# contractors.email.update

Change the email a contractor is invited at, until they join the portal, with id, expectedRevision and email. It must be unique in the organization, and open invitations to the old address are revoked. Once they've joined, the email is their sign-in and can't change here. The audit log records that it changed, never the addresses.

`POST /api/v1/accounting/contractors.email.update`

Permissions: `accounting:read`, `accounting:write` · Roles: admin, finance · Idempotency key required · Send `expectedRevision`

MCP tool: `accounting_contractors_email_update`

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `id` | string (ID) | Yes | The record's ID. |
| `expectedRevision` | integer | Yes | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. at most 9007199254740991; greater than 0. |
| `email` | string (email) | Yes | An email address. at most 320 characters. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–150 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/contractors.email.update \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
  "expectedRevision": 3,
  "email": "finance@example.com"
}'
```

Reference page: https://app.getoatmilk.com/docs/api/contractors.email.update
