OUTCOME · Revise and reconcile
What changes
Updates only the allowlisted workspace preferences fields and version accepted by the authoritative owner; it grants no adjacent authority.
v2Identity sessions and federation
/api/v2/me/workspaces/{workspace_uuid}/preferencesPURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Call this when an identity, compliance, relying-party, or trust agent workflow needs to apply the documented workspace preferences transition after re-reading the current authoritative state so it can make a purpose-limited identity or assurance decision with current policy and lifecycle state.
OUTCOME · Revise and reconcile
Updates only the allowlisted workspace preferences fields and version accepted by the authoritative owner; it grants no adjacent authority.
WHY IT MATTERS
ISOLATION + AUTHORITY
Bearer subject, tenant, purpose, policy version, role, issuer, reviewer, provider, and relying-party boundaries remain distinct. The response or transition grants no payment, custody, settlement, publisher, matching, or trading authority and must not expose regulated evidence beyond the live schema.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
The exact deployed parameters, schemas, responses, security requirements, and Hybrid-Chain agent metadata are authoritative at this operation's production OpenAPI JSON Pointer. The readable tables below add integration guidance; the deployed OpenAPI controls if guidance and the machine contract ever differ.
Open the authoritative production contract ↗EXTENDED INTEGRATION GUIDANCE
Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing profile:write authority.EXAMPLEBearer hc_live_…
workspace_uuidpathRequiredidentifierCanonical workspace uuid. It selects the exact workspace uuid addressed by this route.EXAMPLEworkspace-uuid-01
X-Request-IDheaderOptionalstringOptional caller correlation identifier. The gateway emits the effective value on the response.
Idempotency-KeyheaderRequiredASCII string · 1–128Caller-generated stable key reused for retries of the same logical mutation.
Content-DigestheaderRequiredstringRFC 9530 sha-256 digest of the exact transmitted request-body bytes.
Signature-InputheaderRequiredstringRFC 9421 sig1 input covering @method, @path, content-digest, content-type, and idempotency-key, with created, expires, nonce, keyid, and alg=ed25519.
SignatureheaderRequiredstringRFC 9421 sig1 Ed25519 signature made by an active key registered to the bearer client.
default_wallet_networkbodyOptionalhybrid-devnet | hybrid-testnet | hybrid-mainnet | nullDefault wallet environment for this authenticated user in this workspace. Use null to clear the default.Explicit null acceptedEXAMPLEhybrid-mainnet
REQUEST
{
"default_wallet_network": "example-default-wallet-network"
}RESPONSES
{
"default_wallet_network": "example-default-wallet-network",
"updated_at": "2026-09-02T18:30:00Z",
"version": 0,
"workspace_uuid": "01K4A7M4N8Y2Q6R9T3V5W7X1ZB"
}{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentials{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentials{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentials{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentialsOPERATIONAL NOTES
This route is implemented in canonical gateway source and appears in the production OpenAPI snapshot observed 2026-09-11T06:35:11.572Z. Authentication, tenant, feature, venue, and market policy still apply.
Verify the exact production OpenAPI operation ↗Return to the V2 directory ↗