Replace an issue's assignees.
A whole-list replace, not an add: {"assignees": []} clears everyone. (The
older single assigned_to string is still accepted — a string becomes a
one-element list, null clears — and is ignored when assignees is
present.) Every address must belong to an active member of your
organization; a typo or an outsider is rejected 422 before anything is
written, so the call never half-applies.
The permission check is on the DIFF, not on the request. With issues:read
you may take YOURSELF off the list, or send a no-op; adding anybody, or
removing somebody else, needs issues:create and is otherwise 403. Everyone
left on the list, plus you, is subscribed to the thread.
Authorizations
A scoped AgentEye API key. Mint one in the dashboard under Settings → API keys, or with POST /v1/keys. Each endpoint names the permission it requires; a key without it gets 403 and a required_permission field naming what was missing.
Path Parameters
The issue's id.
Body
Legacy single-assignee shape. Kept so older API callers (the
PR-1 collector hook + any external scripts) don't break the day
the dashboard rolls forward. null clears, a string is treated
as a one-element list. Ignored when assignees is present.
Replacement assignee list. Empty array (or omitted) clears everyone. Preferred shape going forward.
Response
Assignees replaced; returns the stored list.

