Skip to content
POST /toolbox/{id}/share

Grants one user, team, or the whole org access at a level. Levels are ordered `view` < `use` < `edit`: `use` DELEGATES — the grantee executes tools on this toolbox, running each pinned entry through ITS delegator's own authority, never their own. Re-granting the same grantee replaces the level rather than stacking. The response repeats the toolbox's `delegation` summary — the same bounded rollup `GET /toolbox/{id}` carries, so a client that shares without ever having read the detail still learns what it just handed out. Rejects a dynamic id with 400 — there is no ACL behind one. Requires `edit` access or ownership, and `toolbox:share`.

Path Parameters

idstring
required·

Stored toolbox id (tbx_…).

curl -X POST 'https://api.elaichi.ai/toolbox/<id>/share' \
  -H 'Authorization: Bearer $ELAICHI_API_TOKEN' \
  -H 'Content-Type: application/json'
const response = await fetch('https://api.elaichi.ai/toolbox/<id>/share', {
  method: 'POST',
  headers: {
    'Authorization': 'Bearer ' + process.env.ELAICHI_API_TOKEN,
    'Content-Type': 'application/json',
  },
});

const data = await response.json();
console.log(data);
import os
import requests

url = "https://api.elaichi.ai/toolbox/<id>/share"
headers = {
    "Authorization": f"Bearer {os.environ['ELAICHI_API_TOKEN']}",
    "Content-Type": "application/json",
}

response = requests.post(url, headers=headers)
print(response.json())