> ## Documentation Index
> Fetch the complete documentation index at: https://arize-ax.mintlify.site/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Admin mutations

> Create and manage organizations, spaces, memberships, API keys, SAML and gates. Arguments, return types and a validated example for each of the 15 mutations.

Create and manage organizations, spaces, memberships, API keys, SAML and gates.

For task-oriented walkthroughs of these operations, see the [Admin guide](/docs/ax/graphql-reference/guides/admin). Every mutation below is sent as a `POST` to `https://app.arize.com/graphql` with an `x-api-key` header; see [Forming calls](/docs/ax/graphql-reference/overview/how-to-use-graphql/forming-calls).

## Mutations in this page

* [`createOrganization`](#createorganization): Create an organization to populate with spaces
* [`createSpace`](#createspace): Create a space within an organization
* [`updateSpace`](#updatespace): Update a space within an organization
* [`deleteSpace`](#deletespace): Delete a space
* [`assignSpaceMembership`](#assignspacemembership): Assign multiple users to multiple spaces with appropriate roles
* [`removeSpaceMember`](#removespacemember): Remove a user from a space
* [`createUserApiKey`](#createuserapikey): Create a new user API key
* [`createServiceApiKey`](#createserviceapikey): Create a new service API key and its associated bot user
* [`revokeApiKey`](#revokeapikey): Revokes an API key
* [`createSAMLIdP`](#createsamlidp): Create a new SAML Identity Provider configuration
* [`updateSAMLIdP`](#updatesamlidp): Update an existing SAML Identity Provider configuration
* [`addSAMLRoleMapping`](#addsamlrolemapping): Add a single role mapping to a SAML Identity Provider without touching its other role mappings.
* [`createExporterAuditLog`](#createexporterauditlog): Create an exporter audit log
* [`setSpaceGateLimit`](#setspacegatelimit): Set a rate limit gate value for a space.
* [`deleteSpaceGateLimit`](#deletespacegatelimit): Remove a rate limit gate from a space, resetting it to no limit.

## Reference

### createOrganization

Create an organization to populate with spaces

`createOrganization(input: CreateOrganizationMutationInput!): CreateOrganizationMutationPayload`

#### Arguments

<ParamField body="input" type="CreateOrganizationMutationInput!" required>
  <Expandable title="CreateOrganizationMutationInput fields">
    <ParamField body="name" type="String!" required>
      The name of the organization
    </ParamField>

    <ParamField body="description" type="String">
      The description of the organization
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="organization" type="AccountOrganization!">
  <Expandable title="AccountOrganization fields">
    Scalar fields: `id`, `name`, `createdAt`, `description`, `predictionVolume`.

    Object fields (select subfields): `creator`, `spaces`, `accountOrganizationUsers`, `integrations`, `externalLlmApiKeys`, `customLlmEndpoints`, `webhooks`, `costConfigs`, `alyxCustomViews`, `modelCount`, `monitorTriggeredCount`, `modelTriggeredCount`, `modelInferencesCount`, `llmSpansCount`, `llmModelCosts`, `llmModelCostsBySpace`, `totalCostOverTime`, `averageLatencyOverTime`, `evalNames`, `averageEvalScoreOverTime`, `evalLabelDistribution`, `traceCountOverTime`, `errorsOverTime`, `summaryDashboardConfig`.
  </Expandable>
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation CreateOrganization($input: CreateOrganizationMutationInput!) {
    createOrganization(input: $input) {
      organization { id name }
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "name": "<string>"
    }
  }
  ```
</CodeGroup>

### createSpace

Create a space within an organization

`createSpace(input: CreateSpaceMutationInput!): CreateSpaceMutationPayload`

#### Arguments

<ParamField body="input" type="CreateSpaceMutationInput!" required>
  <Expandable title="CreateSpaceMutationInput fields">
    <ParamField body="accountOrganizationId" type="ID!" required>
      The ID of the account organization to add the space to
    </ParamField>

    <ParamField body="name" type="String!" required>
      The name of the space
    </ParamField>

    <ParamField body="private" type="Boolean!" required>
      Whether or not the space is private
    </ParamField>

    <ParamField body="description" type="String">
      The description of the space
    </ParamField>

    <ParamField body="gradientStartColor" type="HexColorCode">
      Start color for space gradient avatar
    </ParamField>

    <ParamField body="gradientEndColor" type="HexColorCode">
      End color for space gradient avatar
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="space" type="Space!">
  <Expandable title="Space fields">
    Scalar fields: `id`, `name`, `description`, `uuid`, `createdAt`, `liveEnabled`, `isLLMOnlySpace`, `playgroundTracingModelId`, `evalTracingModelId`, `sandboxTracingModelId`, `mlModelsEnabled`, `private`, `gradientStartColor`, `gradientEndColor`, `hasDashboardsCreated`.

    Object fields (select subfields): `organization`, `models`, `monitors`, `dashboards`, `spaceUsers`, `byobConnectors`, `importJobs`, `tableJobs`, `sandboxJobs`, `signalInsightSummary`, `signalEnabledProjectSummary`, `signalIssues`, `agentIssues`, `automations`, `datasets`, `experiments`, `customMetrics`, `onlineTasks`, `prompts`, `tags`, `evaluators`, `annotationQueues`, `playgroundViews`, `annotationConfigs`, `traceFilters`, `llmIntegrations`, `defaultLlmIntegration`, `defaultAgentRuntime`, `gates`, `_access`.
  </Expandable>
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation CreateSpace($input: CreateSpaceMutationInput!) {
    createSpace(input: $input) {
      space { id name }
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "accountOrganizationId": "<ID>",
      "name": "<string>",
      "private": true
    }
  }
  ```
</CodeGroup>

### updateSpace

Update a space within an organization

`updateSpace(input: UpdateSpaceMutationInput!): UpdateSpaceMutationPayload`

#### Arguments

<ParamField body="input" type="UpdateSpaceMutationInput!" required>
  <Expandable title="UpdateSpaceMutationInput fields">
    <ParamField body="spaceId" type="ID!" required>
      The ID of the space to update
    </ParamField>

    <ParamField body="name" type="String">
      The name of the space
    </ParamField>

    <ParamField body="private" type="Boolean">
      Whether or not the space is private
    </ParamField>

    <ParamField body="description" type="String">
      The description of the space
    </ParamField>

    <ParamField body="gradientStartColor" type="HexColorCode">
      Start color for space gradient avatar
    </ParamField>

    <ParamField body="gradientEndColor" type="HexColorCode">
      End color for space gradient avatar
    </ParamField>

    <ParamField body="mlModelsEnabled" type="Boolean">
      Whether the ML Models tab is enabled for this space
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="space" type="Space">
  <Expandable title="Space fields">
    Scalar fields: `id`, `name`, `description`, `uuid`, `createdAt`, `liveEnabled`, `isLLMOnlySpace`, `playgroundTracingModelId`, `evalTracingModelId`, `sandboxTracingModelId`, `mlModelsEnabled`, `private`, `gradientStartColor`, `gradientEndColor`, `hasDashboardsCreated`.

    Object fields (select subfields): `organization`, `models`, `monitors`, `dashboards`, `spaceUsers`, `byobConnectors`, `importJobs`, `tableJobs`, `sandboxJobs`, `signalInsightSummary`, `signalEnabledProjectSummary`, `signalIssues`, `agentIssues`, `automations`, `datasets`, `experiments`, `customMetrics`, `onlineTasks`, `prompts`, `tags`, `evaluators`, `annotationQueues`, `playgroundViews`, `annotationConfigs`, `traceFilters`, `llmIntegrations`, `defaultLlmIntegration`, `defaultAgentRuntime`, `gates`, `_access`.
  </Expandable>
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation UpdateSpace($input: UpdateSpaceMutationInput!) {
    updateSpace(input: $input) {
      space { id name }
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "spaceId": "<ID>"
    }
  }
  ```
</CodeGroup>

### deleteSpace

Delete a space

`deleteSpace(input: DeleteSpaceMutationInput!): DeleteSpaceMutationPayload`

#### Arguments

<ParamField body="input" type="DeleteSpaceMutationInput!" required>
  <Expandable title="DeleteSpaceMutationInput fields">
    <ParamField body="spaceUuid" type="String!" required>
      The uuid of the space to delete
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="success" type="Boolean">
  Whether the space was deleted successfully
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation DeleteSpace($input: DeleteSpaceMutationInput!) {
    deleteSpace(input: $input) {
      success
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "spaceUuid": "<string>"
    }
  }
  ```
</CodeGroup>

### assignSpaceMembership

Assign multiple users to multiple spaces with appropriate roles

`assignSpaceMembership(input: AssignSpaceMembershipMutationInput!): AssignSpaceMembershipMutationPayload`

#### Arguments

<ParamField body="input" type="AssignSpaceMembershipMutationInput!" required>
  <Expandable title="AssignSpaceMembershipMutationInput fields">
    <ParamField body="spaceMemberships" type="[SpaceMemberInput!]!" required>
      A list of user ID's, roles, and space ID's

      <Expandable title="SpaceMemberInput fields">
        <ParamField body="userId" type="ID!" required />

        <ParamField body="spaceId" type="ID!" required />

        <ParamField body="role" type="SpaceMemberRole">
          Legacy space role (admin, member, readOnly, annotator). Either role or customRoleId must be provided, but not both. One of: `admin`, `member`, `readOnly`, `annotator`.
        </ParamField>

        <ParamField body="customRoleId" type="ID">
          Custom role ID. Either role or customRoleId must be provided, but not both.
        </ParamField>
      </Expandable>
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="spaceMemberships" type="[SpaceMember!]">
  <Expandable title="SpaceMember fields">
    Scalar fields: `id`, `role`.

    Object fields (select subfields): `user`.
  </Expandable>
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation AssignSpaceMembership($input: AssignSpaceMembershipMutationInput!) {
    assignSpaceMembership(input: $input) {
      spaceMemberships { id }
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {}
  }
  ```
</CodeGroup>

### removeSpaceMember

Remove a user from a space

`removeSpaceMember(input: RemoveSpaceMemberMutationInput!): RemoveSpaceMemberMutationPayload`

#### Arguments

<ParamField body="input" type="RemoveSpaceMemberMutationInput!" required>
  <Expandable title="RemoveSpaceMemberMutationInput fields">
    <ParamField body="spaceId" type="ID!" required>
      The ID of the space
    </ParamField>

    <ParamField body="userId" type="ID!" required>
      The user ID of the space member
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="space" type="Space">
  <Expandable title="Space fields">
    Scalar fields: `id`, `name`, `description`, `uuid`, `createdAt`, `liveEnabled`, `isLLMOnlySpace`, `playgroundTracingModelId`, `evalTracingModelId`, `sandboxTracingModelId`, `mlModelsEnabled`, `private`, `gradientStartColor`, `gradientEndColor`, `hasDashboardsCreated`.

    Object fields (select subfields): `organization`, `models`, `monitors`, `dashboards`, `spaceUsers`, `byobConnectors`, `importJobs`, `tableJobs`, `sandboxJobs`, `signalInsightSummary`, `signalEnabledProjectSummary`, `signalIssues`, `agentIssues`, `automations`, `datasets`, `experiments`, `customMetrics`, `onlineTasks`, `prompts`, `tags`, `evaluators`, `annotationQueues`, `playgroundViews`, `annotationConfigs`, `traceFilters`, `llmIntegrations`, `defaultLlmIntegration`, `defaultAgentRuntime`, `gates`, `_access`.
  </Expandable>
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation RemoveSpaceMember($input: RemoveSpaceMemberMutationInput!) {
    removeSpaceMember(input: $input) {
      space { id name }
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "spaceId": "<ID>",
      "userId": "<ID>"
    }
  }
  ```
</CodeGroup>

### createUserApiKey

Create a new user API key

`createUserApiKey(input: CreateUserApiKeyInput!): CreateUserApiKeyPayload`

#### Arguments

<ParamField body="input" type="CreateUserApiKeyInput!" required>
  <Expandable title="CreateUserApiKeyInput fields">
    <ParamField body="name" type="String!" required>
      The name of the API key, required
    </ParamField>

    <ParamField body="description" type="String">
      The description of the API key
    </ParamField>

    <ParamField body="expiresAt" type="DateTime">
      The date and time the API key will expire
    </ParamField>

    <ParamField body="type" type="ApiKeyType!" required>
      The type of the API key, required One of: `user`, `service`.
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="apiKey" type="String">
  The newly created user API key
</ResponseField>

<ResponseField name="keyInfo" type="ApiKey">
  The information about the newly created API key

  <Expandable title="ApiKey fields">
    Scalar fields: `id`, `name`, `description`, `keyType`, `status`, `redactedKey`, `createdAt`, `expiresAt`, `createdByUserId`, `botUserId`, `spaceRole`.

    Object fields (select subfields): `customRole`.
  </Expandable>
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation CreateUserApiKey($input: CreateUserApiKeyInput!) {
    createUserApiKey(input: $input) {
      apiKey
      keyInfo { id name status }
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "name": "<string>",
      "type": "user"
    }
  }
  ```
</CodeGroup>

### createServiceApiKey

Create a new service API key and its associated bot user

`createServiceApiKey(input: CreateServiceApiKeyInput!): CreateServiceApiKeyPayload`

#### Arguments

<ParamField body="input" type="CreateServiceApiKeyInput!" required>
  <Expandable title="CreateServiceApiKeyInput fields">
    <ParamField body="name" type="String!" required>
      The name of the bot user and service API key
    </ParamField>

    <ParamField body="spaceId" type="String">
      The ID of the space where the bot will be created (legacy single-space path). Mutually exclusive with organizations.
    </ParamField>

    <ParamField body="spaceRole" type="SpaceMemberRole">
      The predefined legacy role of the bot user in the space. Mutually exclusive with spaceRoleId. One of: `admin`, `member`, `readOnly`, `annotator`.
    </ParamField>

    <ParamField body="spaceRoleId" type="String">
      The ID of the custom or predefined role of the bot user in the space. Mutually exclusive with spaceRole.
    </ParamField>

    <ParamField body="accountOrganizationRole" type="AccountOrganizationRoles">
      The role of the bot user in the account organization (legacy single-space path). One of: `admin`, `member`, `readOnly`, `annotator`.
    </ParamField>

    <ParamField body="organizations" type="[ServiceKeyOrgAssignmentInput!]">
      One or more organizations, each with one or more spaces, to grant the service key access to. When provided, use instead of spaceId/spaceRole/spaceRoleId/accountOrganizationRole.

      <Expandable title="ServiceKeyOrgAssignmentInput fields">
        <ParamField body="orgId" type="String!" required>
          The ID of the organization.
        </ParamField>

        <ParamField body="orgRole" type="AccountOrganizationRoles!" required>
          The role of the bot user in this organization. One of: `admin`, `member`, `readOnly`, `annotator`.
        </ParamField>

        <ParamField body="spaces" type="[ServiceKeySpaceAssignmentInput!]!" required>
          Spaces within this organization to grant the service key access to. Must include at least one.

          <Expandable title="ServiceKeySpaceAssignmentInput fields">
            <ParamField body="spaceId" type="String!" required>
              The ID of the space.
            </ParamField>

            <ParamField body="spaceRole" type="SpaceMemberRole">
              The predefined legacy role of the bot user in this space. Mutually exclusive with spaceRoleId. One of: `admin`, `member`, `readOnly`, `annotator`.
            </ParamField>

            <ParamField body="spaceRoleId" type="String">
              The ID of the custom or predefined role of the bot user in this space. Mutually exclusive with spaceRole.
            </ParamField>
          </Expandable>
        </ParamField>
      </Expandable>
    </ParamField>

    <ParamField body="accountRole" type="AccountRole!" required>
      The role of the bot user in the account. One of: `admin`, `member`, `annotator`.
    </ParamField>

    <ParamField body="expiresAt" type="DateTime">
      The date and time the service API key will expire
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="botUserId" type="String">
  The ID of the newly created bot user
</ResponseField>

<ResponseField name="apiKey" type="String">
  The newly created service API key
</ResponseField>

<ResponseField name="keyInfo" type="ApiKey">
  The information about the newly created service API key

  <Expandable title="ApiKey fields">
    Scalar fields: `id`, `name`, `description`, `keyType`, `status`, `redactedKey`, `createdAt`, `expiresAt`, `createdByUserId`, `botUserId`, `spaceRole`.

    Object fields (select subfields): `customRole`.
  </Expandable>
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation CreateServiceApiKey($input: CreateServiceApiKeyInput!) {
    createServiceApiKey(input: $input) {
      botUserId
      apiKey
      keyInfo { id name status }
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "name": "<string>",
      "accountRole": "admin"
    }
  }
  ```
</CodeGroup>

### revokeApiKey

Revokes an API key

`revokeApiKey(input: RevokeApiKeyInput!): RevokeApiKeyPayload`

#### Arguments

<ParamField body="input" type="RevokeApiKeyInput!" required>
  <Expandable title="RevokeApiKeyInput fields">
    <ParamField body="apiKeyId" type="ID!" required>
      The ID of the API key to revoke
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="status" type="RevokeApiKeyStatus!">
  The status of the API key revocation One of: `ok`.
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation RevokeApiKey($input: RevokeApiKeyInput!) {
    revokeApiKey(input: $input) {
      status
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "apiKeyId": "<ID>"
    }
  }
  ```
</CodeGroup>

### createSAMLIdP

Create a new SAML Identity Provider configuration

`createSAMLIdP(input: CreateSAMLIdPInput!): CreateSAMLIdPPayload`

#### Arguments

<ParamField body="input" type="CreateSAMLIdPInput!" required>
  <Expandable title="CreateSAMLIdPInput fields">
    <ParamField body="emailDomainsList" type="[EmailDomainInput!]!" required>
      Email domains that this IdP handles

      <Expandable title="EmailDomainInput fields">
        <ParamField body="id" type="ID">
          Optional ID for the email domain
        </ParamField>

        <ParamField body="domain" type="String!" required>
          The email domain (e.g., example.com)
        </ParamField>

        <ParamField body="validated" type="Boolean">
          Whether the domain has been validated
        </ParamField>
      </Expandable>
    </ParamField>

    <ParamField body="metadataUrl" type="String">
      URL to fetch SAML metadata from
    </ParamField>

    <ParamField body="metadataXml" type="String">
      Raw SAML metadata XML
    </ParamField>

    <ParamField body="defaultOrgId" type="ID">
      Default organization ID for new users
    </ParamField>

    <ParamField body="defaultSpaceId" type="ID">
      Default space ID for new users
    </ParamField>

    <ParamField body="defaultOrgRoleId" type="ID">
      Default organization role ID for new users
    </ParamField>

    <ParamField body="defaultSpaceRoleId" type="ID">
      Default space role ID for new users
    </ParamField>

    <ParamField body="enforceSaml" type="Boolean">
      Whether to enforce SAML authentication for the account
    </ParamField>

    <ParamField body="syncUserRoles" type="Boolean">
      Whether to sync user roles from SAML assertions
    </ParamField>

    <ParamField body="signAuthn" type="Boolean">
      Whether to sign authentication requests
    </ParamField>

    <ParamField body="roleMappings" type="RoleMappingsInput">
      Input for role mappings configuration

      <Expandable title="RoleMappingsInput fields">
        <ParamField body="mappingsList" type="[RoleMappingInput]">
          List of role mappings

          <Expandable title="RoleMappingInput fields">
            <ParamField body="id" type="ID">
              Optional ID for the role mapping
            </ParamField>

            <ParamField body="spaceRolesMap" type="[[String]]">
              Map of space roles as array of \[spaceId, role] tuples matching protobuf format
            </ParamField>

            <ParamField body="spaceRbacRolesMap" type="[[String!]!]">
              Map of RBAC space roles as array of \[spaceId, rbacRoleRelayGlobalId] tuples. Mutually exclusive with spaceRolesMap per mapping.
            </ParamField>

            <ParamField body="projectRolesMap" type="[[String!]!]">
              Map of project RBAC roles as array of \[projectId, rbacRoleRelayGlobalId] tuples. Requires org\_role to be set.
            </ParamField>

            <ParamField body="projectRolesManaged" type="Boolean">
              Whether project role mappings are managed for this role mapping. When false, projectRolesMap is ignored.
            </ParamField>

            <ParamField body="attributesMap" type="[[String]]">
              Map of attributes as array of \[key, value] tuples matching protobuf format
            </ParamField>

            <ParamField body="isAccountAdmin" type="Boolean">
              Whether the user is an account admin
            </ParamField>

            <ParamField body="orgRole" type="OrgRoleInput">
              Organization role with orgId and roleId Nested `OrgRoleInput` (same shape as above).
            </ParamField>

            <ParamField body="developerAccess" type="Boolean">
              Ignored. Developer access is derived from the assigned Account role. **Deprecated:** Developer access is derived from the assigned Account role.
            </ParamField>
          </Expandable>
        </ParamField>
      </Expandable>
    </ParamField>

    <ParamField body="allowLoginWithDefaults" type="Boolean">
      Whether to allow login with default roles
    </ParamField>

    <ParamField body="status" type="String">
      The status of the IdP (active or deleted)
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="idp" type="SAMLIdP">
  The created SAML IdP configuration

  <Expandable title="SAMLIdP fields">
    Scalar fields: `id`, `accountId`, `metadataUrl`, `metadataXml`, `defaultOrgId`, `defaultSpaceId`, `defaultOrgRoleId`, `defaultSpaceRoleId`, `enforceSaml`, `syncUserRoles`, `signAuthn`, `allowLoginWithDefaults`, `createdAt`, `createdByUserId`, `updatedAt`, `isManagedByFile`.

    Object fields (select subfields): `emailDomainsList`, `roleMappings`.
  </Expandable>
</ResponseField>

<ResponseField name="error" type="String">
  Error message if the operation failed
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation CreateSAMLIdP($input: CreateSAMLIdPInput!) {
    createSAMLIdP(input: $input) {
      idp { id }
      error
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "emailDomainsList": [
        {
          "domain": "<string>"
        }
      ]
    }
  }
  ```
</CodeGroup>

### updateSAMLIdP

Update an existing SAML Identity Provider configuration

`updateSAMLIdP(input: UpdateSAMLIdPInput!): UpdateSAMLIdPPayload`

#### Arguments

<ParamField body="input" type="UpdateSAMLIdPInput!" required>
  <Expandable title="UpdateSAMLIdPInput fields">
    <ParamField body="id" type="ID!" required>
      The ID of the SAML IdP to update
    </ParamField>

    <ParamField body="emailDomainsList" type="[EmailDomainInput!]">
      Email domains that this IdP handles

      <Expandable title="EmailDomainInput fields">
        <ParamField body="id" type="ID">
          Optional ID for the email domain
        </ParamField>

        <ParamField body="domain" type="String!" required>
          The email domain (e.g., example.com)
        </ParamField>

        <ParamField body="validated" type="Boolean">
          Whether the domain has been validated
        </ParamField>
      </Expandable>
    </ParamField>

    <ParamField body="metadataUrl" type="String">
      URL to fetch SAML metadata from
    </ParamField>

    <ParamField body="metadataXml" type="String">
      Raw SAML metadata XML
    </ParamField>

    <ParamField body="defaultOrgId" type="ID">
      Default organization ID for new users
    </ParamField>

    <ParamField body="defaultSpaceId" type="ID">
      Default space ID for new users
    </ParamField>

    <ParamField body="defaultOrgRoleId" type="ID">
      Default organization role ID for new users
    </ParamField>

    <ParamField body="defaultSpaceRoleId" type="ID">
      Default space role ID for new users
    </ParamField>

    <ParamField body="enforceSaml" type="Boolean">
      Whether to enforce SAML authentication for the account
    </ParamField>

    <ParamField body="syncUserRoles" type="Boolean">
      Whether to sync user roles from SAML assertions
    </ParamField>

    <ParamField body="signAuthn" type="Boolean">
      Whether to sign authentication requests
    </ParamField>

    <ParamField body="roleMappings" type="RoleMappingsInput">
      Input for role mappings configuration

      <Expandable title="RoleMappingsInput fields">
        <ParamField body="mappingsList" type="[RoleMappingInput]">
          List of role mappings

          <Expandable title="RoleMappingInput fields">
            <ParamField body="id" type="ID">
              Optional ID for the role mapping
            </ParamField>

            <ParamField body="spaceRolesMap" type="[[String]]">
              Map of space roles as array of \[spaceId, role] tuples matching protobuf format
            </ParamField>

            <ParamField body="spaceRbacRolesMap" type="[[String!]!]">
              Map of RBAC space roles as array of \[spaceId, rbacRoleRelayGlobalId] tuples. Mutually exclusive with spaceRolesMap per mapping.
            </ParamField>

            <ParamField body="projectRolesMap" type="[[String!]!]">
              Map of project RBAC roles as array of \[projectId, rbacRoleRelayGlobalId] tuples. Requires org\_role to be set.
            </ParamField>

            <ParamField body="projectRolesManaged" type="Boolean">
              Whether project role mappings are managed for this role mapping. When false, projectRolesMap is ignored.
            </ParamField>

            <ParamField body="attributesMap" type="[[String]]">
              Map of attributes as array of \[key, value] tuples matching protobuf format
            </ParamField>

            <ParamField body="isAccountAdmin" type="Boolean">
              Whether the user is an account admin
            </ParamField>

            <ParamField body="orgRole" type="OrgRoleInput">
              Organization role with orgId and roleId Nested `OrgRoleInput` (same shape as above).
            </ParamField>

            <ParamField body="developerAccess" type="Boolean">
              Ignored. Developer access is derived from the assigned Account role. **Deprecated:** Developer access is derived from the assigned Account role.
            </ParamField>
          </Expandable>
        </ParamField>
      </Expandable>
    </ParamField>

    <ParamField body="allowLoginWithDefaults" type="Boolean">
      Whether to allow login with default roles
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="idp" type="SAMLIdP">
  The updated SAML IdP configuration

  <Expandable title="SAMLIdP fields">
    Scalar fields: `id`, `accountId`, `metadataUrl`, `metadataXml`, `defaultOrgId`, `defaultSpaceId`, `defaultOrgRoleId`, `defaultSpaceRoleId`, `enforceSaml`, `syncUserRoles`, `signAuthn`, `allowLoginWithDefaults`, `createdAt`, `createdByUserId`, `updatedAt`, `isManagedByFile`.

    Object fields (select subfields): `emailDomainsList`, `roleMappings`.
  </Expandable>
</ResponseField>

<ResponseField name="error" type="String">
  Error message if the operation failed
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation UpdateSAMLIdP($input: UpdateSAMLIdPInput!) {
    updateSAMLIdP(input: $input) {
      idp { id }
      error
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "id": "<ID>"
    }
  }
  ```
</CodeGroup>

### addSAMLRoleMapping

Add a single role mapping to a SAML Identity Provider without touching its other role mappings. Rejected if a mapping with identical SAML attributes and organization already exists.

`addSAMLRoleMapping(input: AddSAMLRoleMappingInput!): AddSAMLRoleMappingPayload`

#### Arguments

<ParamField body="input" type="AddSAMLRoleMappingInput!" required>
  <Expandable title="AddSAMLRoleMappingInput fields">
    <ParamField body="id" type="ID!" required>
      The ID of the SAML IdP to update
    </ParamField>

    <ParamField body="mapping" type="RoleMappingInput!" required>
      The role mapping to add

      <Expandable title="RoleMappingInput fields">
        <ParamField body="id" type="ID">
          Optional ID for the role mapping
        </ParamField>

        <ParamField body="spaceRolesMap" type="[[String]]">
          Map of space roles as array of \[spaceId, role] tuples matching protobuf format
        </ParamField>

        <ParamField body="spaceRbacRolesMap" type="[[String!]!]">
          Map of RBAC space roles as array of \[spaceId, rbacRoleRelayGlobalId] tuples. Mutually exclusive with spaceRolesMap per mapping.
        </ParamField>

        <ParamField body="projectRolesMap" type="[[String!]!]">
          Map of project RBAC roles as array of \[projectId, rbacRoleRelayGlobalId] tuples. Requires org\_role to be set.
        </ParamField>

        <ParamField body="projectRolesManaged" type="Boolean">
          Whether project role mappings are managed for this role mapping. When false, projectRolesMap is ignored.
        </ParamField>

        <ParamField body="attributesMap" type="[[String]]">
          Map of attributes as array of \[key, value] tuples matching protobuf format
        </ParamField>

        <ParamField body="isAccountAdmin" type="Boolean">
          Whether the user is an account admin
        </ParamField>

        <ParamField body="orgRole" type="OrgRoleInput">
          Organization role with orgId and roleId

          <Expandable title="OrgRoleInput fields">
            <ParamField body="orgId" type="ID">
              Organization ID
            </ParamField>

            <ParamField body="roleId" type="ID">
              Role ID
            </ParamField>
          </Expandable>
        </ParamField>

        <ParamField body="developerAccess" type="Boolean">
          Ignored. Developer access is derived from the assigned Account role. **Deprecated:** Developer access is derived from the assigned Account role.
        </ParamField>
      </Expandable>
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="idp" type="SAMLIdP">
  The updated SAML IdP configuration

  <Expandable title="SAMLIdP fields">
    Scalar fields: `id`, `accountId`, `metadataUrl`, `metadataXml`, `defaultOrgId`, `defaultSpaceId`, `defaultOrgRoleId`, `defaultSpaceRoleId`, `enforceSaml`, `syncUserRoles`, `signAuthn`, `allowLoginWithDefaults`, `createdAt`, `createdByUserId`, `updatedAt`, `isManagedByFile`.

    Object fields (select subfields): `emailDomainsList`, `roleMappings`.
  </Expandable>
</ResponseField>

<ResponseField name="error" type="String">
  Error message if the operation failed
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation AddSAMLRoleMapping($input: AddSAMLRoleMappingInput!) {
    addSAMLRoleMapping(input: $input) {
      idp { id }
      error
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "id": "<ID>",
      "mapping": {}
    }
  }
  ```
</CodeGroup>

### createExporterAuditLog

Create an exporter audit log

`createExporterAuditLog(input: CreateExporterAuditLogInput!): CreateExporterAuditLogPayload`

#### Arguments

<ParamField body="input" type="CreateExporterAuditLogInput!" required>
  <Expandable title="CreateExporterAuditLogInput fields">
    <ParamField body="datasetUuid" type="ID!" required>
      The uuid of the model to create the audit log for
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="logged" type="Boolean!">
  Whether or not the exporter audit log was successfully logged. False if logging is not enabled for the account.
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation CreateExporterAuditLog($input: CreateExporterAuditLogInput!) {
    createExporterAuditLog(input: $input) {
      logged
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "datasetUuid": "<ID>"
    }
  }
  ```
</CodeGroup>

### setSpaceGateLimit

Set a rate limit gate value for a space. A value of 0 blocks all ingestion.

`setSpaceGateLimit(input: SetSpaceGateLimitMutationInput!): SetSpaceGateLimitMutationPayload`

#### Arguments

<ParamField body="input" type="SetSpaceGateLimitMutationInput!" required>
  <Expandable title="SetSpaceGateLimitMutationInput fields">
    <ParamField body="spaceId" type="ID!" required>
      The ID of the space to set the gate limit for
    </ParamField>

    <ParamField body="gateType" type="TierGate!" required>
      The gate type to set the limit for One of: `workspaces`, `organizations`, `prodPredictions`, `preProdPredictions`, `activeModels`, `features`, `dataSize`.
    </ParamField>

    <ParamField body="limitValue" type="Float!" required>
      The limit value to set. 0 blocks all ingestion; positive values cap usage.
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="space" type="Space">
  <Expandable title="Space fields">
    Scalar fields: `id`, `name`, `description`, `uuid`, `createdAt`, `liveEnabled`, `isLLMOnlySpace`, `playgroundTracingModelId`, `evalTracingModelId`, `sandboxTracingModelId`, `mlModelsEnabled`, `private`, `gradientStartColor`, `gradientEndColor`, `hasDashboardsCreated`.

    Object fields (select subfields): `organization`, `models`, `monitors`, `dashboards`, `spaceUsers`, `byobConnectors`, `importJobs`, `tableJobs`, `sandboxJobs`, `signalInsightSummary`, `signalEnabledProjectSummary`, `signalIssues`, `agentIssues`, `automations`, `datasets`, `experiments`, `customMetrics`, `onlineTasks`, `prompts`, `tags`, `evaluators`, `annotationQueues`, `playgroundViews`, `annotationConfigs`, `traceFilters`, `llmIntegrations`, `defaultLlmIntegration`, `defaultAgentRuntime`, `gates`, `_access`.
  </Expandable>
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation SetSpaceGateLimit($input: SetSpaceGateLimitMutationInput!) {
    setSpaceGateLimit(input: $input) {
      space { id name }
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "spaceId": "<ID>",
      "gateType": "workspaces",
      "limitValue": 1
    }
  }
  ```
</CodeGroup>

### deleteSpaceGateLimit

Remove a rate limit gate from a space, resetting it to no limit.

`deleteSpaceGateLimit(input: DeleteSpaceGateLimitMutationInput!): DeleteSpaceGateLimitMutationPayload`

#### Arguments

<ParamField body="input" type="DeleteSpaceGateLimitMutationInput!" required>
  <Expandable title="DeleteSpaceGateLimitMutationInput fields">
    <ParamField body="spaceId" type="ID!" required>
      The ID of the space to remove the gate limit from
    </ParamField>

    <ParamField body="gateType" type="TierGate!" required>
      The gate type to remove One of: `workspaces`, `organizations`, `prodPredictions`, `preProdPredictions`, `activeModels`, `features`, `dataSize`.
    </ParamField>

    <ParamField body="clientMutationId" type="String" />
  </Expandable>
</ParamField>

#### Returns

<ResponseField name="space" type="Space">
  <Expandable title="Space fields">
    Scalar fields: `id`, `name`, `description`, `uuid`, `createdAt`, `liveEnabled`, `isLLMOnlySpace`, `playgroundTracingModelId`, `evalTracingModelId`, `sandboxTracingModelId`, `mlModelsEnabled`, `private`, `gradientStartColor`, `gradientEndColor`, `hasDashboardsCreated`.

    Object fields (select subfields): `organization`, `models`, `monitors`, `dashboards`, `spaceUsers`, `byobConnectors`, `importJobs`, `tableJobs`, `sandboxJobs`, `signalInsightSummary`, `signalEnabledProjectSummary`, `signalIssues`, `agentIssues`, `automations`, `datasets`, `experiments`, `customMetrics`, `onlineTasks`, `prompts`, `tags`, `evaluators`, `annotationQueues`, `playgroundViews`, `annotationConfigs`, `traceFilters`, `llmIntegrations`, `defaultLlmIntegration`, `defaultAgentRuntime`, `gates`, `_access`.
  </Expandable>
</ResponseField>

#### Example

Only required input fields are shown. Replace `<ID>` and `<string>` placeholders with real values; the [object graph](/docs/ax/graphql-reference/queries/object-graph) page shows how to look IDs up.

<CodeGroup>
  ```graphql Mutation theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  mutation DeleteSpaceGateLimit($input: DeleteSpaceGateLimitMutationInput!) {
    deleteSpaceGateLimit(input: $input) {
      space { id name }
    }
  }
  ```

  ```json Variables theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
  {
    "input": {
      "spaceId": "<ID>",
      "gateType": "workspaces"
    }
  }
  ```
</CodeGroup>
