Skip to main content

Access

Generated from apiome-rest/openapi.yaml (API version 1.204.1) — do not edit by hand. How to authenticate is on the REST API reference.

Tag: access · 14 operations

GET /v1/access/{tenant_slug}/audit​

List Audit

List access-audit entries for the tenant, newest first, with an optional category filter.

Categories are all, role, permission, member, admin and styleGuide (style-guide governance: create / edit / assign, GOV-1.6). An unknown value is treated as all.

since is an optional ISO 8601 lower bound on created_at — what the UI's date range sends, and what its CSV export sends back so the two agree (HIVE-5.5, #5308).

Each row carries prev_hash and entry_hash, its position in the tenant's hash chain.

Operation id: list_audit_v1_access__tenant_slug__audit_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
filterquerystringnoQuery parameter: filter.
sincequerystring or nullnoQuery parameter: since.
limitqueryintegernoMaximum number of rows to return.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list audit.application/json array of object
422Validation Errorapplication/json HTTPValidationError

GET /v1/access/{tenant_slug}/audit/export​

Export Audit

Export the tenant's access-audit ledger as CSV (SOC 2 / ISO 27001 access-review evidence).

Takes the same filter and since narrowing as the list endpoint, so the CSV holds the rows the reader was looking at rather than a second, wider answer. Omitting both exports the whole ledger, which is what every caller before HIVE-5.5 (#5308) got.

Operation id: export_audit_v1_access__tenant_slug__audit_export_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
filterquerystringnoQuery parameter: filter.
sincequerystring or nullnoQuery parameter: since.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for export audit.application/json any
422Validation Errorapplication/json HTTPValidationError

GET /v1/access/{tenant_slug}/members​

List Members

List tenant members with their role, lifecycle status, and admin flag.

Operation id: list_members_v1_access__tenant_slug__members_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list members.application/json array of object
422Validation Errorapplication/json HTTPValidationError

POST /v1/access/{tenant_slug}/members​

Invite Member

Invite an existing account into the tenant and optionally assign a role.

The invitee must already have an Apiome account (email-only invites that provision brand-new accounts are a later SSO/SCIM ticket). The new membership is created active.

Seat-gated (OLO-5.3, #4213): when the tenant's license seats (seats.max_users_per_tenant) are all occupied by non-suspended members, the request is refused with a structured 403 (code license-seats-exhausted) before any lookup or write happens — including re-invites of existing members, which are inert at capacity anyway.

Operation id: invite_member_v1_access__tenant_slug__members_post

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for invite member.

Responses

StatusDescriptionBody
200Successful response for invite member.application/json object
422Validation Errorapplication/json HTTPValidationError

PATCH /v1/access/{tenant_slug}/members/{user_id}​

Update Member

Assign a member's role and/or change their lifecycle status (suspend / reinstate).

Operation id: update_member_v1_access__tenant_slug__members__user_id__patch

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
user_idpathstringyesPath parameter identifying the user id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for update member.

Responses

StatusDescriptionBody
200Successful response for update member.application/json object
422Validation Errorapplication/json HTTPValidationError

DELETE /v1/access/{tenant_slug}/members/{user_id}​

Offboard Member

Offboard a member: remove membership, role assignment, and any tenant-admin row.

Operation id: offboard_member_v1_access__tenant_slug__members__user_id__delete

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
user_idpathstringyesPath parameter identifying the user id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
204Successful response for offboard member.—
422Validation Errorapplication/json HTTPValidationError

POST /v1/access/{tenant_slug}/members/{user_id}/resend-invite​

Resend Member Invite

Re-issue a member's outstanding invitation (HIVE-5.2, #5305).

Apiome does not mail invitations: :func:invite_member requires the invitee to hold an account already, and a pending membership becomes active the next time they sign in. Re-issuing therefore renews the invitation rather than re-sending a message — the membership row is re-stamped so the members screen's "Invited {date}" reads freshly, and the renewal is recorded in the access ledger as member.invite_resent so an access review can see who kept an outstanding invitation alive.

Gated on members:create, the same permission as issuing the invitation in the first place. Consumes no seat: the pending membership already holds one, so the OLO-5.3 capacity guard is deliberately not consulted.

:raises HTTPException: 404 when the user has no membership in the tenant, 409 when their membership is not pending (there is no invitation outstanding to renew).

Operation id: resend_member_invite_v1_access__tenant_slug__members__user_id__resend_invite_post

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
user_idpathstringyesPath parameter identifying the user id segment.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for resend member invite.application/json object
422Validation Errorapplication/json HTTPValidationError

GET /v1/access/{tenant_slug}/permissions/me​

Get My Permissions

Return the caller's effective resource:action permissions in this tenant.

Tenant administrators are reported as having every permission. The UI uses this to show/hide mutating controls without hard-coding role names.

Operation id: get_my_permissions_v1_access__tenant_slug__permissions_me_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get my permissions.application/json object
422Validation Errorapplication/json HTTPValidationError

GET /v1/access/{tenant_slug}/roles​

List Roles

List the tenant's roles (built-in first) with member counts and permission grids.

Operation id: list_roles_v1_access__tenant_slug__roles_get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for list roles.application/json array of object
422Validation Errorapplication/json HTTPValidationError

POST /v1/access/{tenant_slug}/roles​

Create Role

Create a custom role with an initial permission grid (Owner/Admin only by default).

Operation id: create_role_v1_access__tenant_slug__roles_post

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for create role.

Responses

StatusDescriptionBody
200Successful response for create role.application/json object
422Validation Errorapplication/json HTTPValidationError

GET /v1/access/{tenant_slug}/roles/{role_id}​

Get Role

Fetch a single role with its permission grid.

Operation id: get_role_v1_access__tenant_slug__roles__role_id__get

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
role_idpathstringyesRole identifier.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get role.application/json object
422Validation Errorapplication/json HTTPValidationError

PUT /v1/access/{tenant_slug}/roles/{role_id}​

Update Role

Update a role's name/description and replace its permission grid.

Built-in role names are immutable, but their permission grids may be tuned by an administrator.

Operation id: update_role_v1_access__tenant_slug__roles__role_id__put

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
role_idpathstringyesRole identifier.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for update role.

Responses

StatusDescriptionBody
200Successful response for update role.application/json object
422Validation Errorapplication/json HTTPValidationError

DELETE /v1/access/{tenant_slug}/roles/{role_id}​

Delete Role

Delete a custom role. Built-in roles cannot be deleted.

Operation id: delete_role_v1_access__tenant_slug__roles__role_id__delete

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
role_idpathstringyesRole identifier.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
204Successful response for delete role.—
422Validation Errorapplication/json HTTPValidationError

POST /v1/access/{tenant_slug}/roles/{role_id}/duplicate​

Duplicate Role

Clone a role's permission grid into a new custom role.

Operation id: duplicate_role_v1_access__tenant_slug__roles__role_id__duplicate_post

Parameters

NameInTypeRequiredDescription
tenant_slugpathstringyesURL-safe tenant slug that scopes the request.
role_idpathstringyesRole identifier.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for duplicate role.

Responses

StatusDescriptionBody
200Successful response for duplicate role.application/json object
422Validation Errorapplication/json HTTPValidationError

Schemas used​

HTTPValidationError​

Validation error response emitted when request data fails schema checks.

PropertyTypeRequiredDescription
detailarray of ValidationErrornoDetail.

MemberInviteRequest​

Invite an existing account to the tenant and assign a role.

PropertyTypeRequiredDescription
emailstringyesEmail.
role_idstring or nullnoRole ID.

MemberUpdateRequest​

Change a member's role and/or lifecycle status.

PropertyTypeRequiredDescription
role_idstring or nullnoRole ID.
statusstring or nullnoStatus.

RoleDuplicateRequest​

Clone an existing role under a new name.

PropertyTypeRequiredDescription
namestringyesHuman-readable name.

RoleWriteRequest​

Create/update payload for a role (name, description, full permission grid).

PropertyTypeRequiredDescription
namestringyesHuman-readable name.
descriptionstring or nullnoFree-text description.
permissionsarray of PermissionCellnoPermissions.