Create and manage organizations, spaces, memberships, API keys, SAML and gates.
For task-oriented walkthroughs of these operations, see the Admin guide . Every mutation below is sent as a POST to https://app.arize.com/graphql with an x-api-key header; see Forming calls .
Mutations in this page
Reference
createOrganization
Create an organization to populate with spaces
createOrganization(input: CreateOrganizationMutationInput!): CreateOrganizationMutationPayload
Arguments
input CreateOrganizationMutationInput!
required
Show CreateOrganizationMutationInput fields
The name of the organization
The description of the organization
Returns
Show AccountOrganization fields
Scalar fields: id, name, createdAt, description, predictionVolume. Object fields (select subfields): creator, spaces, accountOrganizationUsers, integrations, externalLlmApiKeys, customLlmEndpoints, webhooks, costConfigs, alyxCustomViews, modelCount, monitorTriggeredCount, modelTriggeredCount, modelInferencesCount, llmSpansCount, llmModelCosts, llmModelCostsBySpace, totalCostOverTime, averageLatencyOverTime, evalNames, averageEvalScoreOverTime, evalLabelDistribution, traceCountOverTime, errorsOverTime, summaryDashboardConfig.
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
createSpace
Create a space within an organization
createSpace(input: CreateSpaceMutationInput!): CreateSpaceMutationPayload
Arguments
input CreateSpaceMutationInput!
required
Show CreateSpaceMutationInput fields
The ID of the account organization to add the space to
Whether or not the space is private
The description of the space
Start color for space gradient avatar
End color for space gradient avatar
Returns
Scalar fields: id, name, description, uuid, createdAt, liveEnabled, isLLMOnlySpace, playgroundTracingModelId, evalTracingModelId, sandboxTracingModelId, mlModelsEnabled, private, gradientStartColor, gradientEndColor, hasDashboardsCreated. Object fields (select subfields): organization, models, monitors, dashboards, spaceUsers, byobConnectors, importJobs, tableJobs, sandboxJobs, signalInsightSummary, signalEnabledProjectSummary, signalIssues, agentIssues, automations, datasets, experiments, customMetrics, onlineTasks, prompts, tags, evaluators, annotationQueues, playgroundViews, annotationConfigs, traceFilters, llmIntegrations, defaultLlmIntegration, defaultAgentRuntime, gates, _access.
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
updateSpace
Update a space within an organization
updateSpace(input: UpdateSpaceMutationInput!): UpdateSpaceMutationPayload
Arguments
input UpdateSpaceMutationInput!
required
Show UpdateSpaceMutationInput fields
The ID of the space to update
Whether or not the space is private
The description of the space
Start color for space gradient avatar
End color for space gradient avatar
Whether the ML Models tab is enabled for this space
Returns
Scalar fields: id, name, description, uuid, createdAt, liveEnabled, isLLMOnlySpace, playgroundTracingModelId, evalTracingModelId, sandboxTracingModelId, mlModelsEnabled, private, gradientStartColor, gradientEndColor, hasDashboardsCreated. Object fields (select subfields): organization, models, monitors, dashboards, spaceUsers, byobConnectors, importJobs, tableJobs, sandboxJobs, signalInsightSummary, signalEnabledProjectSummary, signalIssues, agentIssues, automations, datasets, experiments, customMetrics, onlineTasks, prompts, tags, evaluators, annotationQueues, playgroundViews, annotationConfigs, traceFilters, llmIntegrations, defaultLlmIntegration, defaultAgentRuntime, gates, _access.
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
deleteSpace
Delete a space
deleteSpace(input: DeleteSpaceMutationInput!): DeleteSpaceMutationPayload
Arguments
input DeleteSpaceMutationInput!
required
Show DeleteSpaceMutationInput fields
The uuid of the space to delete
Returns
Whether the space was deleted successfully
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
assignSpaceMembership
Assign multiple users to multiple spaces with appropriate roles
assignSpaceMembership(input: AssignSpaceMembershipMutationInput!): AssignSpaceMembershipMutationPayload
Arguments
input AssignSpaceMembershipMutationInput!
required
Show AssignSpaceMembershipMutationInput fields
spaceMemberships [SpaceMemberInput!]!
required
A list of user ID’s, roles, and space ID’s Show SpaceMemberInput fields
Legacy space role (admin, member, readOnly, annotator). Either role or customRoleId must be provided, but not both. One of: admin, member, readOnly, annotator.
Custom role ID. Either role or customRoleId must be provided, but not both.
Returns
Scalar fields: id, role. Object fields (select subfields): user.
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
removeSpaceMember
Remove a user from a space
removeSpaceMember(input: RemoveSpaceMemberMutationInput!): RemoveSpaceMemberMutationPayload
Arguments
input RemoveSpaceMemberMutationInput!
required
Show RemoveSpaceMemberMutationInput fields
The user ID of the space member
Returns
Scalar fields: id, name, description, uuid, createdAt, liveEnabled, isLLMOnlySpace, playgroundTracingModelId, evalTracingModelId, sandboxTracingModelId, mlModelsEnabled, private, gradientStartColor, gradientEndColor, hasDashboardsCreated. Object fields (select subfields): organization, models, monitors, dashboards, spaceUsers, byobConnectors, importJobs, tableJobs, sandboxJobs, signalInsightSummary, signalEnabledProjectSummary, signalIssues, agentIssues, automations, datasets, experiments, customMetrics, onlineTasks, prompts, tags, evaluators, annotationQueues, playgroundViews, annotationConfigs, traceFilters, llmIntegrations, defaultLlmIntegration, defaultAgentRuntime, gates, _access.
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
createUserApiKey
Create a new user API key
createUserApiKey(input: CreateUserApiKeyInput!): CreateUserApiKeyPayload
Arguments
input CreateUserApiKeyInput!
required
Show CreateUserApiKeyInput fields
The name of the API key, required
The description of the API key
The date and time the API key will expire
The type of the API key, required One of: user, service.
Returns
The newly created user API key
The information about the newly created API key Scalar fields: id, name, description, keyType, status, redactedKey, createdAt, expiresAt, createdByUserId, botUserId, spaceRole. Object fields (select subfields): customRole.
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
createServiceApiKey
Create a new service API key and its associated bot user
createServiceApiKey(input: CreateServiceApiKeyInput!): CreateServiceApiKeyPayload
Arguments
input CreateServiceApiKeyInput!
required
Show CreateServiceApiKeyInput fields
The name of the bot user and service API key
The ID of the space where the bot will be created (legacy single-space path). Mutually exclusive with organizations.
The predefined legacy role of the bot user in the space. Mutually exclusive with spaceRoleId. One of: admin, member, readOnly, annotator.
The ID of the custom or predefined role of the bot user in the space. Mutually exclusive with spaceRole.
The role of the bot user in the account organization (legacy single-space path). One of: admin, member, readOnly, annotator.
organizations [ServiceKeyOrgAssignmentInput!]
One or more organizations, each with one or more spaces, to grant the service key access to. When provided, use instead of spaceId/spaceRole/spaceRoleId/accountOrganizationRole. Show ServiceKeyOrgAssignmentInput fields
The ID of the organization.
orgRole AccountOrganizationRoles!
required
The role of the bot user in this organization. One of: admin, member, readOnly, annotator.
spaces [ServiceKeySpaceAssignmentInput!]!
required
Spaces within this organization to grant the service key access to. Must include at least one. Show ServiceKeySpaceAssignmentInput fields
The predefined legacy role of the bot user in this space. Mutually exclusive with spaceRoleId. One of: admin, member, readOnly, annotator.
The ID of the custom or predefined role of the bot user in this space. Mutually exclusive with spaceRole.
The role of the bot user in the account. One of: admin, member, annotator.
The date and time the service API key will expire
Returns
The ID of the newly created bot user
The newly created service API key
The information about the newly created service API key Scalar fields: id, name, description, keyType, status, redactedKey, createdAt, expiresAt, createdByUserId, botUserId, spaceRole. Object fields (select subfields): customRole.
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
revokeApiKey
Revokes an API key
revokeApiKey(input: RevokeApiKeyInput!): RevokeApiKeyPayload
Arguments
input RevokeApiKeyInput!
required
Show RevokeApiKeyInput fields
The ID of the API key to revoke
Returns
The status of the API key revocation One of: ok.
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
createSAMLIdP
Create a new SAML Identity Provider configuration
createSAMLIdP(input: CreateSAMLIdPInput!): CreateSAMLIdPPayload
Arguments
input CreateSAMLIdPInput!
required
Show CreateSAMLIdPInput fields
emailDomainsList [EmailDomainInput!]!
required
Email domains that this IdP handles Show EmailDomainInput fields
Optional ID for the email domain
The email domain (e.g., example.com)
Whether the domain has been validated
URL to fetch SAML metadata from
Default organization ID for new users
Default space ID for new users
Default organization role ID for new users
Default space role ID for new users
Whether to enforce SAML authentication for the account
Whether to sync user roles from SAML assertions
Whether to sign authentication requests
Input for role mappings configuration Show RoleMappingsInput fields
List of role mappings Show RoleMappingInput fields
Optional ID for the role mapping
Map of space roles as array of [spaceId, role] tuples matching protobuf format
Map of RBAC space roles as array of [spaceId, rbacRoleRelayGlobalId] tuples. Mutually exclusive with spaceRolesMap per mapping.
Map of project RBAC roles as array of [projectId, rbacRoleRelayGlobalId] tuples. Requires org_role to be set.
Whether project role mappings are managed for this role mapping. When false, projectRolesMap is ignored.
Map of attributes as array of [key, value] tuples matching protobuf format
Whether the user is an account admin
Organization role with orgId and roleId Nested OrgRoleInput (same shape as above).
Ignored. Developer access is derived from the assigned Account role. Deprecated: Developer access is derived from the assigned Account role.
Whether to allow login with default roles
The status of the IdP (active or deleted)
Returns
The created SAML IdP configuration Scalar fields: id, accountId, metadataUrl, metadataXml, defaultOrgId, defaultSpaceId, defaultOrgRoleId, defaultSpaceRoleId, enforceSaml, syncUserRoles, signAuthn, allowLoginWithDefaults, createdAt, createdByUserId, updatedAt, isManagedByFile. Object fields (select subfields): emailDomainsList, roleMappings.
Error message if the operation failed
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
updateSAMLIdP
Update an existing SAML Identity Provider configuration
updateSAMLIdP(input: UpdateSAMLIdPInput!): UpdateSAMLIdPPayload
Arguments
input UpdateSAMLIdPInput!
required
Show UpdateSAMLIdPInput fields
The ID of the SAML IdP to update
Email domains that this IdP handles Show EmailDomainInput fields
Optional ID for the email domain
The email domain (e.g., example.com)
Whether the domain has been validated
URL to fetch SAML metadata from
Default organization ID for new users
Default space ID for new users
Default organization role ID for new users
Default space role ID for new users
Whether to enforce SAML authentication for the account
Whether to sync user roles from SAML assertions
Whether to sign authentication requests
Input for role mappings configuration Show RoleMappingsInput fields
List of role mappings Show RoleMappingInput fields
Optional ID for the role mapping
Map of space roles as array of [spaceId, role] tuples matching protobuf format
Map of RBAC space roles as array of [spaceId, rbacRoleRelayGlobalId] tuples. Mutually exclusive with spaceRolesMap per mapping.
Map of project RBAC roles as array of [projectId, rbacRoleRelayGlobalId] tuples. Requires org_role to be set.
Whether project role mappings are managed for this role mapping. When false, projectRolesMap is ignored.
Map of attributes as array of [key, value] tuples matching protobuf format
Whether the user is an account admin
Organization role with orgId and roleId Nested OrgRoleInput (same shape as above).
Ignored. Developer access is derived from the assigned Account role. Deprecated: Developer access is derived from the assigned Account role.
Whether to allow login with default roles
Returns
The updated SAML IdP configuration Scalar fields: id, accountId, metadataUrl, metadataXml, defaultOrgId, defaultSpaceId, defaultOrgRoleId, defaultSpaceRoleId, enforceSaml, syncUserRoles, signAuthn, allowLoginWithDefaults, createdAt, createdByUserId, updatedAt, isManagedByFile. Object fields (select subfields): emailDomainsList, roleMappings.
Error message if the operation failed
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
addSAMLRoleMapping
Add a single role mapping to a SAML Identity Provider without touching its other role mappings. Rejected if a mapping with identical SAML attributes and organization already exists.
addSAMLRoleMapping(input: AddSAMLRoleMappingInput!): AddSAMLRoleMappingPayload
Arguments
input AddSAMLRoleMappingInput!
required
Show AddSAMLRoleMappingInput fields
The ID of the SAML IdP to update
mapping RoleMappingInput!
required
The role mapping to add Show RoleMappingInput fields
Optional ID for the role mapping
Map of space roles as array of [spaceId, role] tuples matching protobuf format
Map of RBAC space roles as array of [spaceId, rbacRoleRelayGlobalId] tuples. Mutually exclusive with spaceRolesMap per mapping.
Map of project RBAC roles as array of [projectId, rbacRoleRelayGlobalId] tuples. Requires org_role to be set.
Whether project role mappings are managed for this role mapping. When false, projectRolesMap is ignored.
Map of attributes as array of [key, value] tuples matching protobuf format
Whether the user is an account admin
Organization role with orgId and roleId Ignored. Developer access is derived from the assigned Account role. Deprecated: Developer access is derived from the assigned Account role.
Returns
The updated SAML IdP configuration Scalar fields: id, accountId, metadataUrl, metadataXml, defaultOrgId, defaultSpaceId, defaultOrgRoleId, defaultSpaceRoleId, enforceSaml, syncUserRoles, signAuthn, allowLoginWithDefaults, createdAt, createdByUserId, updatedAt, isManagedByFile. Object fields (select subfields): emailDomainsList, roleMappings.
Error message if the operation failed
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
createExporterAuditLog
Create an exporter audit log
createExporterAuditLog(input: CreateExporterAuditLogInput!): CreateExporterAuditLogPayload
Arguments
input CreateExporterAuditLogInput!
required
Show CreateExporterAuditLogInput fields
The uuid of the model to create the audit log for
Returns
Whether or not the exporter audit log was successfully logged. False if logging is not enabled for the account.
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
setSpaceGateLimit
Set a rate limit gate value for a space. A value of 0 blocks all ingestion.
setSpaceGateLimit(input: SetSpaceGateLimitMutationInput!): SetSpaceGateLimitMutationPayload
Arguments
input SetSpaceGateLimitMutationInput!
required
Show SetSpaceGateLimitMutationInput fields
The ID of the space to set the gate limit for
The gate type to set the limit for One of: workspaces, organizations, prodPredictions, preProdPredictions, activeModels, features, dataSize.
The limit value to set. 0 blocks all ingestion; positive values cap usage.
Returns
Scalar fields: id, name, description, uuid, createdAt, liveEnabled, isLLMOnlySpace, playgroundTracingModelId, evalTracingModelId, sandboxTracingModelId, mlModelsEnabled, private, gradientStartColor, gradientEndColor, hasDashboardsCreated. Object fields (select subfields): organization, models, monitors, dashboards, spaceUsers, byobConnectors, importJobs, tableJobs, sandboxJobs, signalInsightSummary, signalEnabledProjectSummary, signalIssues, agentIssues, automations, datasets, experiments, customMetrics, onlineTasks, prompts, tags, evaluators, annotationQueues, playgroundViews, annotationConfigs, traceFilters, llmIntegrations, defaultLlmIntegration, defaultAgentRuntime, gates, _access.
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.
deleteSpaceGateLimit
Remove a rate limit gate from a space, resetting it to no limit.
deleteSpaceGateLimit(input: DeleteSpaceGateLimitMutationInput!): DeleteSpaceGateLimitMutationPayload
Arguments
input DeleteSpaceGateLimitMutationInput!
required
Show DeleteSpaceGateLimitMutationInput fields
The ID of the space to remove the gate limit from
The gate type to remove One of: workspaces, organizations, prodPredictions, preProdPredictions, activeModels, features, dataSize.
Returns
Scalar fields: id, name, description, uuid, createdAt, liveEnabled, isLLMOnlySpace, playgroundTracingModelId, evalTracingModelId, sandboxTracingModelId, mlModelsEnabled, private, gradientStartColor, gradientEndColor, hasDashboardsCreated. Object fields (select subfields): organization, models, monitors, dashboards, spaceUsers, byobConnectors, importJobs, tableJobs, sandboxJobs, signalInsightSummary, signalEnabledProjectSummary, signalIssues, agentIssues, automations, datasets, experiments, customMetrics, onlineTasks, prompts, tags, evaluators, annotationQueues, playgroundViews, annotationConfigs, traceFilters, llmIntegrations, defaultLlmIntegration, defaultAgentRuntime, gates, _access.
Example
Only required input fields are shown. Replace <ID> and <string> placeholders with real values; the object graph page shows how to look IDs up.