RFC 9457 problem details object - the body of every error response. `detail` is the human-readable explanation; `request_id` identifies the request for support.

object

**type**

required

`about:blank` or a `urn:taskadence:problem:*` identifier

string

Allowed values: about:blank urn:taskadence:problem:validation urn:taskadence:problem:invalid-parameter urn:taskadence:problem:precondition-failed urn:taskadence:problem:idempotency-key-reused urn:taskadence:problem:idempotency-key-in-flight urn:taskadence:problem:idempotency-key-invalid urn:taskadence:problem:rate-limit urn:taskadence:problem:internal urn:taskadence:problem:token-invalid urn:taskadence:problem:token-expired urn:taskadence:problem:token-revoked urn:taskadence:problem:insufficient-scope urn:taskadence:problem:test-token-read-only urn:taskadence:problem:token-policy urn:taskadence:problem:url-refused urn:taskadence:problem:mfa-required urn:taskadence:problem:email-unverified urn:taskadence:problem:upload-too-large urn:taskadence:problem:upload-type-not-allowed urn:taskadence:problem:upload-type-mismatch urn:taskadence:problem:upload-rejected

**title**

required

string

**status**

required

integer

**detail**

required

Human-readable explanation (a string; for a 422, the list of validation errors)

**instance**

required

string

**request\_id**

required

string

**errors**

Structured failures: validation errors, or `{loc, msg, allowed}` for a bad parameter

Array<object>

object

**mfa**

On an `mfa-required` problem only: `enrolled` (does the person have an authenticator app set up), `required_for` (`all` or `admins`) and `reason` (`org_policy`: the organization’s requirement; `step_up`: this action needs a second step)

object

**enrolled**

boolean

**required\_for**

string

Allowed values: all admins

**reason**

string

Allowed values: org\_policy step\_up

Example

```json
{
  "type": "about:blank",
  "title": "Missing or invalid bearer token",
  "status": 401,
  "detail": "…",
  "instance": "/v1/…",
  "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"
}
```

### 403

Authenticated, but not allowed

application/problem+json

_Problem_

An RFC 9457 problem details object - the body of every error response. `detail` is the human-readable explanation; `request_id` identifies the request for support.

object

**type**

required

`about:blank` or a `urn:taskadence:problem:*` identifier

string

Allowed values: about:blank urn:taskadence:problem:validation urn:taskadence:problem:invalid-parameter urn:taskadence:problem:precondition-failed urn:taskadence:problem:idempotency-key-reused urn:taskadence:problem:idempotency-key-in-flight urn:taskadence:problem:idempotency-key-invalid urn:taskadence:problem:rate-limit urn:taskadence:problem:internal urn:taskadence:problem:token-invalid urn:taskadence:problem:token-expired urn:taskadence:problem:token-revoked urn:taskadence:problem:insufficient-scope urn:taskadence:problem:test-token-read-only urn:taskadence:problem:token-policy urn:taskadence:problem:url-refused urn:taskadence:problem:mfa-required urn:taskadence:problem:email-unverified urn:taskadence:problem:upload-too-large urn:taskadence:problem:upload-type-not-allowed urn:taskadence:problem:upload-type-mismatch urn:taskadence:problem:upload-rejected

**title**

required

string

**status**

required

integer

**detail**

required

Human-readable explanation (a string; for a 422, the list of validation errors)

**instance**

required

string

**request\_id**

required

string

**errors**

Structured failures: validation errors, or `{loc, msg, allowed}` for a bad parameter

Array<object>

object

**mfa**

On an `mfa-required` problem only: `enrolled` (does the person have an authenticator app set up), `required_for` (`all` or `admins`) and `reason` (`org_policy`: the organization’s requirement; `step_up`: this action needs a second step)

object

**enrolled**

boolean

**required\_for**

string

Allowed values: all admins

**reason**

string

Allowed values: org\_policy step\_up

Example

```json
{
  "type": "about:blank",
  "title": "Authenticated, but not allowed",
  "status": 403,
  "detail": "…",
  "instance": "/v1/…",
  "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"
}
```

### 404

Not found

application/problem+json

_Problem_

An RFC 9457 problem details object - the body of every error response. `detail` is the human-readable explanation; `request_id` identifies the request for support.

object

**type**

required

`about:blank` or a `urn:taskadence:problem:*` identifier

string

Allowed values: about:blank urn:taskadence:problem:validation urn:taskadence:problem:invalid-parameter urn:taskadence:problem:precondition-failed urn:taskadence:problem:idempotency-key-reused urn:taskadence:problem:idempotency-key-in-flight urn:taskadence:problem:idempotency-key-invalid urn:taskadence:problem:rate-limit urn:taskadence:problem:internal urn:taskadence:problem:token-invalid urn:taskadence:problem:token-expired urn:taskadence:problem:token-revoked urn:taskadence:problem:insufficient-scope urn:taskadence:problem:test-token-read-only urn:taskadence:problem:token-policy urn:taskadence:problem:url-refused urn:taskadence:problem:mfa-required urn:taskadence:problem:email-unverified urn:taskadence:problem:upload-too-large urn:taskadence:problem:upload-type-not-allowed urn:taskadence:problem:upload-type-mismatch urn:taskadence:problem:upload-rejected

**title**

required

string

**status**

required

integer

**detail**

required

Human-readable explanation (a string; for a 422, the list of validation errors)

**instance**

required

string

**request\_id**

required

string

**errors**

Structured failures: validation errors, or `{loc, msg, allowed}` for a bad parameter

Array<object>

object

**mfa**

On an `mfa-required` problem only: `enrolled` (does the person have an authenticator app set up), `required_for` (`all` or `admins`) and `reason` (`org_policy`: the organization’s requirement; `step_up`: this action needs a second step)

object

**enrolled**

boolean

**required\_for**

string

Allowed values: all admins

**reason**

string

Allowed values: org\_policy step\_up

Example

```json
{
  "type": "about:blank",
  "title": "Not found",
  "status": 404,
  "detail": "…",
  "instance": "/v1/…",
  "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"
}
```

### 409

Conflict (a duplicate, or an `Idempotency-Key` still in flight)

application/problem+json

_Problem_

An RFC 9457 problem details object - the body of every error response. `detail` is the human-readable explanation; `request_id` identifies the request for support.

object

**type**

required

`about:blank` or a `urn:taskadence:problem:*` identifier

string

Allowed values: about:blank urn:taskadence:problem:validation urn:taskadence:problem:invalid-parameter urn:taskadence:problem:precondition-failed urn:taskadence:problem:idempotency-key-reused urn:taskadence:problem:idempotency-key-in-flight urn:taskadence:problem:idempotency-key-invalid urn:taskadence:problem:rate-limit urn:taskadence:problem:internal urn:taskadence:problem:token-invalid urn:taskadence:problem:token-expired urn:taskadence:problem:token-revoked urn:taskadence:problem:insufficient-scope urn:taskadence:problem:test-token-read-only urn:taskadence:problem:token-policy urn:taskadence:problem:url-refused urn:taskadence:problem:mfa-required urn:taskadence:problem:email-unverified urn:taskadence:problem:upload-too-large urn:taskadence:problem:upload-type-not-allowed urn:taskadence:problem:upload-type-mismatch urn:taskadence:problem:upload-rejected

**title**

required

string

**status**

required

integer

**detail**

required

Human-readable explanation (a string; for a 422, the list of validation errors)

**instance**

required

string

**request\_id**

required

string

**errors**

Structured failures: validation errors, or `{loc, msg, allowed}` for a bad parameter

Array<object>

object

**mfa**

On an `mfa-required` problem only: `enrolled` (does the person have an authenticator app set up), `required_for` (`all` or `admins`) and `reason` (`org_policy`: the organization’s requirement; `step_up`: this action needs a second step)

object

**enrolled**

boolean

**required\_for**

string

Allowed values: all admins

**reason**

string

Allowed values: org\_policy step\_up

Example

```json
{
  "type": "about:blank",
  "title": "Conflict (a duplicate, or an `Idempotency-Key` still in flight)",
  "status": 409,
  "detail": "…",
  "instance": "/v1/…",
  "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"
}
```

### 412

`If-Match` does not match the current `ETag`

application/problem+json

_Problem_

An RFC 9457 problem details object - the body of every error response. `detail` is the human-readable explanation; `request_id` identifies the request for support.

object

**type**

required

`about:blank` or a `urn:taskadence:problem:*` identifier

string

Allowed values: about:blank urn:taskadence:problem:validation urn:taskadence:problem:invalid-parameter urn:taskadence:problem:precondition-failed urn:taskadence:problem:idempotency-key-reused urn:taskadence:problem:idempotency-key-in-flight urn:taskadence:problem:idempotency-key-invalid urn:taskadence:problem:rate-limit urn:taskadence:problem:internal urn:taskadence:problem:token-invalid urn:taskadence:problem:token-expired urn:taskadence:problem:token-revoked urn:taskadence:problem:insufficient-scope urn:taskadence:problem:test-token-read-only urn:taskadence:problem:token-policy urn:taskadence:problem:url-refused urn:taskadence:problem:mfa-required urn:taskadence:problem:email-unverified urn:taskadence:problem:upload-too-large urn:taskadence:problem:upload-type-not-allowed urn:taskadence:problem:upload-type-mismatch urn:taskadence:problem:upload-rejected

**title**

required

string

**status**

required

integer

**detail**

required

Human-readable explanation (a string; for a 422, the list of validation errors)

**instance**

required

string

**request\_id**

required

string

**errors**

Structured failures: validation errors, or `{loc, msg, allowed}` for a bad parameter

Array<object>

object

**mfa**

On an `mfa-required` problem only: `enrolled` (does the person have an authenticator app set up), `required_for` (`all` or `admins`) and `reason` (`org_policy`: the organization’s requirement; `step_up`: this action needs a second step)

object

**enrolled**

boolean

**required\_for**

string

Allowed values: all admins

**reason**

string

Allowed values: org\_policy step\_up

Example

```json
{
  "type": "about:blank",
  "title": "`If-Match` does not match the current `ETag`",
  "status": 412,
  "detail": "…",
  "instance": "/v1/…",
  "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"
}
```

### 422

The body or query did not validate (`validation`), or an `Idempotency-Key` was reused

application/problem+json

_Problem_

An RFC 9457 problem details object - the body of every error response. `detail` is the human-readable explanation; `request_id` identifies the request for support.

object

**type**

required

`about:blank` or a `urn:taskadence:problem:*` identifier

string

Allowed values: about:blank urn:taskadence:problem:validation urn:taskadence:problem:invalid-parameter urn:taskadence:problem:precondition-failed urn:taskadence:problem:idempotency-key-reused urn:taskadence:problem:idempotency-key-in-flight urn:taskadence:problem:idempotency-key-invalid urn:taskadence:problem:rate-limit urn:taskadence:problem:internal urn:taskadence:problem:token-invalid urn:taskadence:problem:token-expired urn:taskadence:problem:token-revoked urn:taskadence:problem:insufficient-scope urn:taskadence:problem:test-token-read-only urn:taskadence:problem:token-policy urn:taskadence:problem:url-refused urn:taskadence:problem:mfa-required urn:taskadence:problem:email-unverified urn:taskadence:problem:upload-too-large urn:taskadence:problem:upload-type-not-allowed urn:taskadence:problem:upload-type-mismatch urn:taskadence:problem:upload-rejected

**title**

required

string

**status**

required

integer

**detail**

required

Human-readable explanation (a string; for a 422, the list of validation errors)

**instance**

required

string

**request\_id**

required

string

**errors**

Structured failures: validation errors, or `{loc, msg, allowed}` for a bad parameter

Array<object>

object

**mfa**

On an `mfa-required` problem only: `enrolled` (does the person have an authenticator app set up), `required_for` (`all` or `admins`) and `reason` (`org_policy`: the organization’s requirement; `step_up`: this action needs a second step)

object

**enrolled**

boolean

**required\_for**

string

Allowed values: all admins

**reason**

string

Allowed values: org\_policy step\_up

Example

```json
{
  "type": "about:blank",
  "title": "The body or query did not validate (`validation`), or an `Idempotency-Key` was reused",
  "status": 422,
  "detail": "…",
  "instance": "/v1/…",
  "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"
}
```

### 429

An access token, or a signed-in user, or an address over its limit (`rate-limit`; see `Retry-After`)

application/problem+json

_Problem_

An RFC 9457 problem details object - the body of every error response. `detail` is the human-readable explanation; `request_id` identifies the request for support.

object

**type**

required

`about:blank` or a `urn:taskadence:problem:*` identifier

string

Allowed values: about:blank urn:taskadence:problem:validation urn:taskadence:problem:invalid-parameter urn:taskadence:problem:precondition-failed urn:taskadence:problem:idempotency-key-reused urn:taskadence:problem:idempotency-key-in-flight urn:taskadence:problem:idempotency-key-invalid urn:taskadence:problem:rate-limit urn:taskadence:problem:internal urn:taskadence:problem:token-invalid urn:taskadence:problem:token-expired urn:taskadence:problem:token-revoked urn:taskadence:problem:insufficient-scope urn:taskadence:problem:test-token-read-only urn:taskadence:problem:token-policy urn:taskadence:problem:url-refused urn:taskadence:problem:mfa-required urn:taskadence:problem:email-unverified urn:taskadence:problem:upload-too-large urn:taskadence:problem:upload-type-not-allowed urn:taskadence:problem:upload-type-mismatch urn:taskadence:problem:upload-rejected

**title**

required

string

**status**

required

integer

**detail**

required

Human-readable explanation (a string; for a 422, the list of validation errors)

**instance**

required

string

**request\_id**

required

string

**errors**

Structured failures: validation errors, or `{loc, msg, allowed}` for a bad parameter

Array<object>

object

**mfa**

On an `mfa-required` problem only: `enrolled` (does the person have an authenticator app set up), `required_for` (`all` or `admins`) and `reason` (`org_policy`: the organization’s requirement; `step_up`: this action needs a second step)

object

**enrolled**

boolean

**required\_for**

string

Allowed values: all admins

**reason**

string

Allowed values: org\_policy step\_up

Example

```json
{
  "type": "about:blank",
  "title": "An access token, or a signed-in user, or an address over its limit (`rate-limit`; see `Retry-After`)",
  "status": 429,
  "detail": "…",
  "instance": "/v1/…",
  "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"
}
```

### 500

Unexpected server error - quote `request_id`

application/problem+json

_Problem_

An RFC 9457 problem details object - the body of every error response. `detail` is the human-readable explanation; `request_id` identifies the request for support.

object

**type**

required

`about:blank` or a `urn:taskadence:problem:*` identifier

string

Allowed values: about:blank urn:taskadence:problem:validation urn:taskadence:problem:invalid-parameter urn:taskadence:problem:precondition-failed urn:taskadence:problem:idempotency-key-reused urn:taskadence:problem:idempotency-key-in-flight urn:taskadence:problem:idempotency-key-invalid urn:taskadence:problem:rate-limit urn:taskadence:problem:internal urn:taskadence:problem:token-invalid urn:taskadence:problem:token-expired urn:taskadence:problem:token-revoked urn:taskadence:problem:insufficient-scope urn:taskadence:problem:test-token-read-only urn:taskadence:problem:token-policy urn:taskadence:problem:url-refused urn:taskadence:problem:mfa-required urn:taskadence:problem:email-unverified urn:taskadence:problem:upload-too-large urn:taskadence:problem:upload-type-not-allowed urn:taskadence:problem:upload-type-mismatch urn:taskadence:problem:upload-rejected

**title**

required

string

**status**

required

integer

**detail**

required

Human-readable explanation (a string; for a 422, the list of validation errors)

**instance**

required

string

**request\_id**

required

string

**errors**

Structured failures: validation errors, or `{loc, msg, allowed}` for a bad parameter

Array<object>

object

**mfa**

On an `mfa-required` problem only: `enrolled` (does the person have an authenticator app set up), `required_for` (`all` or `admins`) and `reason` (`org_policy`: the organization’s requirement; `step_up`: this action needs a second step)

object

**enrolled**

boolean

**required\_for**

string

Allowed values: all admins

**reason**

string

Allowed values: org\_policy step\_up

Example

```json
{
  "type": "about:blank",
  "title": "Unexpected server error",
  "status": 500,
  "detail": "…",
  "instance": "/v1/…",
  "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11"
}
```

---
Source: https://docs.taskadence.com/reference/operations/organizationsupdate_settings/
