## Update

**patch** `/zones/{zoneId}/groups/{groupId}`

Updates a group's name and/or identifier (partial update). A group's source is immutable. The name of a group synced from an external directory cannot be changed while external sync is enabled for the zone; its identifier can.

### Path Parameters

- `zoneId: string`

- `groupId: string`

### Body Parameters

- `identifier: optional string`

  User-specified identifier, unique within the zone.

- `name: optional string`

  Human-readable group name

### Returns

- `Group = object { id, created_at, external, 7 more }`

  A zone-scoped group of users, assignable to roles and usable in policies. Roles assigned to a group are inherited by its members. `external` is false for groups managed in Keycard and true for groups synced from an external directory.

  - `id: string`

    Unique identifier of the group

  - `created_at: string`

    Entity creation timestamp

  - `external: boolean`

    Whether the group is synced from an external directory. When true the group is directory-owned and its membership is read-only; when false it is managed in Keycard. Read-only: set by external sync, never by the caller.

  - `identifier: string`

    User-specified identifier, unique within the zone. Automatically assigned for groups from an external directory.

  - `name: string`

    Human-readable group name

  - `organization_id: string`

    Organization this group belongs to

  - `updated_at: string`

    Entity update timestamp

  - `zone_id: string`

    Zone this group belongs to

  - `member_count: optional number`

    Number of users in the group. Included only when requested via `expand[]=member_count` (group get or list).

  - `roles: optional array of string`

    Identifiers of the roles assigned to the group; members inherit them. Deduped across scopes. Included only when requested via `expand[]=roles` (group get or list).

### Example

```http
curl https://api.keycard.ai/zones/$ZONE_ID/groups/$GROUP_ID \
    -X PATCH \
    -H "Authorization: Bearer $KEYCARD_API_API_KEY"
```
