During an audit of published items at our division we ran into an issue for assets where the owner was no longer with the company or was not responsive to communication. We could find the URL to get to the published version but struggled to find the underlying asset to make the updates to the publish settings. The solution was to unpublish the items for them, however we found an issue where we could pull a report of all published items but the Asset ID is not viable to find the document. Instead an Item ID is required which is what is included in a URL.
An API can be used to assume the user's role. This allows an admin to share the workspace or asset with themself. To complete the process, you need the asset name, the publisher email, the publish Link and an API Token that is already set up.
Steps
1. Search for the Asset ID
- This gets you the numeric ID that the API needs.
curl -H "Authorization: Bearer TOKEN" -H "Assume-User: user%40email.com" "https://api.smartsheet.com/2.0/search?query=Asset+Name"
- From the response, grab the
objectId for the archived version.
2. Confirm EQBCT Match
- Check that the publish URL matches your tracking sheet.
curl -H "Authorization: Bearer TOKEN" -H "Assume-User: user%40email.com" "https://api.smartsheet.com/2.0/TYPE/ID/publish"
- Replace
TYPE with sheets, reports, or sights. Replace ID with the objectId from Step 1. - Match the EQBCT code in the response URL to the Publish Link in your tracking sheet.
3. Unpublish
- Same URL as Step 2, with -X PUT and the disable payload.
curl -X PUT -H "Authorization: Bearer TOKEN" -H "Assume-User: user%40email.com" -H "Content-Type: application/json" -d "{"readOnlyFullEnabled":false}" "https://api.smartsheet.com/2.0/TYPE/ID/publish"
- Success response: {"message":"SUCCESS","resultCode":0,"result":{"readOnlyFullEnabled":false}}
4. Verify and Mark done.
- Open the original publish link in an incognito browser window. If it shows an error or blank page, it’s unpublished.
Reminders
- %40 instead of @ in emails
- + instead of spaces in search queries
- Always use the archived result from the search
- One space after Bearer then the full token
- Admins cannot impersonate other admins
Troubleshooting
- Error 1004 "Not authorized" — Email not URI-encoded (use %40), or target user is also an admin
- Error 1002 "Invalid token" — Token expired or regenerated. Generate a new one.
- Error 2000 "Invalid username/password" — Token pasted incorrectly. Check for extra spaces or missing characters.
- Search returns no results — Asset may be owned by a different user or named differently. Try broader search terms.