# Replace workspace delegation

Connect a domain: name the provider (google or microsoft) and the connection_id of the account just picked in the ordinary OAuth chooser; the domain is derived from that address unless a company with several domains says which. service_account_json, subject_email and directory_tenant_id are gone and are refused BY NAME — the service account and the app registration are ours, and nobody pastes a key here. ADMIN AND ENTERPRISE; the seat is checked before the plan, so a broker-plan member hears 403 rather than an invitation to buy.

Access class: `workspace:admin`.

## Endpoint

`PUT /v1/workspace/delegation`

## Request body

Content type: `application/json`.

```json
{
  "body": {
    "connection_id": "",
    "directory_tenant_id": "",
    "domain": "string",
    "provider": "string",
    "service_account_json": "string",
    "subject_email": "string"
  },
  "params": {},
  "query": {}
}
```

## Responses

### 200

the action's answer

Content type: `application/json`.

```json
{
  "data": {
    "created_at": "string",
    "domain": "string",
    "id": "",
    "mailboxes": 1.5,
    "provider": "string",
    "status": "string",
    "status_detail": "string",
    "verified_at": "string"
  }
}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
