Find the IDs you need
Most admin mutations take an organization ID, a space ID, or a user ID. Start fromaccount to walk down to organizations and their spaces, and from node once you already hold a global ID. See using global node IDs for how these IDs are encoded.
account.users(search: "<email>").
List the spaces in an organization and their members
Before assigning or removing membership, pull the current member list for a space (or the full organization roster) so you know which user IDs and roles you are working with.Space.spaceUsers returns every user with access to the space, including account and organization admins who were never explicitly added, not only direct members. For users with custom RBAC roles, role on SpaceUser is null; check customRole instead.
Create a space in an organization
Spaces are created inside an organization, so you need the organization’s ID first (see above).createSpace. To rename a space, change its description, or flip mlModelsEnabled, use updateSpace with the same spaceId. To delete one, use deleteSpace, which takes the space’s uuid, not its global id.
Bulk-assign users to spaces with roles
assignSpaceMembership takes a list, so you can onboard a whole team across multiple spaces in one call. Each entry needs either a legacy role or a customRoleId, never both.
assignSpaceMembership. Legacy role accepts admin, member, readOnly or annotator. Custom RBAC role IDs (for customRoleId) aren’t queryable through this API; copy them from Settings > Roles in the Arize UI.
Scripting this in bulk is a common CI task, for example syncing space access from an HR system:
Remove a member from a space
removeSpaceMember. This removes direct space membership only; a user who still has access through an organization or account admin role keeps access to the space.
Create a service API key for CI
Service keys back a dedicated bot user rather than a human, which is what you want for pipelines. Grant access either to a single space (legacy path) or to multiple organizations and spaces at once withorganizations; the two approaches are mutually exclusive.
createServiceApiKey. The response’s apiKey field is the only time the raw key is returned; store it immediately. For a personal key instead of a bot-backed one, use createUserApiKey, which only takes a name, optional description and expiresAt, and a type of user or service.
Revoke an API key
revokeApiKey. status only ever returns ok on success; a failed revocation (for example, an already-revoked or unknown key) comes back as a GraphQL error rather than a different status value. Find the key ID to revoke on viewer.apiKeys for your own keys, or from the keyInfo.id returned when the key was created.
Configure a SAML identity provider and add a role mapping
Create the IdP with its email domains and metadata, then add role mappings one at a time so you don’t have to resend the entire configuration for each change.createSAMLIdP and addSAMLRoleMapping. addSAMLRoleMapping rejects a mapping whose SAML attributes and organization already match an existing one. To change the metadata, default roles or other top-level settings afterward, use updateSAMLIdP, which replaces the full configuration, so include every roleMappings entry you want to keep, not just the ones you’re changing. spaceRolesMap (legacy roles) and spaceRbacRolesMap (custom RBAC role IDs) are mutually exclusive on the same mapping, and custom role IDs have to come from the Arize UI since there’s no query that lists them.
Set or clear a space ingestion gate
Ingestion gates cap how much data a space can take in perTierGate category. Setting a gate to 0 blocks all ingestion for that category; clearing it removes the limit entirely.
setSpaceGateLimit and deleteSpaceGateLimit. gateType is one of workspaces, organizations, prodPredictions, preProdPredictions, activeModels, features or dataSize; dataSize is measured in bytes. See Space rate limiting for what each gate controls.
Gotchas and behavior notes
Mutually exclusive inputs, checked at runtime, not by the type system
Mutually exclusive inputs, checked at runtime, not by the type system
SpaceMemberInput requires either role or customRoleId, never both. CreateServiceApiKeyInput requires either the legacy spaceId/spaceRole/spaceRoleId/accountOrganizationRole path or organizations, never both, and within each space assignment, spaceRole and spaceRoleId are themselves mutually exclusive. A RoleMappingInput can set spaceRolesMap or spaceRbacRolesMap, but not both. None of this is enforced by the schema’s nullability; sending both fields returns a runtime error.deleteSpace takes a uuid, not the global id
deleteSpace takes a uuid, not the global id
Every other space mutation takes
spaceId (the global ID!). deleteSpace instead takes spaceUuid, the Space.uuid scalar field. Query uuid separately before calling it.There is no deleteSAMLIdP mutation
There is no deleteSAMLIdP mutation
The admin mutations are limited to
createSAMLIdP, updateSAMLIdP and addSAMLRoleMapping; there’s no mutation to delete a SAML configuration. CreateSAMLIdPInput accepts a status of "active" or "deleted" at creation time, but UpdateSAMLIdPInput has no status field, so an existing config can’t be soft-deleted through the API either.updateSAMLIdP replaces the whole configuration
updateSAMLIdP replaces the whole configuration
Treat every call as a full replacement. Fields you omit may reset rather than stay untouched, and that applies to
roleMappings.mappingsList too: resend every mapping you want to keep alongside any changes.No query lists custom RBAC roles
No query lists custom RBAC roles
The schema has no
roles field on Account and no connection type for roles; Role doesn’t implement Node either, so you can’t fetch one by ID through node. Get custom role IDs for customRoleId, spaceRoleId or spaceRbacRolesMap from Settings > Roles in the Arize UI.developerAccessDefault is deprecated
developerAccessDefault is deprecated
Account.developerAccessDefault always returns true now; developer access comes from the user’s assigned account role. Use Account.developerAccessLocked to disable developer access account-wide instead.Admin mutations reference
Full arguments, return types and minimal examples for every admin mutation.
All mutations
Browse mutations for every other domain: monitors, datasets, prompts and more.
API explorer
Run queries and mutations interactively against your own space.