# contractorOps.roles.assign

Give a contractor a job role, or remove it with roleId null.

`POST /api/v1/accounting/contractorOps.roles.assign`

Permissions: `accounting:read`, `accounting:write` · Roles: admin, finance · Idempotency key required

MCP tool: `accounting_contractor_ops_roles_assign`

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `contractorId` | string (ID) | Yes | The ID of a contractor, from contractors.list. |
| `roleId` | string (ID) or null | Yes |  |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/contractorOps.roles.assign \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "contractorId": "4d5e6f7a-8b9c-4d0e-8f1a-2b3c4d5e6f7a",
  "roleId": "7f0f6c1e-1c1f-4b5e-9c8d-2f5e8e3c1a10"
}'
```

Reference page: https://app.getoatmilk.com/docs/api/contractorOps.roles.assign
