Skip to content

Label many nodes at once — the operation that makes tagging usable at all.

POST
/api/v1/nodes/tags
curl --request POST \
--url https://example.com/api/v1/nodes/tags \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "add": [ "example" ], "node_ids": [ "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0" ], "remove": [ "example" ] }'

🚨 This MERGES; it does not replace. The caller picked rows in the inventory tree and knows one label it wants on all of them; it has no idea what else each of them carries. A replacing bulk write would silently wipe every other label on every selected node (PUT /nodes/{id}/bindings replaces, and that is correct there because the dialog shows the whole map).

⚠️ Scoped via Scoped, not Admin alone. manage_config is held by Operator, and an Operator can be group-scoped, so a bulk write that skipped the scope would let one site’s operator relabel another’s. This is the shape POST /nodes/move chose deliberately (ADR-124 decision 8). The single-node writes took VisibleNode later: their old ADMIN_CFG claim let a scoped caller write any node by id (ADR-158 A8).

Media typeapplication/json

Add and/or remove tags across many nodes at once (ADR-135).

object
add

Labels to add to every named node. One a node already carries is a no-op, and one not named here is left alone. Same validation as the single-node edit.

⚠️ Adds to each node’s own labels. A label a node inherits from its folder is not touched by this, and cannot be removed by it.

Array<string>
node_ids
required
Array<string>
remove

Labels to take off every named node. One a node does not carry is not an error.

⚠️ Not length- or character-checked, for the reason normalized_removals records: a label already stored may predate the rules that now apply to new ones.

Array<string>
Examplegenerated
{
"add": [
"example"
],
"node_ids": [
"2489E9AD-2EE2-8E00-8EC9-32D5F69181C0"
],
"remove": [
"example"
]
}

How many of the named nodes were relabelled

Media typeapplication/json

What a bulk tag edit actually did.

object
applied
required

Rows that were actually written. Lower than requested is normal: an id can name a node that has since been deleted, or one outside the caller’s scope. The two are not distinguished — saying which would confirm that a node the caller may not see exists.

integer format: int64
requested
required

Distinct ids the request named, after de-duplication.

integer
Examplegenerated
{
"applied": 1,
"requested": 1
}

An illegal tag key or value, or more ids than one request may carry

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

No valid bearer token

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

Role lacks ManageConfig

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}

This deployment has no write side (skeleton mode)

Media typeapplication/json

The ADR-019 envelope every failure renders as. pub(crate) and schema-bearing so the OpenAPI document can name one error shape for every endpoint (ADR-035) instead of leaving 4xx/5xx bodies undescribed — a client that has to guess the failure shape ends up parsing the success shape and reading undefined.

object
error
required
object
code
required

Stable machine-readable code. Clients branch on this, never on the message.

string
message
required

Operator-facing sentence. Safe to display; never carries an internal error’s own text.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example"
}
}