Преминете към основното съдържание

Entrosity Hub API (0.1.0)

Download OpenAPI specification:Download

Identity and access for all Entrosity products: sign-in, sessions, two-factor authentication, organizations, members, product access and platform administration. This file is the source of truth for the platform server interfaces (oapi-codegen), request validation, and the platform web app's types (openapi-typescript). Run make gen after editing.

Authentication: Authorization: Bearer <access token> (15 min JWT, audience platform). The refresh token lives in the httpOnly cookie platform_rt scoped to /api/platform/v1/auth and is rotated on every /auth/refresh. Cookie-authenticated routes (/auth/refresh, /auth/logout, /auth/product-token) only accept same-origin requests with a JSON body.

Products (e.g. Entrosity Axis at /axis) do not accept platform access tokens: the browser exchanges the session cookie for a short-lived product token (POST /auth/product-token), signed with Ed25519 and verifiable with the keys at /.well-known/jwks.json. Product tokens carry no roles; products read roles from their own copy of the access data, which they pull from the platform's internal API (not served here).

Every route's access rule (public, authenticated, organization admin, platform admin) is declared in platform/backend/internal/http/access.go and enforced before the handler runs. Requests for another organization's resources return 404.

system

Liveness probe

Responses

Response samples

Content type
application/json
{
  • "status": "ok"
}

Public keys that verify product and step-up tokens (Ed25519)

Responses

Response samples

Content type
application/json
{
  • "keys": [
    ]
}

auth

Sign in with e-mail and password (and TOTP code when enabled)

Request Body schema: application/json
required
email
required
string [ 3 .. 254 ] characters
password
required
string [ 1 .. 256 ] characters
totp_code
string <= 16 characters

6-digit code or a recovery code.

Responses

Request samples

Content type
application/json
{
  • "email": "string",
  • "password": "string",
  • "totp_code": "string"
}

Response samples

Content type
application/json
{
  • "access_token": "string",
  • "expires_in": 0,
  • "user": {
    }
}

Exchange the session cookie for a new access token (rotates the cookie)

cookie Parameters
platform_rt
string <= 128 characters

Responses

Response samples

Content type
application/json
{
  • "access_token": "string",
  • "expires_in": 0,
  • "user": {
    }
}

End the session and clear the session cookie

cookie Parameters
platform_rt
string <= 128 characters

Responses

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

Short-lived token for a product (e.g. RMM), from the session cookie

Returns a 5-minute Ed25519-signed JWT with audience = the product id. It never rotates or revokes the session cookie, so it can run while another tab refreshes. 401 without a valid session; 403 no_product_access when the user has no role in the product; 403 totp_setup_required when an organization of the user requires two-factor authentication and it is not enabled.

cookie Parameters
platform_rt
string <= 128 characters
Request Body schema: application/json
required
product
required
string (ProductID) ^[a-z][a-z0-9-]{1,30}$

Responses

Request samples

Content type
application/json
{
  • "product": "rmm"
}

Response samples

Content type
application/json
{
  • "token": "string",
  • "expires_in": 0
}

Confirm the password for a sensitive product action (2-minute, single-use token)

For actions a product protects with the password (e.g. deleting an RMM enrollment token). Authenticated by the session cookie, like product tokens, so product web apps can ask for it. The token is bound to the session and can be used once. A wrong password is a 422 on password; 401 without a valid session. Rate-limited like sign-in.

cookie Parameters
platform_rt
string <= 128 characters
Request Body schema: application/json
required
product
required
string (ProductID) ^[a-z][a-z0-9-]{1,30}$
password
required
string [ 1 .. 256 ] characters

Responses

Request samples

Content type
application/json
{
  • "product": "rmm",
  • "password": "string"
}

Response samples

Content type
application/json
{
  • "token": "string",
  • "expires_in": 0
}

E-mail a password reset link (always 202)

Request Body schema: application/json
required
email
required
string [ 3 .. 254 ] characters

Responses

Request samples

Content type
application/json
{
  • "email": "string"
}

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

Set a new password with a reset token (signs out all sessions)

Request Body schema: application/json
required
token
required
string [ 20 .. 128 ] characters
new_password
required
string [ 1 .. 256 ] characters

Responses

Request samples

Content type
application/json
{
  • "token": "stringstringstringst",
  • "new_password": "string"
}

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

Change the signed-in user's password (other sessions are signed out)

Requires the current password. The calling session stays signed in; all other sessions of the user are signed out. A wrong current password or a weak new one is a 422 naming the field (current_password, new_password). Rate-limited like sign-in.

Authorizations:
bearerAuth
Request Body schema: application/json
required
current_password
required
string [ 1 .. 256 ] characters
new_password
required
string [ 1 .. 256 ] characters

Responses

Request samples

Content type
application/json
{
  • "current_password": "string",
  • "new_password": "string"
}

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

Apply an e-mail change with the link's token (signs out all sessions)

The token comes from the link e-mailed to the new address by POST /me/email. The old address is told about the change. An unknown, used or expired token is a 400 invalid_token; an address taken by another account since the request is a 422 on new_email.

Request Body schema: application/json
required
token
required
string [ 20 .. 128 ] characters

Responses

Request samples

Content type
application/json
{
  • "token": "stringstringstringst"
}

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

Start enrolling an authenticator app

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "secret": "string",
  • "otpauth_url": "string",
  • "qr_svg": "string"
}

Confirm the authenticator with a code; enables 2FA and returns recovery codes

Authorizations:
bearerAuth
Request Body schema: application/json
required
code
required
string = 6 characters ^[0-9]{6}$

Responses

Request samples

Content type
application/json
{
  • "code": "string"
}

Response samples

Content type
application/json
{
  • "recovery_codes": [
    ]
}

Disable 2FA (requires the password; refused while an organization requires it)

Authorizations:
bearerAuth
Request Body schema: application/json
required
password
required
string [ 1 .. 256 ] characters

Responses

Request samples

Content type
application/json
{
  • "password": "string"
}

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

Public details of an open invitation

path Parameters
token
required
string [ 20 .. 128 ] characters

Responses

Response samples

Content type
application/json
{
  • "email": "string",
  • "organization_name": "string",
  • "platform_admin": true,
  • "existing_account": true,
  • "expires_at": "2019-08-24T14:15:22Z"
}

Accept an invitation (creates the account, or adds access to the signed-in account)

For a new e-mail address, display_name and password are required and the response signs the new user in. For an address that already has an account, the caller must be signed in as that account (bearer token); the invitation's access is added and the current session is returned. Signed in as another account: 409 invitation_other_account.

Authorizations:
NonebearerAuth
path Parameters
token
required
string [ 20 .. 128 ] characters
Request Body schema: application/json
required
display_name
string [ 1 .. 200 ] characters
password
string [ 1 .. 256 ] characters

Responses

Request samples

Content type
application/json
{
  • "display_name": "string",
  • "password": "string"
}

Response samples

Content type
application/json
{
  • "access_token": "string",
  • "expires_in": 0,
  • "user": {
    }
}

me

The signed-in user

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "email": "string",
  • "display_name": "string",
  • "status": "active",
  • "is_platform_admin": true,
  • "totp_enabled": true,
  • "totp_required": true,
  • "last_login_at": "2019-08-24T14:15:22Z",
  • "created_at": "2019-08-24T14:15:22Z"
}

Change my display name

Authorizations:
bearerAuth
Request Body schema: application/json
required
display_name
required
string [ 1 .. 200 ] characters

Responses

Request samples

Content type
application/json
{
  • "display_name": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "email": "string",
  • "display_name": "string",
  • "status": "active",
  • "is_platform_admin": true,
  • "totp_enabled": true,
  • "totp_required": true,
  • "last_login_at": "2019-08-24T14:15:22Z",
  • "created_at": "2019-08-24T14:15:22Z"
}

Ask to change my e-mail (a confirmation link goes to the new address)

Requires the current password. Nothing changes until the link is opened; only the newest link works. A wrong password or an invalid, unchanged or taken address is a 422 naming the field (current_password, new_email). Rate-limited like sign-in.

Authorizations:
bearerAuth
Request Body schema: application/json
required
current_password
required
string [ 1 .. 256 ] characters
new_email
required
string [ 3 .. 254 ] characters

Responses

Request samples

Content type
application/json
{
  • "current_password": "string",
  • "new_email": "string"
}

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

My signed-in sessions (browsers)

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "items": [
    ]
}

Sign out one of my sessions

Authorizations:
bearerAuth
path Parameters
sessionID
required
string <uuid>

Responses

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

The products I can open, per organization (the launcher)

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "items": [
    ]
}

The organizations I belong to, with my roles

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "items": [
    ]
}

Products and their roles (for role pickers)

Products in beta are listed to platform admins only.

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "items": [
    ]
}

organizations

An organization I administer

Authorizations:
bearerAuth
path Parameters
orgID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "slug": "string",
  • "status": "active",
  • "settings": {
    },
  • "products": [
    ],
  • "member_count": 0,
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z"
}

Audit log of one organization (its admins and platform admins)

Authorizations:
bearerAuth
path Parameters
orgID
required
string <uuid>
query Parameters
page
integer [ 1 .. 100000 ]
Default: 1
page_size
integer [ 1 .. 200 ]
Default: 50
actor_user_id
string <uuid>
action
string <= 100 characters
from
string <date-time>
to
string <date-time>

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "page": 0,
  • "page_size": 0,
  • "total": 0
}

Members and open invitations of an organization

Authorizations:
bearerAuth
path Parameters
orgID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "members": [
    ],
  • "invitations": [
    ]
}

Change a member's organization role or product roles

product_roles replaces all product roles of the member in this organization; only products enabled for the organization are accepted. Demoting the last organization admin is a 409 last_org_admin.

Authorizations:
bearerAuth
path Parameters
orgID
required
string <uuid>
userID
required
string <uuid>
Request Body schema: application/json
required
org_role
string (OrgRole)
Enum: "admin" "member"

admin manages the organization's members and their product roles.

Array of objects (ProductRole) <= 20 items

Responses

Request samples

Content type
application/json
{
  • "org_role": "admin",
  • "product_roles": [
    ]
}

Response samples

Content type
application/json
{
  • "user": {
    },
  • "org_role": "admin",
  • "product_roles": [
    ],
  • "joined_at": "2019-08-24T14:15:22Z"
}

Remove a member from the organization (the account stays)

Authorizations:
bearerAuth
path Parameters
orgID
required
string <uuid>
userID
required
string <uuid>

Responses

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

Invite someone to the organization (e-mail, organization role, product roles)

Authorizations:
bearerAuth
path Parameters
orgID
required
string <uuid>
Request Body schema: application/json
required
email
required
string [ 3 .. 254 ] characters
org_role
required
string (OrgRole)
Enum: "admin" "member"

admin manages the organization's members and their product roles.

required
Array of objects (ProductRole) <= 20 items

Responses

Request samples

Content type
application/json
{
  • "email": "string",
  • "org_role": "admin",
  • "product_roles": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "email": "string",
  • "organization": {
    },
  • "org_role": "admin",
  • "product_roles": [
    ],
  • "platform_admin": true,
  • "invited_by": "0fdabe0c-eb7c-440a-96d2-2c65906c3777",
  • "expires_at": "2019-08-24T14:15:22Z",
  • "created_at": "2019-08-24T14:15:22Z"
}

Revoke an open invitation

Authorizations:
bearerAuth
path Parameters
orgID
required
string <uuid>
invitationID
required
string <uuid>

Responses

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

admin

Put a product in beta (platform admins only) or release it

Authorizations:
bearerAuth
path Parameters
productID
required
string (ProductID) ^[a-z][a-z0-9-]{1,30}$
Example: rmm
Request Body schema: application/json
required
beta
required
boolean

true puts the product in beta (platform admins only).

Responses

Request samples

Content type
application/json
{
  • "beta": true
}

Response samples

Content type
application/json
{
  • "id": "rmm",
  • "name": "Entrosity Axis",
  • "base_path": "/axis",
  • "roles": [
    ],
  • "enabled": true,
  • "beta": true
}

Counters for the platform admin home page

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "users_total": 0,
  • "users_active": 0,
  • "platform_admins": 0,
  • "organizations_total": 0,
  • "organizations_active": 0,
  • "invitations_open": 0,
  • "products": [
    ]
}

All organizations

Authorizations:
bearerAuth
query Parameters
page
integer [ 1 .. 100000 ]
Default: 1
page_size
integer [ 1 .. 200 ]
Default: 50
q
string <= 200 characters
status
string (OrgStatus)
Enum: "active" "suspended"

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "page": 0,
  • "page_size": 0,
  • "total": 0
}

Create an organization, enable products and optionally invite its first admin

Authorizations:
bearerAuth
Request Body schema: application/json
required
name
required
string [ 1 .. 200 ] characters
slug
required
string^[a-z0-9-]{3,40}$
products
Array of strings (ProductID) <= 20 items [ items^[a-z][a-z0-9-]{1,30}$ ]

Products to enable.

object (OrganizationSettings)
admin_email
string [ 3 .. 254 ] characters

Invite this address as the first organization admin, with the most privileged role in every enabled product.

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "slug": "string",
  • "products": [
    ],
  • "settings": {
    },
  • "admin_email": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "slug": "string",
  • "status": "active",
  • "settings": {
    },
  • "products": [
    ],
  • "member_count": 0,
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z"
}

One organization

Authorizations:
bearerAuth
path Parameters
orgID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "slug": "string",
  • "status": "active",
  • "settings": {
    },
  • "products": [
    ],
  • "member_count": 0,
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z"
}

Rename, suspend or reactivate an organization, or change its settings

Authorizations:
bearerAuth
path Parameters
orgID
required
string <uuid>
Request Body schema: application/json
required
name
string [ 1 .. 200 ] characters
status
string (OrgStatus)
Enum: "active" "suspended"
object (OrganizationSettings)

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "status": "active",
  • "settings": {
    }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "slug": "string",
  • "status": "active",
  • "settings": {
    },
  • "products": [
    ],
  • "member_count": 0,
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z"
}

Suspend an organization (members lose access to its products; no data is deleted)

Authorizations:
bearerAuth
path Parameters
orgID
required
string <uuid>

Responses

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

Give an organization access to a product

Authorizations:
bearerAuth
path Parameters
orgID
required
string <uuid>
productID
required
string (ProductID) ^[a-z][a-z0-9-]{1,30}$
Example: rmm

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "slug": "string",
  • "status": "active",
  • "settings": {
    },
  • "products": [
    ],
  • "member_count": 0,
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z"
}

Take a product away from an organization (its members' roles in it are removed)

The product keeps its data for the organization (RMM suspends the tenant); enabling the product again restores access once roles are given again.

Authorizations:
bearerAuth
path Parameters
orgID
required
string <uuid>
productID
required
string (ProductID) ^[a-z][a-z0-9-]{1,30}$
Example: rmm

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "slug": "string",
  • "status": "active",
  • "settings": {
    },
  • "products": [
    ],
  • "member_count": 0,
  • "created_at": "2019-08-24T14:15:22Z",
  • "updated_at": "2019-08-24T14:15:22Z"
}

All users

Authorizations:
bearerAuth
query Parameters
page
integer [ 1 .. 100000 ]
Default: 1
page_size
integer [ 1 .. 200 ]
Default: 50
q
string <= 200 characters
status
string (UserStatus)
Enum: "active" "disabled" "deleted"
organization_id
string <uuid>
platform_admin
boolean

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "page": 0,
  • "page_size": 0,
  • "total": 0
}

One user with all memberships and product roles

Authorizations:
bearerAuth
path Parameters
userID
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "email": "string",
  • "display_name": "string",
  • "status": "active",
  • "is_platform_admin": true,
  • "totp_enabled": true,
  • "last_login_at": "2019-08-24T14:15:22Z",
  • "created_at": "2019-08-24T14:15:22Z",
  • "memberships": [
    ]
}

Change a user's name, status or platform admin flag

Disabling signs the user out everywhere. Guard rails (409): self_change (you cannot disable yourself or drop your own platform admin flag), last_platform_admin.

Authorizations:
bearerAuth
path Parameters
userID
required
string <uuid>
Request Body schema: application/json
required
display_name
string [ 1 .. 200 ] characters
status
string
Enum: "active" "disabled"
is_platform_admin
boolean

Responses

Request samples

Content type
application/json
{
  • "display_name": "string",
  • "status": "active",
  • "is_platform_admin": true
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "email": "string",
  • "display_name": "string",
  • "status": "active",
  • "is_platform_admin": true,
  • "totp_enabled": true,
  • "last_login_at": "2019-08-24T14:15:22Z",
  • "created_at": "2019-08-24T14:15:22Z",
  • "memberships": [
    ]
}

Delete a user (signs out, removes all access; the record is kept for attribution)

Authorizations:
bearerAuth
path Parameters
userID
required
string <uuid>

Responses

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

Replace a user's organization memberships and product roles

The whole list is replaced: organizations missing from it are removed. Product roles must be roles of products enabled for that organization. Removing the last admin of an organization is a 409 last_org_admin.

Authorizations:
bearerAuth
path Parameters
userID
required
string <uuid>
Request Body schema: application/json
required
required
Array of objects (AccessEntry) <= 500 items
Array (<= 500 items)
organization_id
required
string <uuid>
org_role
required
string (OrgRole)
Enum: "admin" "member"

admin manages the organization's members and their product roles.

required
Array of objects (ProductRole) <= 20 items

Responses

Request samples

Content type
application/json
{
  • "memberships": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "email": "string",
  • "display_name": "string",
  • "status": "active",
  • "is_platform_admin": true,
  • "totp_enabled": true,
  • "last_login_at": "2019-08-24T14:15:22Z",
  • "created_at": "2019-08-24T14:15:22Z",
  • "memberships": [
    ]
}

Sign a user out everywhere

Authorizations:
bearerAuth
path Parameters
userID
required
string <uuid>

Responses

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

Reset a user's two-factor authentication, password, or both

two_factor turns two-factor authentication off (the authenticator and recovery codes stop working; the user can set it up again). password replaces the password with one nobody knows and e-mails the user a link, valid for 24 hours, to choose a new one. Either way the user is signed out everywhere. Errors: 422 when neither is chosen; 409 self_reset (use your own account page), user_not_active (a password reset needs an active user), nothing_to_reset (two-factor authentication is not set up).

Authorizations:
bearerAuth
path Parameters
userID
required
string <uuid>
Request Body schema: application/json
required
two_factor
boolean
Default: false

Turn two-factor authentication off.

password
boolean
Default: false

Replace the password and e-mail a link to choose a new one.

Responses

Request samples

Content type
application/json
{
  • "two_factor": false,
  • "password": false
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "email": "string",
  • "display_name": "string",
  • "status": "active",
  • "is_platform_admin": true,
  • "totp_enabled": true,
  • "last_login_at": "2019-08-24T14:15:22Z",
  • "created_at": "2019-08-24T14:15:22Z",
  • "memberships": [
    ]
}

All open invitations

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "items": [
    ]
}

Invite someone (platform admin, and/or to an organization with product roles)

Authorizations:
bearerAuth
Request Body schema: application/json
required
email
required
string [ 3 .. 254 ] characters
platform_admin
boolean
Default: false
organization_id
string <uuid>
org_role
string (OrgRole)
Enum: "admin" "member"

admin manages the organization's members and their product roles.

Array of objects (ProductRole) <= 20 items

Responses

Request samples

Content type
application/json
{
  • "email": "string",
  • "platform_admin": false,
  • "organization_id": "7c60d51f-b44e-4682-87d6-449835ea4de6",
  • "org_role": "admin",
  • "product_roles": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "email": "string",
  • "organization": {
    },
  • "org_role": "admin",
  • "product_roles": [
    ],
  • "platform_admin": true,
  • "invited_by": "0fdabe0c-eb7c-440a-96d2-2c65906c3777",
  • "expires_at": "2019-08-24T14:15:22Z",
  • "created_at": "2019-08-24T14:15:22Z"
}

Revoke an open invitation

Authorizations:
bearerAuth
path Parameters
invitationID
required
string <uuid>

Responses

Response samples

Content type
application/problem+json
{
  • "type": "about:blank",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "code": "string",
  • "instance": "string",
  • "request_id": "string",
  • "fields": {
    }
}

Platform audit log

Authorizations:
bearerAuth
query Parameters
page
integer [ 1 .. 100000 ]
Default: 1
page_size
integer [ 1 .. 200 ]
Default: 50
organization_id
string <uuid>
actor_user_id
string <uuid>
action
string <= 100 characters
from
string <date-time>
to
string <date-time>

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "page": 0,
  • "page_size": 0,
  • "total": 0
}