Create a Stakeholder on an Account

Creates a Stakeholder record. One Stakeholder per (subjectType, subjectId, accountId) triple — duplicates return 409 ResourceConflict. For Account-typed members, roleId, roleIds and scopes must be null (Account-to-Account access flows through parentAccountId hierarchy and Organization policy controls). An Active Person without acceptance returns 409 with users.StakeholderAcceptanceRequired; create the teammate entry by email, invite it, and ask the Person to accept from their own session.

If externalId is supplied and already used by another resource of this type for the owning Account, the request returns 409 ResourceConflict; create is not an upsert. Use filter[externalId][eq] on the list endpoint to retrieve the existing resource.
isPrincipal=true, unresolved natural-human Stakeholders (subjectId omitted), email-only Stakeholders, and subject-bearing accountSuppliedComplianceEntityId attachment are backed by the users service. Because Stakeholder ids are normally server-assigned, external clients usually create the Stakeholder first, create the subject ComplianceEntity with the returned id, then PATCH this field.

Requires a session with recent MFA step-up for StakeholderChange. If step-up is missing or expired, this operation returns 403 StepUpMfaRequired; create and verify an MFA challenge at /v3/platform/mfa-challenges with requiredFor: "StakeholderChange", then retry.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Account identifier. Newly created V3 Accounts use a 22-character Wingspan ID; migrated Accounts may retain a 24-character lowercase Mongo ObjectId.

Query Params
page
object

Pagination query parameters. Serializes as page[size] and page[token].

Body Params
string
enum
required

The subject entity type: Person for a natural human or Account for an entity owner. Principal authority is represented separately by isPrincipal on a Person subject. A Person subject may remain unresolved until invited, or remain no-login. Account subjects provide ownership only; Account access uses the Account hierarchy.

Allowed:
string
required
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Existing member Person or Account. Required when subjectType=Account. Optional when subjectType=Person; omit to create an unresolved natural-human Stakeholder that may resolve or create a Person when invited, or remain no-login for platform-managed flows.

string
boolean

Whether this Person subject is the Account principal; managed through principal transfer after creation.

string

Email for an unresolved Principal or Person Stakeholder and default destination for inviteStakeholder. Natural-human only; rejected for subjectType=Account.

string

Subject-bearing ComplianceEntity that stages the member's identity before the human confirms. The CE must already be Account-owned, current, Individual, and subject-bound to the Stakeholder id. Because ids are normally server-assigned, external clients usually create the Stakeholder first, create the subject CE with the returned id, then PATCH this field. Natural-human only. Omit and the member supplies their own identity via inviteToken submission.

string
^(role_[a-zA-Z0-9_-]+|[A-Z][a-z0-9]+(?:[A-Z][a-z0-9]+)*)$

Assigns one Role. Send roleId or roleIds, not both. Use AuthorizationCreate for explicit access beyond the roles.

roleIds
array of strings
length ≥ 1

Assigns one or more Roles. The member gets everything any of them allows. Send roleId or roleIds, not both.

roleIds
roleFilters
object

Optional ABAC predicates on one Stakeholder Role assignment. Role definitions are never filtered. Filter dimensions remain disabled until every affected path has an approved fail-closed consumer.

scopes
array of strings
deprecated

Deprecated. Use AuthorizationCreate for access beyond roleId.

scopes
float
0 to 100
boolean

Substantial-control flag for natural-human stakeholders. Optional for isPrincipal=true; the server treats Principal as controller / authorized representative by default and rejects an explicit false value.

string
enum
Allowed:
controlNatures
array of strings, unique
string
string
metadata
object

Free-form key-value pairs. Max 50 keys; key length at most 40 characters; value length at most 500 characters. Where a list endpoint declares metadata filtering, it uses the QueryQL namespace via filter[metadata.{key}][eq]=value or filter[metadata.{key}][in][]=value. Endpoints that do not declare the dynamic Metadata filter do not support Metadata filtering.

Headers
string
length between 1 and 255
^[\x21-\x7e]{1,255}$

Optional idempotency token for authenticated POST and PATCH requests. Reusing the same key and body returns the cached response for 24 hours, except credential operations that explicitly document a 409 because one-time secret material is never cached; reusing it with a different body returns 409 IdempotencyKeyConflict. Use 1-255 printable ASCII characters.

string
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Select the Account for an Account-scoped operation. A direct ServiceAccount API key MUST supply this header, and the target must be within the ServiceAccount owner's or Authorization grant's Account boundary. A Person bearer may select an Account on which it has an active Stakeholder, and an Account session may select its bound Account (or a descendant only when the session explicitly includes descendants).

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json