Skip to main content
Admin resources are the account-level building blocks everything else in Arize AX sits on: organizations group spaces, spaces hold the models, projects and prompts you instrument, and space membership and API keys control who and what can reach them. This guide covers scripting those resources directly instead of clicking through the UI, which is useful for onboarding automation, CI pipelines that provision their own service keys, and bulk user or SAML role management. For the product-level concepts, see Organizations & Spaces, API and service keys, SSO & RBAC and Space rate limiting.

Find the IDs you need

Most admin mutations take an organization ID, a space ID, or a user ID. Start from account to walk down to organizations and their spaces, and from node once you already hold a global ID. See using global node IDs for how these IDs are encoded.
To find a user’s ID, either look them up within an organization (see the first recipe below) or, if you only have an email, page through account.users(search: "<email>").

List the spaces in an organization and their members

Before assigning or removing membership, pull the current member list for a space (or the full organization roster) so you know which user IDs and roles you are working with.
Space.spaceUsers returns every user with access to the space, including account and organization admins who were never explicitly added, not only direct members. For users with custom RBAC roles, role on SpaceUser is null; check customRole instead.

Create a space in an organization

Spaces are created inside an organization, so you need the organization’s ID first (see above).
Reference: createSpace. To rename a space, change its description, or flip mlModelsEnabled, use updateSpace with the same spaceId. To delete one, use deleteSpace, which takes the space’s uuid, not its global id.

Bulk-assign users to spaces with roles

assignSpaceMembership takes a list, so you can onboard a whole team across multiple spaces in one call. Each entry needs either a legacy role or a customRoleId, never both.
Reference: assignSpaceMembership. Legacy role accepts admin, member, readOnly or annotator. Custom RBAC role IDs (for customRoleId) aren’t queryable through this API; copy them from Settings > Roles in the Arize UI. Scripting this in bulk is a common CI task, for example syncing space access from an HR system:

Remove a member from a space

Reference: removeSpaceMember. This removes direct space membership only; a user who still has access through an organization or account admin role keeps access to the space.

Create a service API key for CI

Service keys back a dedicated bot user rather than a human, which is what you want for pipelines. Grant access either to a single space (legacy path) or to multiple organizations and spaces at once with organizations; the two approaches are mutually exclusive.
Reference: createServiceApiKey. The response’s apiKey field is the only time the raw key is returned; store it immediately. For a personal key instead of a bot-backed one, use createUserApiKey, which only takes a name, optional description and expiresAt, and a type of user or service.

Revoke an API key

Reference: revokeApiKey. status only ever returns ok on success; a failed revocation (for example, an already-revoked or unknown key) comes back as a GraphQL error rather than a different status value. Find the key ID to revoke on viewer.apiKeys for your own keys, or from the keyInfo.id returned when the key was created.

Configure a SAML identity provider and add a role mapping

Create the IdP with its email domains and metadata, then add role mappings one at a time so you don’t have to resend the entire configuration for each change.
Then add a mapping that promotes a SAML attribute to a space role without touching the mappings already configured:
Reference: createSAMLIdP and addSAMLRoleMapping. addSAMLRoleMapping rejects a mapping whose SAML attributes and organization already match an existing one. To change the metadata, default roles or other top-level settings afterward, use updateSAMLIdP, which replaces the full configuration, so include every roleMappings entry you want to keep, not just the ones you’re changing. spaceRolesMap (legacy roles) and spaceRbacRolesMap (custom RBAC role IDs) are mutually exclusive on the same mapping, and custom role IDs have to come from the Arize UI since there’s no query that lists them.

Set or clear a space ingestion gate

Ingestion gates cap how much data a space can take in per TierGate category. Setting a gate to 0 blocks all ingestion for that category; clearing it removes the limit entirely.
Reference: setSpaceGateLimit and deleteSpaceGateLimit. gateType is one of workspaces, organizations, prodPredictions, preProdPredictions, activeModels, features or dataSize; dataSize is measured in bytes. See Space rate limiting for what each gate controls.

Gotchas and behavior notes

SpaceMemberInput requires either role or customRoleId, never both. CreateServiceApiKeyInput requires either the legacy spaceId/spaceRole/spaceRoleId/accountOrganizationRole path or organizations, never both, and within each space assignment, spaceRole and spaceRoleId are themselves mutually exclusive. A RoleMappingInput can set spaceRolesMap or spaceRbacRolesMap, but not both. None of this is enforced by the schema’s nullability; sending both fields returns a runtime error.
Every other space mutation takes spaceId (the global ID!). deleteSpace instead takes spaceUuid, the Space.uuid scalar field. Query uuid separately before calling it.
The admin mutations are limited to createSAMLIdP, updateSAMLIdP and addSAMLRoleMapping; there’s no mutation to delete a SAML configuration. CreateSAMLIdPInput accepts a status of "active" or "deleted" at creation time, but UpdateSAMLIdPInput has no status field, so an existing config can’t be soft-deleted through the API either.
Treat every call as a full replacement. Fields you omit may reset rather than stay untouched, and that applies to roleMappings.mappingsList too: resend every mapping you want to keep alongside any changes.
The schema has no roles field on Account and no connection type for roles; Role doesn’t implement Node either, so you can’t fetch one by ID through node. Get custom role IDs for customRoleId, spaceRoleId or spaceRbacRolesMap from Settings > Roles in the Arize UI.
Account.developerAccessDefault always returns true now; developer access comes from the user’s assigned account role. Use Account.developerAccessLocked to disable developer access account-wide instead.

Admin mutations reference

Full arguments, return types and minimal examples for every admin mutation.

All mutations

Browse mutations for every other domain: monitors, datasets, prompts and more.

API explorer

Run queries and mutations interactively against your own space.