> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Set own default tenant

> Makes `tenantId` your default tenant: your next sign-in goes there. Setting the tenant that is already your default succeeds again.

`tenantId` must be one of the tenants `GET /v1/users/{id}/tenants` lists. Any other value is refused with the same `403 IDE-0057` as another user's `{id}`, which does not say why.

Any authenticated member may call this for THEMSELVES; an `{id}` other than your token's subject is refused with `403 IDE-0057`.

On success the response has no body (204).

Failures:
- `400` — `{id}` is not a UUID, or `tenantId` is missing or empty.
- `401` — no bearer token.
- `403 IDE-0057` — `{id}` is not you, or you have no active account in that tenant.
- `404` — no such user.
- `503 IDE-0060` — the identity provider is unavailable (unreachable, too slow to answer, or failing). Nothing about the request was wrong; retry it later.



## OpenAPI

````yaml /pt/openapi/v3-current/AM-identity.yaml put /v1/users/{id}/tenants/default
openapi: 3.1.0
info:
  contact:
    name: Lerian Studio
    url: https://lerian.studio
  description: >-
    OpenAPI 3.1 surface for the plugin-access-manager identity component. It
    exposes the M2M-gated declarations upsert (PUT /v1/declarations/{slug}),
    through which each plugin declares its own permissions/roles/M2M contract,
    and partner management (/v1/partners), through which a tenant administrator
    grants its own customers scoped API credentials. The remaining identity
    routes stay Fiber-native and are described by the separate OAS 2 document in
    the same folder.
  license:
    name: Apache-2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Plugin Access Manager — Identity API
  version: v1
servers: []
security: []
tags:
  - description: >-
      M2M-only: each plugin declares its own permissions, roles and M2M
      contract, and the server reconciles them.
    name: Declarations
  - description: >-
      A tenant administrator's customers. Each partner holds what its
      credentials may DO (permissions, per product) and WHERE they may do it
      (scope, per product and dimension); an M2M application attached to one is
      confined to that intersection. Administrator-only: authorized on the
      "partners" resource, and every route resolves the owning organization from
      the caller's token.
    name: Partners
paths:
  /v1/users/{id}/tenants/default:
    put:
      tags:
        - Users
      summary: Set own default tenant
      description: >-
        Makes `tenantId` your default tenant: your next sign-in goes there.
        Setting the tenant that is already your default succeeds again.


        `tenantId` must be one of the tenants `GET /v1/users/{id}/tenants`
        lists. Any other value is refused with the same `403 IDE-0057` as
        another user's `{id}`, which does not say why.


        Any authenticated member may call this for THEMSELVES; an `{id}` other
        than your token's subject is refused with `403 IDE-0057`.


        On success the response has no body (204).


        Failures:

        - `400` — `{id}` is not a UUID, or `tenantId` is missing or empty.

        - `401` — no bearer token.

        - `403 IDE-0057` — `{id}` is not you, or you have no active account in
        that tenant.

        - `404` — no such user.

        - `503 IDE-0060` — the identity provider is unavailable (unreachable,
        too slow to answer, or failing). Nothing about the request was wrong;
        retry it later.
      operationId: setOwnDefaultTenant
      parameters:
        - description: Caller's own User ID.
          in: path
          name: id
          required: true
          schema:
            description: Caller's own User ID.
            examples:
              - 00000000-0000-0000-0000-000000000000
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DefaultTenantInput'
              description: The tenant that becomes the default.
        required: true
      responses:
        '204':
          description: No Content
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPError'
          description: Bad Request
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPError'
          description: Unauthorized
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPError'
          description: Forbidden
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPError'
          description: Not Found
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unprocessable Entity
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPError'
          description: Internal Server Error
        '503':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPError'
          description: Service Unavailable
      security:
        - BearerAuth: []
components:
  schemas:
    DefaultTenantInput:
      additionalProperties: false
      properties:
        tenantId:
          examples:
            - acme-b
          type: string
      required:
        - tenantId
      type: object
    HTTPError:
      additionalProperties: false
      properties:
        code:
          type: string
        entityType:
          type: string
        err: {}
        message:
          type: string
        title:
          type: string
      type: object
    Detail:
      additionalProperties: true
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.