Skip to content

Development environment: content is being written, nothing points to production.

Documentation contents

members

Version 0.1.06 operations

Members with role and scope, and pending invitations

GET/organisations/{id}/membersDashboard session

Parameters

  • idstringpathrequired

Responses

  • 200

    • membersMemberDto[]required
      • userIdstring (uuid)required
      • emailstringrequired
      • firstNamestringrequired
      • lastNamestringrequired
      • roleIdstring (uuid)required
      • rolestring | nullrequired
      • roleNamestringrequired
      • isOwnerbooleanrequired
      • permissionsstring[]required
      • scopestringrequired
        • enum: "all", "accounts"
      • accountIdsstring[]required
      • lastLoginAtstring (date-time) | nullrequired
      • joinedAtstring (date-time)required
    • invitationsInvitationDto[]required

      Pending invitations

      • idstring (uuid)required
      • emailstringrequired
      • roleIdstring (uuid)required
      • roleNamestringrequired
      • scopestringrequired
        • enum: "all", "accounts"
      • accountIdsstring[]required
      • expiresAtstring (date-time)required
      • createdAtstring (date-time)required

Code samples

curl -X GET "$KONNECT_API_URL/organisations/id/members" \
  -H "Cookie: konnect_session=$KONNECT_SESSION"

Example: 200

{
  "members": [
    {
      "userId": "userId",
      "email": "buyer@example.com",
      "firstName": "Salma",
      "lastName": "Example",
      "roleId": "roleId",
      "role": "role",
      "roleName": "roleName",
      "isOwner": true,
      "permissions": [
        "payments.view"
      ],
      "scope": "all",
      "accountIds": [
        "string"
      ],
      "lastLoginAt": "2026-10-01T09:30:00.000Z",
      "joinedAt": "2026-10-01T09:30:00.000Z"
    }
  ],
  "invitations": [
    {
      "id": "id",
      "email": "buyer@example.com",
      "roleId": "roleId",
      "roleName": "roleName",
      "scope": "all",
      "accountIds": [
        "string"
      ],
      "expiresAt": "2026-10-01T09:30:00.000Z",
      "createdAt": "2026-10-01T09:30:00.000Z"
    }
  ]
}

Invite by email with a role and a scope (link returned outside production)

POST/organisations/{id}/membersDashboard session

Parameters

  • idstringpathrequired

Request body application/json

  • scopestring
    • enum: "all", "accounts"
    • default: "all"
  • accountIdsstring[]

    Payment account ids when scope is "accounts"

  • emailstringrequired
  • roleIdstring (uuid)required

Responses

  • 201

    • idstring (uuid)required
    • emailstringrequired
    • roleIdstring (uuid)required
    • roleNamestringrequired
    • scopestringrequired
      • enum: "all", "accounts"
    • accountIdsstring[]required
    • expiresAtstring (date-time)required
    • createdAtstring (date-time)required
    • inviteLinkstring | null

      Invitation link, returned outside production only until email transport exists

Code samples

curl -X POST "$KONNECT_API_URL/organisations/id/members" \
  -H "Cookie: konnect_session=$KONNECT_SESSION" \
  -H "Content-Type: application/json" \
  -d '{
  "scope": "all",
  "accountIds": [
    "string"
  ],
  "email": "new.member@example.test",
  "roleId": "roleId"
}'

Example: request body

{
  "scope": "all",
  "accountIds": [
    "string"
  ],
  "email": "new.member@example.test",
  "roleId": "roleId"
}

Example: 201

{
  "id": "id",
  "email": "buyer@example.com",
  "roleId": "roleId",
  "roleName": "roleName",
  "scope": "all",
  "accountIds": [
    "string"
  ],
  "expiresAt": "2026-10-01T09:30:00.000Z",
  "createdAt": "2026-10-01T09:30:00.000Z",
  "inviteLink": "inviteLink"
}

Change the role or the scope of a member (not the owner)

PATCH/organisations/{id}/members/{userId}Dashboard session

Parameters

  • idstringpathrequired
  • userIdstringpathrequired

Request body application/json

  • scopestring
    • enum: "all", "accounts"
    • default: "all"
  • accountIdsstring[]

    Payment account ids when scope is "accounts"

  • roleIdstring (uuid)

Responses

  • 204

Code samples

curl -X PATCH "$KONNECT_API_URL/organisations/id/members/userId" \
  -H "Cookie: konnect_session=$KONNECT_SESSION" \
  -H "Content-Type: application/json" \
  -d '{
  "scope": "all",
  "accountIds": [
    "string"
  ],
  "roleId": "roleId"
}'

Example: request body

{
  "scope": "all",
  "accountIds": [
    "string"
  ],
  "roleId": "roleId"
}

Remove a member (not the owner)

DELETE/organisations/{id}/members/{userId}Dashboard session

Parameters

  • idstringpathrequired
  • userIdstringpathrequired

Responses

  • 204

Code samples

curl -X DELETE "$KONNECT_API_URL/organisations/id/members/userId" \
  -H "Cookie: konnect_session=$KONNECT_SESSION"

Cancel a pending invitation

DELETE/organisations/{id}/invitations/{invitationId}Dashboard session

Parameters

  • idstringpathrequired
  • invitationIdstringpathrequired

Responses

  • 204

Code samples

curl -X DELETE "$KONNECT_API_URL/organisations/id/invitations/invitationId" \
  -H "Cookie: konnect_session=$KONNECT_SESSION"

Accept an invitation: creates the account for a new email, or needs the session of the invited email

POST/invitations/accept

Parameters

No parameters.

Request body application/json

  • tokenstringrequired
  • firstNamestring

    Required when the email has no account yet

  • lastNamestring

    Required when the email has no account yet

  • passwordstring (password)

    Required when the email has no account yet

Responses

  • 200

    • organisationIdstring (uuid)required
    • userIdstring (uuid)required
    • accountCreatedbooleanrequired

      True when the account was created by this acceptance

Code samples

curl -X POST "$KONNECT_API_URL/invitations/accept" \
  -H "Content-Type: application/json" \
  -d '{
  "token": "token",
  "firstName": "Salma",
  "lastName": "Example",
  "password": "password"
}'

Example: request body

{
  "token": "token",
  "firstName": "Salma",
  "lastName": "Example",
  "password": "password"
}

Example: 200

{
  "organisationId": "org_01J9Z3K4EXAMPLE0000000000",
  "userId": "userId",
  "accountCreated": true
}