---
title: "Update a Group Mapping"
method: PATCH
path: "/iam/v2/sso/group-mappings/{id}"
tags: ["Group Mappings (iam/v2/sso)"]
---

# Update a Group Mapping

`PATCH /iam/v2/sso/group-mappings/{id}`

[![General Availability](https://img.shields.io/badge/Lifecycle%20Stage-General%20Availability-%2345c6e8)](#section/Versioning/API-Lifecycle-Policy)

Make a request to update a group mapping.

## Path parameters

- `id` string, required

## Request body

- IamV2SsoGroupMapping — `GroupMapping` objects establish relationships between user groups in your SSO identity provider and specific RBAC roles in Confluent Cloud. Group mappings enable automated and secure access control to Confluent Cloud resources, reducing administrative workload by streamlining user provisioning and authorization. Related guide: [Use group mappings with your SSO identity provider](https://docs.confluent.io/cloud/current/access-management/authenticate/sso/group-mapping/overview.html). ## The Group Mappings Model <SchemaDefinition schemaRef="#/components/schemas/iam.v2.sso.GroupMapping" /> ## Quotas and Limits This resource is subject to the [following quotas](https://docs.confluent.io/cloud/current/quotas/overview.html): | Quota | Description | | --- | --- | | `group_mappings_per_org` | Number of group mappings per organization |
  - `api_version` 'iam.v2/sso' — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'GroupMapping' — Kind defines the object this REST resource represents.
  - `id` string — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
  - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
    - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
    - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
    - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
    - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
    - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
  - `display_name` string — The name of the group mapping.
  - `description` string — A description explaining the purpose and use of the group mapping.
  - `filter` string — A single group identifier or a condition based on [supported CEL operators](https://docs.confluent.io/cloud/current/access-management/authenticate/sso/group-mapping/overview.html#supported-cel-operators-for-group-mapping) that defines which groups are included.
  - `principal` string — The unique federated identity associated with this group mapping.
  - `state` string — The current state of the group mapping.

## Response `200`

Group Mapping.

- object — `GroupMapping` objects establish relationships between user groups in your SSO identity provider and specific RBAC roles in Confluent Cloud. Group mappings enable automated and secure access control to Confluent Cloud resources, reducing administrative workload by streamlining user provisioning and authorization. Related guide: [Use group mappings with your SSO identity provider](https://docs.confluent.io/cloud/current/access-management/authenticate/sso/group-mapping/overview.html). ## The Group Mappings Model <SchemaDefinition schemaRef="#/components/schemas/iam.v2.sso.GroupMapping" /> ## Quotas and Limits This resource is subject to the [following quotas](https://docs.confluent.io/cloud/current/quotas/overview.html): | Quota | Description | | --- | --- | | `group_mappings_per_org` | Number of group mappings per organization |
  - `api_version` 'iam.v2/sso', required — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'GroupMapping', required — Kind defines the object this REST resource represents.
  - `id` string, required — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
  - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
    - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
    - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
    - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
    - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
    - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
  - `display_name` string, required — The name of the group mapping.
  - `description` string, required — A description explaining the purpose and use of the group mapping.
  - `filter` string, required — A single group identifier or a condition based on [supported CEL operators](https://docs.confluent.io/cloud/current/access-management/authenticate/sso/group-mapping/overview.html#supported-cel-operators-for-group-mapping) that defines which groups are included.
  - `principal` string, required — The unique federated identity associated with this group mapping.
  - `state` string, required — The current state of the group mapping.

## Other responses

- `400` — Bad Request
- `401` — The request lacks valid authentication credentials for this resource.
- `402` — The request would exceed one or more quotas.
- `403` — The access credentials were considered insufficient to grant access
- `404` — Not Found
- `409` — The request is in conflict with the current server state
- `422` — Validation Failed
- `429` — Rate Limit Exceeded
- `500` — Oops, something went wrong!

---

[API](https://skmtc.dev/confluent/apis/confluent-cloud-apis.md) · [All operations](https://skmtc.dev/confluent/apis/confluent-cloud-apis/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/confluent/confluent-cloud-apis/revisions/a6a73f98a698/schema)
