> For a complete page index, fetch https://docs.synthflow.ai/llms.txt. For full documentation content, fetch https://docs.synthflow.ai/llms-full.txt.

# Subaccount API: deprecation of permissions object

> Switch to grant_permissions and revoke_permissions before May 5, when PUT Subaccount stops accepting the permissions object.

The legacy `permissions` object in the [**PUT Subaccount**](/api-reference/platform-api/subaccounts/update-subaccount) endpoint is being deprecated and will no longer be supported for permission updates.

**Effective date:** May 5, 2026 (in two weeks)

### What's changing

The current `permissions` object (boolean-based) will be removed from the update flow. Permission updates must instead be made using the new explicit mutation fields:

* `grant_permissions`
* `revoke_permissions`

### Why this change

This update introduces **explicit and unambiguous permission handling**, preventing accidental overwrites and making permission updates safer and more predictable as the permissions model expands.

### What you need to do

If you are currently sending:

```json
{
  "permissions": {
    "assistants": true,
    "actions": false
  }
}
```

You should migrate to:

```json
{
  "grant_permissions": ["assistants"],
  "revoke_permissions": ["actions"]
}
```

### Important notes

* Requests containing the legacy `permissions` object will be **rejected after the effective date**.
* Only `grant_permissions` and `revoke_permissions` will be honored moving forward.
* This change applies specifically to the **PUT Subaccount endpoint**.