update-user-geographic-access-scope
dci update-user-geographic-access-scope [body]
Atomically replaces the geographic scope assigned to a user who belongs to the target customer. The authenticated tenant must be the hierarchy root, and the target must be that root customer or one of its child customers. Repeating an identical request is idempotent. Requires the UsersManager permission.
Pass the request body as name: value arguments or pipe JSON on stdin — see Command structure.
The body is exactly one of type: global, type: country with countryCode,
or type: customRegion with customRegionId; the request replaces the
previous scope atomically. To leave the user unassigned, use
dci delete-user-geographic-access-scope instead.
Examples
# Limit a user to one country (ISO 3166-1 alpha-2 code from `dci list-geographic-access-countries`).
dci update-user-geographic-access-scope <target-customer-id> <user-id> type: country, countryCode: DE
# Limit the user to a custom region (ID from `dci list-geographic-access-custom-regions`).
dci update-user-geographic-access-scope <target-customer-id> <user-id> type: customRegion, customRegionId: cr_01J6M8Q9H3Y7T2K5V4N1P0X8ZA
# Allow the user every country and custom region.
dci update-user-geographic-access-scope <target-customer-id> <user-id> type: global
The updated scope is returned; `type` tells you which shape applied.
Request
Content-Type: application/json
Raw JSON schema
{
"oneOf": [
{
"type": "object",
"additionalProperties": false,
"required": [
"type"
],
"properties": {
"type": {
"type": "string",
"enum": [
"global"
],
"description": "All countries and custom regions are allowed."
}
}
},
{
"type": "object",
"additionalProperties": false,
"required": [
"type",
"countryCode"
],
"properties": {
"type": {
"type": "string",
"enum": [
"country"
],
"description": "Access is limited to one canonical country."
},
"countryCode": {
"type": "string",
"pattern": "^[A-Z]{2}$",
"description": "ISO 3166-1 alpha-2 country code, canonicalized by the service."
}
}
},
{
"type": "object",
"additionalProperties": false,
"required": [
"type",
"customRegionId"
],
"properties": {
"type": {
"type": "string",
"enum": [
"customRegion"
],
"description": "Access is limited to one tenant-owned custom region."
},
"customRegionId": {
"type": "string",
"minLength": 1,
"maxLength": 200,
"description": "Ready custom region owned by the authenticated tenant."
}
}
}
],
"discriminator": {
"propertyName": "type"
}
}
Output
Updated
By default dci renders the result as a table. Use --output json to get the full structure described below — see Output formats.
Returns: one of 4 variants
Example response (--output json)
{
"type": "country",
"countryCode": "DE",
"countryName": "Germany"
}
Raw JSON schema
{
"oneOf": [
{
"type": "object",
"additionalProperties": false,
"required": [
"type"
],
"properties": {
"type": {
"type": "string",
"enum": [
"unassigned"
],
"description": "No geographic scope is assigned."
}
}
},
{
"type": "object",
"additionalProperties": false,
"required": [
"type"
],
"properties": {
"type": {
"type": "string",
"enum": [
"global"
],
"description": "All countries and custom regions are allowed."
}
}
},
{
"type": "object",
"additionalProperties": false,
"required": [
"type",
"countryCode",
"countryName"
],
"properties": {
"type": {
"type": "string",
"enum": [
"country"
],
"description": "Access is limited to one canonical country."
},
"countryCode": {
"type": "string",
"pattern": "^[A-Z]{2}$",
"description": "Canonical ISO 3166-1 alpha-2 country code."
},
"countryName": {
"type": "string",
"description": "Canonical English country name."
}
}
},
{
"type": "object",
"additionalProperties": false,
"required": [
"type",
"customRegionId"
],
"properties": {
"type": {
"type": "string",
"enum": [
"customRegion"
],
"description": "Access is limited to one tenant-owned custom region."
},
"customRegionId": {
"type": "string",
"minLength": 1,
"maxLength": 200,
"description": "Ready custom region owned by the authenticated tenant."
}
}
}
],
"discriminator": {
"propertyName": "type"
}
}
Errors
On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.
HTTP status to exit code mapping
| HTTP status | Exit code | Error code | Meaning |
|---|---|---|---|
| 400 | 30 | VALIDATION_ERROR | The arguments or request body were rejected. Review the command's flags and payload. |
| 401 | 10 | AUTHENTICATION_FAILED | Not signed in, or the API token is invalid. Run dci login or check DCI_API_KEY. |
| 403 | 11 | PERMISSION_DENIED | The DoiT user or the active customer context does not have access. |
| 404 | 20 | RESOURCE_NOT_FOUND | The requested resource does not exist. Check the identifier argument. |
| 409 | 21 | RESOURCE_CONFLICT | The operation conflicts with the resource's current state. |
| 429 | 50 | RATE_LIMITED | Too many requests. Retryable — the CLI reports the server-provided delay. |
| 500, 503 | 40 | API_SERVER_ERROR | The API failed to process the request. Retryable; contact DoiT support if it persists. |
Related
- get-user-geographic-access-scope — Get a user's geographic scope
- delete-user-geographic-access-scope — Clear a user's geographic scope
- update-customer-geographic-access-scope — Replace a customer's geographic scope
- list-geographic-access-countries — List countries available for geographic access
- list-geographic-access-custom-regions — List custom regions
- API reference: PUT /rbac/v1/customers/{targetCustomerId}/users/{userId}/geographic-scope
Aliases: updateusergeographicaccessscope