directory

25 endpoints.

GET/api/organizations Bearer token

List organizations

Lists every organization in the directory, archived ones included. Requires a valid access token.

Responses

StatusDescriptionBody
200Every organization, ordered by name.array of OrganizationSummary
401The access token is missing or invalid.ErrorResponse
500The directory database could not be read.ErrorResponse
POST/api/organizations Bearer token

Create an organization

Creates a new top-level organization. Requires a superuser's access token.

Request body

application/jsonrequiredCreateOrganizationRequest
FieldTypeRequiredDescription
slugstringyes

Unique across all organizations. Slugs are lowercase letters and digits in words separated by single hyphens, like customer-success.

1–100 characters · matches ^[a-z0-9]+(-[a-z0-9]+)*$

namestringyes

1–200 characters

descriptionstringno

Omit or send empty for no description.

at most 2000 characters

Responses

StatusDescriptionBody
201The created organization.Organization
400The request body failed validation.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token's subject is not a superuser.ErrorResponse
409An organization with that slug already exists.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
PATCH/api/organizations/{organizationId} Bearer token

Update an organization

Changes an organization's slug, name or description; omitted fields keep their values. Requires a superuser's access token, like creating one.

Parameters

NameInTypeRequiredDescription
organizationIdpathstring (uuid)yese.g. 6f3b34d8-3c5e-4dd9-9f4e-2b52f0d9a1c7

Request body

application/jsonrequiredUpdateOrganizationRequest
FieldTypeRequiredDescription
slugstringno

Unique across all organizations. Slugs are lowercase letters and digits in words separated by single hyphens, like customer-success.

1–100 characters · matches ^[a-z0-9]+(-[a-z0-9]+)*$

namestringno

1–200 characters

descriptionstring | nullno

Send null or empty to clear the description.

at most 2000 characters

Responses

StatusDescriptionBody
200The updated organization.Organization
400The request body failed validation.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token's subject is not a superuser.ErrorResponse
404No organization has that id.ErrorResponse
409Another organization already has that slug.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
POST/api/organizations/{organizationId}/departments Bearer token

Create a department

Creates a department in an organization, optionally nested under a parent department in the same organization. Requires a superuser's access token, or one whose subject holds the directory:write permission in a scope covering the parent — the organization for a top-level department, the parent department for a nested one.

Parameters

NameInTypeRequiredDescription
organizationIdpathstring (uuid)yese.g. 6f3b34d8-3c5e-4dd9-9f4e-2b52f0d9a1c7

Request body

application/jsonrequiredCreateDepartmentRequest
FieldTypeRequiredDescription
slugstringyes

Unique within the organization. Slugs are lowercase letters and digits in words separated by single hyphens, like customer-success.

1–100 characters · matches ^[a-z0-9]+(-[a-z0-9]+)*$

namestringyes

1–200 characters

descriptionstringno

Omit or send empty for no description.

at most 2000 characters

parent_department_idstring (uuid)no

Nests the new department under one in the same organization.

Responses

StatusDescriptionBody
201The created department.Department
400The request body failed validation.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token's subject is neither a superuser nor a directory:write holder whose scope covers the parent.ErrorResponse
404The organization does not exist, or the parent department is not in that organization.ErrorResponse
409The organization already has a department with that slug.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
PATCH/api/organizations/{organizationId}/departments/{departmentId} Bearer token

Update a department

Changes a department's slug, name or description, or moves it under another parent in the same organization; omitted fields keep their values. Requires a superuser's access token, or one whose subject holds the directory:write permission in a scope covering the department — and, when moving it, the new parent too.

Parameters

NameInTypeRequiredDescription
organizationIdpathstring (uuid)yese.g. 6f3b34d8-3c5e-4dd9-9f4e-2b52f0d9a1c7
departmentIdpathstring (uuid)yese.g. 0b8f9a3e-97a4-4f2f-b3a3-51f2f8f0f7f4

Request body

application/jsonrequiredUpdateDepartmentRequest
FieldTypeRequiredDescription
slugstringno

Unique within the organization. Slugs are lowercase letters and digits in words separated by single hyphens, like customer-success.

1–100 characters · matches ^[a-z0-9]+(-[a-z0-9]+)*$

namestringno

1–200 characters

descriptionstring | nullno

Send null or empty to clear the description.

at most 2000 characters

parent_department_idstring (uuid) | nullno

Moves the department under another in the same organization — never itself or anything nested beneath it. Send null to make it top level.

Responses

StatusDescriptionBody
200The updated department.Department
400The request body failed validation.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token's subject is neither a superuser nor a directory:write holder whose scope covers the department (and the new parent, when moving it).ErrorResponse
404The organization does not exist, the department is not in that organization, or the new parent is not in that organization.ErrorResponse
409The organization already has a department with that slug, or the move would nest the department beneath itself.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
POST/api/organizations/{organizationId}/departments/{departmentId}/roles Bearer token

Create a department role

Creates a role in a department of an organization, with the permission strings it grants. Requires a superuser's access token, or one whose subject holds the directory:write permission in a scope covering the department.

Parameters

NameInTypeRequiredDescription
organizationIdpathstring (uuid)yese.g. 6f3b34d8-3c5e-4dd9-9f4e-2b52f0d9a1c7
departmentIdpathstring (uuid)yese.g. 0b8f9a3e-97a4-4f2f-b3a3-51f2f8f0f7f4

Request body

application/jsonrequiredCreateDepartmentRoleRequest
FieldTypeRequiredDescription
slugstringyes

Unique within the department. Slugs are lowercase letters and digits in words separated by single hyphens, like customer-success.

1–100 characters · matches ^[a-z0-9]+(-[a-z0-9]+)*$

namestringyes

1–200 characters

descriptionstringno

Omit or send empty for no description.

at most 2000 characters

permissionsarray of stringno

The permissions the role grants, from the set the code understands. Duplicates are collapsed; an empty array grants nothing.

at most 34 items · defaults to []

Responses

StatusDescriptionBody
201The created role.DepartmentRole
400The request body failed validation.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token's subject is neither a superuser nor a directory:write holder whose scope covers the department.ErrorResponse
404The organization does not exist, or the department is not in that organization.ErrorResponse
409The department already has a role with that slug.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
PATCH/api/organizations/{organizationId}/departments/{departmentId}/roles/{roleId} Bearer token

Update a department role

Changes a role's slug, name or description, or replaces the permission set it grants; omitted fields keep their values. Requires a superuser's access token, or one whose subject holds the directory:write permission in a scope covering the department.

Parameters

NameInTypeRequiredDescription
organizationIdpathstring (uuid)yese.g. 6f3b34d8-3c5e-4dd9-9f4e-2b52f0d9a1c7
departmentIdpathstring (uuid)yese.g. 0b8f9a3e-97a4-4f2f-b3a3-51f2f8f0f7f4
roleIdpathstring (uuid)yese.g. 4c1d2f6a-8e0b-45c7-9a92-6d84a4f4c9b1

Request body

application/jsonrequiredUpdateDepartmentRoleRequest
FieldTypeRequiredDescription
slugstringno

Unique within the department. Slugs are lowercase letters and digits in words separated by single hyphens, like customer-success.

1–100 characters · matches ^[a-z0-9]+(-[a-z0-9]+)*$

namestringno

1–200 characters

descriptionstring | nullno

Send null or empty to clear the description.

at most 2000 characters

permissionsarray of stringno

Replaces the whole permission set, from the set the code understands. Duplicates are collapsed; an empty array grants nothing.

at most 34 items

Responses

StatusDescriptionBody
200The updated role.DepartmentRole
400The request body failed validation.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token's subject is neither a superuser nor a directory:write holder whose scope covers the department.ErrorResponse
404The organization does not exist, the department is not in that organization, or the department has no role with that id.ErrorResponse
409The department already has a role with that slug.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
GET/api/organizations/{organizationId}/departments/{departmentId}/roles/{roleId}/permanent-deletion Bearer token

Preview permanently deleting a department role

Counts everything DELETE on this path would remove: the people currently holding the role (who lose every permission it grants), every grant of it on record, the reporting lines it sits on either end of, its certification requirements, and the quiz and learning pathway assignments that reached its holders. Nothing is changed. Requires a superuser's access token, or one whose subject holds directory:delete in a scope covering the department — a grant separate from directory:write, which only edits roles.

Parameters

NameInTypeRequiredDescription
organizationIdpathstring (uuid)yese.g. 6f3b34d8-3c5e-4dd9-9f4e-2b52f0d9a1c7
departmentIdpathstring (uuid)yese.g. 0b8f9a3e-97a4-4f2f-b3a3-51f2f8f0f7f4
roleIdpathstring (uuid)yese.g. 4c1d2f6a-8e0b-45c7-9a92-6d84a4f4c9b1

Responses

StatusDescriptionBody
200What the deletion would take with it.DeletionImpact
401The access token is missing or invalid.ErrorResponse
403The access token's subject is neither a superuser nor a directory:delete holder whose scope covers the department.ErrorResponse
404The organization does not exist, the department is not in that organization, or the department has no role with that id.ErrorResponse
500The directory database could not be read.ErrorResponse
DELETE/api/organizations/{organizationId}/departments/{departmentId}/roles/{roleId}/permanent-deletion Bearer token

Permanently delete a department role

Hard-deletes the role and everything that depends on it. Everyone holding it loses it, and with it every permission it granted; every grant of it on record is deleted, so nothing says who ever held it. Its reporting lines, certification requirements, and quiz and learning pathway assignments go with it; certification awards, learning records and attempts already on record stay. Irreversible — roles have no archive. Preview the cost with GET first. Requires a superuser's access token, or one whose subject holds directory:delete in a scope covering the department — a grant separate from directory:write, which only edits roles.

Parameters

NameInTypeRequiredDescription
organizationIdpathstring (uuid)yese.g. 6f3b34d8-3c5e-4dd9-9f4e-2b52f0d9a1c7
departmentIdpathstring (uuid)yese.g. 0b8f9a3e-97a4-4f2f-b3a3-51f2f8f0f7f4
roleIdpathstring (uuid)yese.g. 4c1d2f6a-8e0b-45c7-9a92-6d84a4f4c9b1

Responses

StatusDescriptionBody
204The role and its dependent rows are gone.—
401The access token is missing or invalid.ErrorResponse
403The access token's subject is neither a superuser nor a directory:delete holder whose scope covers the department.ErrorResponse
404The organization does not exist, the department is not in that organization, or the department has no role with that id.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
POST/api/organizations/{org_id}/users/import Bearer token

Import directory members from a CSV file

Adds every row of an uploaded CSV file to the organization's user directory in one request. The file needs a header row naming a user id, name and email column; rows whose subject is already in the directory are skipped rather than overwritten, so an import can safely be re-run. A file with any invalid row imports nothing and reports the problems, so a corrected file can simply be uploaded again. With `allow_email_only`, rows may name a member by email alone (see the form field). Requires a superuser's access token.

Parameters

NameInTypeRequiredDescription
org_idpathstringyesOrganization UUID id or slug.

Request body

multipart/form-datarequiredDirectoryImportForm
FieldTypeRequiredDescription
provider_idstringyes

Sign-in provider UUID id or slug; every row's user_id is the OIDC `sub` claim the member will present at this provider.

at least 1 character

allow_email_onlystringno

Set true to accept rows with a blank (or absent) user_id and an email: each resolves to the account a pending email link or a single live profile email already names, or else creates an account with a pending email link at the provider, so that person's first sign-in there lands in it. Default false.

one of "true" | "false"

filestring (binary)yes

CSV file, at most 1 MB: a header row naming a `user_id` (the OIDC `sub` claim at the named provider; `user_subject`, `subject` and `sub` are accepted too), `name` (or `display_name`) and `email` column in any order, then one member per row. Header matching is case-insensitive and extra columns are ignored. A member's name and email cells may be left blank; they seed a newly created account's profile. With `allow_email_only`, the user_id column may be blank or missing and rows are matched by email instead.

Responses

StatusDescriptionBody
200The import's outcome: what was added and what was already present.DirectoryImportSummary
400The file is not parseable CSV, a required column is missing from the header, a row failed validation, a subject or email appears twice, an email-only row's address is carried by several live accounts, or the file has no (or too many) data rows.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token's subject is not a superuser.ErrorResponse
404No organization or sign-in provider has that id or slug.ErrorResponse
409A concurrent sign-in or import raced this one; re-run the import.ErrorResponse
413The file is larger than 1 MB.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
GET/api/organizations/{org_id}/users Bearer token

List an organization's user directory

Lists every member of the organization's user directory, named members first, each with the number of roles they currently hold. `trainers=true` narrows the list to the members holding a trainer role — an unexpired grant of a role that manages another role through a reporting line — the people an event's trainer pickers offer. Requires a valid access token.

Parameters

NameInTypeRequiredDescription
org_idpathstringyesOrganization UUID id or slug.
trainersquerystringnoSet true to list only the members holding a trainer role: an unexpired grant of a role that manages another role through a reporting line. Defaults to false.

Responses

StatusDescriptionBody
200The directory's members.array of DirectoryUser
401The access token is missing or invalid.ErrorResponse
404No organization has that id or slug.ErrorResponse
500The directory database could not be read.ErrorResponse
POST/api/organizations/{org_id}/users Bearer token

Add a user to the directory

Adds a user to the organization's directory: an existing account by user_id, or a pre-provisioned identity by provider_id + subject — the account is created on the spot when that identity is new. Requires a superuser's access token.

Parameters

NameInTypeRequiredDescription
org_idpathstringyesOrganization UUID id or slug.

Request body

application/jsonrequiredAddDirectoryUserRequest
FieldTypeRequiredDescription
user_idstring (uuid)no

The member's account id (`users.id`). Mutually exclusive with provider_id/subject.

provider_idstringno

Sign-in provider UUID id or slug.

at least 1 character

subjectstringno

OIDC `sub` claim the member will present at that provider.

1–255 characters

display_namestringno

Starting profile for a newly created account; ignored for an existing one.

1–300 characters

emailstringno

1–300 characters

Responses

StatusDescriptionBody
201The added member.DirectoryUser
400The request body failed validation.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token's subject is not a superuser.ErrorResponse
404The organization, the named user, or the named provider does not exist.ErrorResponse
409That user is already in the organization's directory.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
GET/api/organizations/{org_id}/users/{user_id} Bearer token

Get a directory member

Returns one member of the organization's directory, with every role grant they hold there — expired ones included. Requires a valid access token.

Parameters

NameInTypeRequiredDescription
org_idpathstringyesOrganization UUID id or slug.
user_idpathstring (uuid)yesThe member's account id (`users.id`).

Responses

StatusDescriptionBody
200The member and their grants.DirectoryUserWithRoles
401The access token is missing or invalid.ErrorResponse
404The organization does not exist, or that user is not in its directory.ErrorResponse
500The directory database could not be read.ErrorResponse
DELETE/api/organizations/{org_id}/users/{user_id} Bearer token

Remove a user from the directory

Removes a member from the organization's directory, revoking every role they hold there. The account itself (and its history) remains. Requires a superuser's access token.

Parameters

NameInTypeRequiredDescription
org_idpathstringyesOrganization UUID id or slug.
user_idpathstring (uuid)yesThe member's account id (`users.id`).

Responses

StatusDescriptionBody
200The removed member, with the grants that were revoked.DirectoryUserWithRoles
401The access token is missing or invalid.ErrorResponse
403The access token's subject is not a superuser.ErrorResponse
404The organization does not exist, or that user is not in its directory.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
GET/api/organizations/{org_id}/users/{user_id}/roles Bearer token

List a directory member's roles

Lists every role grant a member holds in the organization, expired ones included — check expires_at. Requires a valid access token.

Parameters

NameInTypeRequiredDescription
org_idpathstringyesOrganization UUID id or slug.
user_idpathstring (uuid)yesThe member's account id (`users.id`).

Responses

StatusDescriptionBody
200The member's grants, by department and role name.array of DirectoryUserRole
401The access token is missing or invalid.ErrorResponse
404The organization does not exist, or that user is not in its directory.ErrorResponse
500The directory database could not be read.ErrorResponse
POST/api/organizations/{org_id}/users/{user_id}/roles Bearer token

Assign a role to a directory member

Grants a member one of the roles defined by a department of the organization, open-ended or until an expiry. Requires a superuser's access token, or one whose subject holds directory:write in a scope covering the role's department — and then only for a member who already holds a role in a department that scope covers.

Parameters

NameInTypeRequiredDescription
org_idpathstringyesOrganization UUID id or slug.
user_idpathstring (uuid)yesThe member's account id (`users.id`).

Request body

application/jsonrequiredAssignDirectoryUserRoleRequest
FieldTypeRequiredDescription
department_idstringyes

Department UUID id or slug, resolved within the organization.

at least 1 character

role_idstringyes

Role UUID id or slug, resolved within the department.

at least 1 character

expires_atstring (date-time)no

When the grant lapses; omit for an open-ended one. Must be in the future.

Responses

StatusDescriptionBody
201The created grant.DirectoryUserRole
400The request body failed validation, or expires_at is not in the future.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token's subject is neither a superuser nor holds directory:write over the role's department, or the member holds no role in a department that grant covers.ErrorResponse
404The organization, the member in its directory, the department, or the role does not exist.ErrorResponse
409The member already holds that role.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
PATCH/api/organizations/{org_id}/users/{user_id}/roles/{role_id} Bearer token

Update a directory member's role grant

Changes when a member's grant expires — renewing a lapsed one, scheduling an end, or making it open-ended with null. Requires a superuser's access token.

Parameters

NameInTypeRequiredDescription
org_idpathstringyesOrganization UUID id or slug.
user_idpathstring (uuid)yesThe member's account id (`users.id`).
role_idpathstringyesRole UUID id or slug, resolved among the member's grants. A member holding identically-slugged roles in two departments must be addressed by the UUID.

Request body

application/jsonrequiredUpdateDirectoryUserRoleRequest
FieldTypeRequiredDescription
expires_atstring (date-time) | nullyes

New expiry of the grant; null makes it open-ended.

Responses

StatusDescriptionBody
200The updated grant.DirectoryUserRole
400The request body failed validation, expires_at does not follow the grant time, or the role slug is ambiguous across the member's departments.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token's subject is not a superuser.ErrorResponse
404The organization, the member in its directory, or the member's grant of that role does not exist.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
DELETE/api/organizations/{org_id}/users/{user_id}/roles/{role_id} Bearer token

Revoke a directory member's role

Removes one of a member's role grants. Requires a superuser's access token.

Parameters

NameInTypeRequiredDescription
org_idpathstringyesOrganization UUID id or slug.
user_idpathstring (uuid)yesThe member's account id (`users.id`).
role_idpathstringyesRole UUID id or slug, resolved among the member's grants. A member holding identically-slugged roles in two departments must be addressed by the UUID.

Responses

StatusDescriptionBody
200The revoked grant.DirectoryUserRole
400The role slug is ambiguous across the member's departments.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token's subject is not a superuser.ErrorResponse
404The organization, the member in its directory, or the member's grant of that role does not exist.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
GET/api/organizations/{organizationId}/departments/{departmentId}/roles/{roleId}/managers Bearer token

List a role's reporting lines

Lists the roles managing this role and the roles it manages. Holders of a manager role (or of any role above it in the chain) may approve or reject the pending learning-record submissions of the subordinate role's holders.

Parameters

NameInTypeRequiredDescription
organizationIdpathstring (uuid)yese.g. 6f3b34d8-3c5e-4dd9-9f4e-2b52f0d9a1c7
departmentIdpathstring (uuid)yese.g. 0b8f9a3e-97a4-4f2f-b3a3-51f2f8f0f7f4
roleIdpathstring (uuid)yese.g. 9c2f1f7e-4a35-4b8f-8d21-3f5b2a7c9d10

Responses

StatusDescriptionBody
200The role's reporting lines, both directions.RoleManagers
401The access token is missing or invalid.ErrorResponse
404The organization, department, or role does not exist there.ErrorResponse
500The directory database could not be read.ErrorResponse
POST/api/organizations/{organizationId}/departments/{departmentId}/roles/{roleId}/managers Bearer token

Make a role a manager of this role

Adds a reporting line: the named role becomes a manager of the role in the path. Both roles must belong to the same organization; a line that would close a cycle is refused. Requires a superuser's access token, or one whose user holds directory:write in a scope covering both roles' departments.

Parameters

NameInTypeRequiredDescription
organizationIdpathstring (uuid)yese.g. 6f3b34d8-3c5e-4dd9-9f4e-2b52f0d9a1c7
departmentIdpathstring (uuid)yese.g. 0b8f9a3e-97a4-4f2f-b3a3-51f2f8f0f7f4
roleIdpathstring (uuid)yese.g. 9c2f1f7e-4a35-4b8f-8d21-3f5b2a7c9d10

Request body

application/jsonrequiredCreateRoleManagerRequest
FieldTypeRequiredDescription
manager_role_idstring (uuid)yes

The role to make a manager of this one. Any role of the same organization except this role itself, or one that would close a cycle.

Responses

StatusDescriptionBody
201The created reporting line, manager side resolved.RoleManagerEdge
400The request body failed validation.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The caller is neither a superuser nor a directory:write holder whose scope covers both roles' departments.ErrorResponse
404The organization, department, or role does not exist there, or the manager role is not in that organization.ErrorResponse
409The role already reports to that manager, or the line would close a cycle.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
DELETE/api/organizations/{organizationId}/departments/{departmentId}/roles/{roleId}/managers/{managerRoleId} Bearer token

Remove a manager from this role

Removes the reporting line between this role and the named manager role. Requires a superuser's access token, or one whose user holds directory:write in a scope covering both roles' departments.

Parameters

NameInTypeRequiredDescription
organizationIdpathstring (uuid)yese.g. 6f3b34d8-3c5e-4dd9-9f4e-2b52f0d9a1c7
departmentIdpathstring (uuid)yese.g. 0b8f9a3e-97a4-4f2f-b3a3-51f2f8f0f7f4
roleIdpathstring (uuid)yese.g. 9c2f1f7e-4a35-4b8f-8d21-3f5b2a7c9d10
managerRoleIdpathstring (uuid)yese.g. 2e6d0c4a-8b1f-4e7a-9c3d-5a4b6c7d8e9f

Responses

StatusDescriptionBody
204The reporting line is gone.—
401The access token is missing or invalid.ErrorResponse
403The caller is neither a superuser nor a directory:write holder whose scope covers both roles' departments.ErrorResponse
404No such reporting line — a path segment or the line itself does not exist.ErrorResponse
500The directory database could not be reached, or the write failed.ErrorResponse
GET/api/organizations/{org_id} Bearer token

Get an organization

Returns one organization and every department inside it. Requires a valid access token.

Parameters

NameInTypeRequiredDescription
org_idpathstringyesOrganization UUID id or slug.

Responses

StatusDescriptionBody
200The organization and its departments.OrganizationWithDepartments
401The access token is missing or invalid.ErrorResponse
404No organization has that id or slug.ErrorResponse
500The directory database could not be read.ErrorResponse
GET/api/organizations/{org_id}/departments/{dept_id} Bearer token

Get a department

Returns one department of an organization. Requires a valid access token.

Parameters

NameInTypeRequiredDescription
org_idpathstringyesOrganization UUID id or slug.
dept_idpathstringyesDepartment UUID id or slug, resolved within the organization.

Responses

StatusDescriptionBody
200The department.DepartmentSummary
401The access token is missing or invalid.ErrorResponse
404The organization, or the department within it, does not exist.ErrorResponse
500The directory database could not be read.ErrorResponse
GET/api/organizations/{org_id}/departments/{dept_id}/roles Bearer token

List a department's roles

Lists the roles a department defines, with the permissions each grants and how many users currently hold it. Requires a valid access token.

Parameters

NameInTypeRequiredDescription
org_idpathstringyesOrganization UUID id or slug.
dept_idpathstringyesDepartment UUID id or slug, resolved within the organization.

Responses

StatusDescriptionBody
200The department's roles, ordered by name.array of DepartmentRoleSummary
401The access token is missing or invalid.ErrorResponse
404The organization, or the department within it, does not exist.ErrorResponse
500The directory database could not be read.ErrorResponse
GET/api/organizations/{org_id}/departments/{dept_id}/roles/{role_id} Bearer token

Get a department role

Returns one role of a department, with the permissions it grants and how many users currently hold it. Requires a valid access token.

Parameters

NameInTypeRequiredDescription
org_idpathstringyesOrganization UUID id or slug.
dept_idpathstringyesDepartment UUID id or slug, resolved within the organization.
role_idpathstringyesRole UUID id or slug, resolved within the department.

Responses

StatusDescriptionBody
200The role.DepartmentRoleSummary
401The access token is missing or invalid.ErrorResponse
404The organization, department or role does not exist.ErrorResponse
500The directory database could not be read.ErrorResponse