# accountants.access.update

Extend, shorten or clear an accountant's access end date and, optionally, change their access level to read, comment or prepare (exactly that preset, nothing more), with userId, expiresOn (YYYY-MM-DD or null) and/or preset, expectedRevision and idempotencyKey. Extra permissions never outlast the end date. Administrator access is required. MCP calls also require accounting:admin; the web agent asks for approval before changing outside access. Direct API requests cannot perform these access-granting actions.

`POST /api/v1/accounting/accountants.access.update`

Permissions: `accounting:read`, `accounting:write`, `accounting:admin` · Roles: admin · Idempotency key required · Send `expectedRevision` · Reaches outside Oatmilk (email or a provider)

MCP tool: `accounting_accountants_access_update`

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `userId` | string | Yes | The ID of a person in your company. 1–200 characters. |
| `expiresOn` | string or null |  |  |
| `preset` | enum |  | One of: `read`, `comment`, `prepare`. |
| `expectedRevision` | integer | Yes | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. at most 9007199254740991; greater than 0. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/accountants.access.update \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "userId": "example",
  "expectedRevision": 3,
  "expiresOn": "2026-09-30"
}'
```

Reference page: https://app.getoatmilk.com/docs/api/accountants.access.update
