# Set entitlements

Source: https://immiscible.fly.dev/docs/api/put-api-w-wid-members-uid-entitlements

`PUT /api/w/:wid/members/:uid/entitlements`

Owners and admins (only an owner sets an owner's). Lists replace the manual entitlements of each kind given (`null` clears a kind); `max_payment` is whole pence at the GBP reference. An agent never exceeds the entitlements of the person it acts for.

## Authentication

Session cookie. A signed-in person: the console's session cookie. Every state-changing request also carries the header `x-immiscible-csrf: 1`, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.

## Path parameters

- `wid` (string, required): Workspace id
- `uid` (string, required): Member user id

## Request

curl:

```bash
curl -X PUT "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/members/usr_8a0c/entitlements" \
  -H "cookie: __Host-sid=$IMMISCIBLE_SESSION" \
  -H "x-immiscible-csrf: 1" \
  -H "content-type: application/json" \
  -d '{
    "tool": [
      "github:*"
    ],
    "model": [
      "anthropic/*"
    ],
    "data_field": [
      "address",
      "email"
    ],
    "max_payment": 200000
  }'
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/members/usr_8a0c/entitlements', {
  method: 'PUT',
  headers: {
    cookie: `__Host-sid=${process.env.IMMISCIBLE_SESSION}`,
    'x-immiscible-csrf': '1',
    'content-type': 'application/json',
  },
  body: JSON.stringify({
    tool: ['github:*'],
    model: ['anthropic/*'],
    data_field: ['address', 'email'],
    max_payment: 200000,
  }),
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import os
import requests

res = requests.put(
    "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/members/usr_8a0c/entitlements",
    headers={
        "cookie": f"__Host-sid={os.environ['IMMISCIBLE_SESSION']}",
        "x-immiscible-csrf": "1",
        "content-type": "application/json",
    },
    json={
        "tool": ["github:*"],
        "model": ["anthropic/*"],
        "data_field": ["address", "email"],
        "max_payment": 200000,
    },
)
print(res.status_code, res.json())
```
