PurrOSDocs

Users & Roles

Inviting and managing accounts, custom roles, and company sign-in settings.

Managing accounts and roles needs users.manage or roles.manage with reach Everyone, and works only for people (sessions and personal keys). Integration keys can read roles and users (see Organization) but never change them, so an integration can't escalate access.

You can only create, edit or assign a role if you hold every permission in it with an equal or wider reach. See Users, roles & permissions.

All paths are relative to /api/v1. Key is the scope an integration key needs, People the permission a signed-in person or personal key needs, and Feature the feature switch the endpoint belongs to. See how to read this reference.

  • POST/roles

    Create a role

    Keynot allowed
    Peopleroles.manage (Everyone)
  • PATCH/roles/{id}

    Change a role

    Keynot allowed
    Peopleroles.manage (Everyone)
  • DELETE/roles/{id}

    Delete a role

    Keynot allowed
    Peopleroles.manage (Everyone)
  • GET/settings/authentication

    Sign-in settings

    Keynot allowed
    Peoplesettings.manage (Everyone)
  • PATCH/settings/authentication

    Change sign-in settings

    Keynot allowed
    Peoplesettings.manage (Everyone)
  • POST/users

    Invite someone

    Keynot allowed
    Peopleusers.manage (Everyone)
  • PATCH/users/{id}

    Change someone's name, role, employee link or assignments

    Keynot allowed
    Peopleusers.manage (Everyone)
  • POST/users/{id}:deactivate

    Deactivate an account

    Keynot allowed
    Peopleusers.manage (Everyone)
  • POST/users/{id}:reactivate

    Reactivate an account

    Keynot allowed
    Peopleusers.manage (Everyone)
  • POST/users/{id}:reset-sign-in

    Reset someone's sign-in

    Keynot allowed
    Peopleusers.manage (Everyone)