> ## Documentation Index
> Fetch the complete documentation index at: https://docs.app.strix.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Re-scope a chat to verified domains

> Replaces the verified organization domains a chat is authorized against, including while it is running: the domains are re-validated (owned, verified, inside the caller's access scopes), persisted, and pushed to the running agent, which re-labels proxy traffic and is told its scope changed. An empty list restores organization-wide authorization.



## OpenAPI

````yaml /openapi.json put /chat/{chatId}/domains
openapi: 3.1.0
info:
  title: Strix API
  version: 1.0.0
  description: >-
    Public REST API for the Strix autonomous penetration testing platform.
    Manage scans, vulnerabilities, assets, schedules, API tokens, and webhooks.
servers:
  - url: /api/v1
    description: Strix v1 API
security:
  - BearerAuth: []
tags:
  - name: Scans
    description: Launch, monitor, and manage security scans.
  - name: Vulnerabilities
    description: View and triage discovered vulnerabilities.
  - name: Assets
    description: Domains and repositories registered for scanning.
  - name: Schedules
    description: Recurring scan schedules (Pro plan).
  - name: Tokens
    description: Manage API tokens for authentication.
  - name: Webhooks
    description: Configure webhook subscriptions for real-time event notifications.
  - name: Organization
    description: Workspace configuration for the authenticated organization.
  - name: Members
    description: Manage organization members and roles.
  - name: Invitations
    description: List and revoke organization invitations.
  - name: PR Reviews
    description: Automated security review of pull requests.
  - name: Connectors
    description: Network connectors for scanning internal/private targets.
  - name: Knowledge
    description: >-
      Organization knowledge base: documents, policies, and repo profiles that
      steer the agent.
  - name: Uploads
    description: Upload source/code/documentation archives for whitebox scans.
  - name: Integrations
    description: Third-party integrations (GitLab, Bitbucket, ticketing).
  - name: Chat
    description: Conversational agent sessions.
  - name: Analytics
    description: Aggregate dashboard analytics.
  - name: Test Users
    description: >-
      Per-domain test accounts (with optional MFA) the agent authenticates as
      during scans.
  - name: License
    description: Self-hosted license state, entitlements, and aggregate usage.
  - name: Supply Chain
    description: >-
      SBOM inventory, supply-chain findings, scans, and policy for connected
      repositories.
paths:
  /chat/{chatId}/domains:
    put:
      tags:
        - Chat
      summary: Re-scope a chat to verified domains
      description: >-
        Replaces the verified organization domains a chat is authorized against,
        including while it is running: the domains are re-validated (owned,
        verified, inside the caller's access scopes), persisted, and pushed to
        the running agent, which re-labels proxy traffic and is told its scope
        changed. An empty list restores organization-wide authorization.
      operationId: updateChatDomainScope
      parameters:
        - name: chatId
          in: path
          required: true
          description: Chat id.
          schema:
            type: string
            format: uuid
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                domain_ids:
                  type: array
                  items:
                    type: string
                    format: uuid
                  description: >-
                    Verified organization domain ids. Empty restores
                    organization-wide authorization.
      responses:
        '200':
          description: The chat's new scope.
          content:
            application/json:
              schema:
                type: object
                properties:
                  scoped_domains:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                        domain:
                          type: string
                  delivered:
                    type: boolean
                    description: Whether the running sandbox acknowledged the new scope.
        '400':
          description: A domain is unknown, unverified or out of the caller's access scope.
        '403':
          description: Insufficient role or scope.
        '404':
          description: Chat not found.
      security:
        - BearerAuth:
            - chat:write
components:
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        API token obtained from the Tokens endpoint. Include as `Authorization:
        Bearer <token>`.

````