> ## Documentation Index
> Fetch the complete documentation index at: https://docs.timeback.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Write organization configuration

> Write semantics per key in the body:
- Key absent: no-op.
- Value `null`: delete the row (revert to inherited / default).
- Value present: upsert. Registered keys are validated; invalid values return 400.



## OpenAPI

````yaml /openapi/learn-with-ai/platform-api.yaml put /rostering/1.0/orgs/{sourcedId}/config
openapi: 3.1.1
info:
  title: TimeBack Platform API
  description: >-
    RESTful API for the TimeBack Platform. Covers authentication, rostering,
    curriculum, insights, assessments, content grading, and more.
  version: 2026.09.10.1
servers:
  - url: https://platform.dev.timeback.com
    description: integration
security: []
tags:
  - name: Auth
    description: Authentication and authorization endpoints
  - name: Organizations
    description: Organizations module contains all endpoints around organization management
  - name: Applications
    description: Applications module contains all endpoints for managing LTI applications
  - name: Users
    description: >-
      Users module contains all endpoints around user creation, update and
      consultation
  - name: Students
    description: Students module contains all endpoints around student management
  - name: Demographics
    description: >-
      Demographics module contains all endpoints around demographics
      consultation
  - name: Consent
    description: >-
      Initiate and query TimeBack parental consent for a student, backed by an
      immutable audit trail.
  - name: Classes
    description: Classes module contains all endpoints around class management
  - name: Courses
    description: Courses module contains all endpoints around course management
  - name: Enrollments
    description: Enrollments module contains all endpoints around enrollment consultation
  - name: CASE
    description: Competency and Academic Standards Exchange (CASE) 1.1 API
  - name: Curriculum
    description: Curriculum module contains endpoints for managing curriculum data
  - name: Competency Track
    description: Competency track endpoints
  - name: Content Grading
    description: >-
      Registration and management of graders for free-response content items —
      bring-your-own external graders (Tier 2) and, once shipped,
      platform-managed grading prompts (Tier 1).
  - name: Caliper
    description: The Caliper module contains all endpoints around Caliper Analytics
  - name: Insights
    description: Coaching insights and session analytics endpoints
paths:
  /rostering/1.0/orgs/{sourcedId}/config:
    put:
      tags:
        - Organizations
      summary: Write organization configuration
      description: >-
        Write semantics per key in the body:

        - Key absent: no-op.

        - Value `null`: delete the row (revert to inherited / default).

        - Value present: upsert. Registered keys are validated; invalid values
        return 400.
      operationId: upsertOrgConfig
      parameters:
        - name: sourcedId
          in: path
          description: Unique identifier of the organization
          required: true
          schema:
            type: string
      requestBody:
        description: Map of config keys to values to upsert or delete (null to delete)
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/OrgConfigInput'
      responses:
        '204':
          description: Configuration updated successfully
        '400':
          $ref: '#/components/responses/BadRequest17'
        '404':
          description: Organization not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/imsxStatusInfoDType11'
              examples:
                default:
                  value:
                    imsx_codeMajor: failure
                    imsx_severity: error
                    imsx_description: Organization not found
                    imsx_CodeMinor:
                      imsx_codeMinorField:
                        - imsx_codeMinorFieldName: sourcedId
                          imsx_codeMinorFieldValue: unknownobject
        '500':
          $ref: '#/components/responses/InternalError16'
      security:
        - CognitoUserPoolAuthorizer:
            - https://purl.imsglobal.org/spec/or/v1p2/scope/roster.createput
components:
  schemas:
    OrgConfigInput:
      type: object
      properties:
        config:
          $ref: '#/components/schemas/OrgConfigInputMap'
      required:
        - config
    imsxStatusInfoDType11:
      description: >
        This is the container for the status code and associated information
        returned within the HTTP messages received from the Service Provider.
        For the OneRoster Rostering service this object will only be returned to
        provide information about a failed request i.e. it will NOT be in the
        payload for a successful request.
      type: object
      required:
        - imsx_codeMajor
        - imsx_severity
      properties:
        imsx_codeMajor:
          description: |
            The code major value (from the corresponding enumerated vocabulary).
          type: string
          enum:
            - success
            - processing
            - failure
            - unsupported
        imsx_severity:
          description: |
            The severity value (from the corresponding enumerated vocabulary).
          type: string
          enum:
            - status
            - warning
            - error
        imsx_description:
          description: >-
            A human readable description supplied by the entity creating the
            status code information.
          type: string
        imsx_CodeMinor:
          $ref: '#/components/schemas/imsxCodeMinorDType11'
      additionalProperties: false
    OrgConfigInputMap:
      type: object
      description: >-
        A flat map of config key → value. `null` deletes the row (reverts to
        inherited / default). Keys not present are untouched. Registered keys
        (above) use their declared types and are Zod-validated. Unregistered
        partner-defined keys are stored as plain text and must be `string` or
        `null`. Keys must be safe identifiers (1–255 chars,
        `^[A-Za-z_][A-Za-z0-9_-]*$`); reserved JS prototype slots are rejected.
        Top-level arrays are rejected.
      properties:
        credentialImportMode:
          type:
            - string
            - 'null'
          enum:
            - enabled
            - disabled
        appStoreEnabled:
          type:
            - boolean
            - 'null'
        consentManagementEnabled:
          type:
            - boolean
            - 'null'
        cameraMicDefault:
          type:
            - string
            - 'null'
          enum:
            - always_on
            - at_school
            - user_choice
            - always_off
        privacyPolicyUrl:
          type:
            - string
            - 'null'
          format: uri
        timeZone:
          type:
            - string
            - 'null'
          description: IANA timezone for coaching day boundaries.
        consentAdminEmail:
          type:
            - string
            - 'null'
          format: email
          description: Parental-consent admin digest recipient.
        consentTemplateId:
          type:
            - string
            - 'null'
          description: DocuSign template id for parental-consent envelopes.
      additionalProperties:
        type:
          - string
          - 'null'
      propertyNames:
        type: string
        minLength: 1
        maxLength: 255
        pattern: ^[A-Za-z_][A-Za-z0-9_-]*$
        not:
          enum:
            - __proto__
            - constructor
            - prototype
    imsxCodeMinorDType11:
      description: >
        This is the container for the set of code minor status codes reported in
        the responses from the Service Provider.
      type: object
      required:
        - imsx_codeMinorField
      properties:
        imsx_codeMinorField:
          description: |
            Each reported code minor status code.
          type: array
          minItems: 1
          items:
            $ref: '#/components/schemas/imsxCodeMinorFieldDType11'
      additionalProperties: false
    imsxCodeMinorFieldDType11:
      description: |
        This is the container for a single code minor status code.
      type: object
      required:
        - imsx_codeMinorFieldName
        - imsx_codeMinorFieldValue
      properties:
        imsx_codeMinorFieldName:
          description: >-
            This should contain the identity of the system that has produced the
            code minor status code report. In most cases this will be the target
            service provider denoted as 'TargetEndSystem'.
          type: string
          default: TargetEndSystem
        imsx_codeMinorFieldValue:
          description: >
            The code minor status code (this is a value from the corresponding
            enumerated vocabulary).
          type: string
          enum:
            - fullsuccess
            - invalid_filter_field
            - invalid_selection_field
            - invaliddata
            - unauthorisedrequest
            - forbidden
            - server_busy
            - unknownobject
            - internal_server_error
      additionalProperties: false
  responses:
    BadRequest17:
      description: Bad request
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/imsxStatusInfoDType11'
          examples:
            invalidData:
              value:
                imsx_codeMajor: failure
                imsx_severity: error
                imsx_description: Invalid data provided
                imsx_CodeMinor:
                  imsx_codeMinorField:
                    - imsx_codeMinorFieldName: TargetEndSystem
                      imsx_codeMinorFieldValue: invaliddata
            invalidFilter:
              value:
                imsx_codeMajor: failure
                imsx_severity: error
                imsx_description: Invalid filter field
                imsx_CodeMinor:
                  imsx_codeMinorField:
                    - imsx_codeMinorFieldName: TargetEndSystem
                      imsx_codeMinorFieldValue: invalid_filter_field
    InternalError16:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/imsxStatusInfoDType11'
          examples:
            default:
              value:
                imsx_codeMajor: failure
                imsx_severity: error
                imsx_description: Internal server error
                imsx_CodeMinor:
                  imsx_codeMinorField:
                    - imsx_codeMinorFieldName: TargetEndSystem
                      imsx_codeMinorFieldValue: internal_server_error
  securitySchemes:
    CognitoUserPoolAuthorizer:
      type: oauth2
      description: >-
        OAuth 2.0 client credentials flow. Contact timeback@trilogy.com to
        request credentials for your application.
      flows:
        clientCredentials:
          tokenUrl: https://platform.dev.timeback.com/auth/1.0/token
          scopes:
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster.readonly: roster readonly
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster-core.readonly: roster-core readonly
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster.createput: roster createput
            https://purl.imsglobal.org/spec/lti/v1p3/scope/lti.readonly: lti readonly
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster-demographics.readonly: roster-demographics readonly
            https://timeback-platform.trilogy.com/consent/scope/consent.write: consent write
            https://timeback-platform.trilogy.com/consent/scope/consent.read: consent read
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster-core.createput: roster-core createput
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster.delete: roster delete
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster-core.delete: roster-core delete
            https://purl.imsglobal.org/spec/case/v1p0/scope/case.readonly: case readonly
            https://purl.imsglobal.org/spec/case/v1p0/scope/case.createput: case createput
            https://purl.imsglobal.org/spec/case/v1p0/scope/case.delete: case delete
            https://timeback-platform.trilogy.com/competency-track/scope/competency-track.readonly: competency-track readonly
            https://timeback-platform.trilogy.com/competency-track/scope/competency-track.write: competency-track write
            https://timeback-platform.trilogy.com/competency-track/scope/competency-track.delete: competency-track delete
            https://timeback-platform.trilogy.com/content/scope/content.write: content write
            https://timeback-platform.trilogy.com/content/scope/content.read: content read
            https://purl.imsglobal.org/spec/caliper/v1p2/scope/events.write: events write
            https://purl.imsglobal.org/spec/caliper/v1p2/scope/events.readonly: events readonly
            https://timeback-platform.trilogy.com/webhooks/scope/webhooks.write: webhooks write
            https://timeback-platform.trilogy.com/webhooks/scope/webhooks.read: webhooks read
            https://timeback-platform.trilogy.com/webhooks/scope/webhooks.delete: webhooks delete

````